About Kaspersky CyberTrace App for QRadar

April 11, 2024

ID 171420

Kaspersky CyberTrace App is a QRadar application that provides visualization of Kaspersky CyberTrace data and interaction with Kaspersky CyberTrace. It provides the following features:

  • Search within the feeds database
  • Charts that contain information about detections
  • Lists of most popular indicators of compromise (IoC) detected by Kaspersky CyberTrace Service
  • Information about Kaspersky CyberTrace Service health

    This information is displayed in the Service events table. The KL_ALERT_OutdatedFeed events are marked with the Outdated feed icon (Outdated feed icon in QRadar (white lightning on a red background).).

  • Last 10 alerts from Kaspersky CyberTrace Service

Some custom event properties are provided together with Kaspersky CyberTrace App. These event properties are the fields of detection alerts sent by Kaspersky CyberTrace Service.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.