About Kaspersky CyberTrace

Welcome to Kaspersky CyberTrace documentation.

What is Kaspersky CyberTrace

Kaspersky CyberTrace is a Threat Intelligence Platform that aggregates indicators of compromise (IoC) from various sources, including Kaspersky Threat Data Feeds, and integrates threat data feeds with SIEM solutions for automatic search of indicators of compromise in security events logs as well as for generating alerts on incidents in the existing security operations workflow of an organization.

Kaspersky CyberTrace uses regularly updated threat data feeds for updating the IoC database in use, detecting cyberthreats in the security events logs, and informing security specialists about the risks associated with the threat.

Kaspersky CyberTrace integrates with threat data sources (threat data feeds from Kaspersky, other vendors, OSINT, or custom sources), SIEM solutions, and security events logs sources. If indicators of compromise (IoC) are detected in your environment, Kaspersky CyberTrace automatically sends to SIEM an alert on the detected indicator along with the additional context information. Kaspersky CyberTrace provides analysts with a set of instruments for conducting alert and response triage through categorization and deduplication.

Diagram of using Kaspersky CyberTrace inside a corporate network.

Kaspersky CyberTrace inside a corporate network

Features of Kaspersky CyberTrace:

The main parts of Kaspersky CyberTrace are Kaspersky CyberTrace Service, Feed Utility, Log Scanner, and Kaspersky CyberTrace Web.

Diagram of main components of CyberTrace.

Main components of Kaspersky CyberTrace

For more information about how Kaspersky CyberTrace works, watch the video below:

Documentation contents

This documentation is divided into several chapters:

In this section

What's new

About feeds and certificates

Page top