With the number of available threat intelligence sources continuing to grow, a third of CISOs feel under pressure as they cannot consume cybercrime intelligence easily or effectively. To help large companies overcome this challenge, Kaspersky Lab has launched Kaspersky CyberTrace – a free threat intelligence fusion and analysis tool. It aggregates and evaluates disconnected data feeds to help identify what threats pose a danger to the organisation and ensure security teams focus on the right areas.
The variety of threat intelligence sources available on the market doesn’t always translate to protection from cyberattacks, as organisations struggle to decide which are relevant and most important for them. SIEMs or network security controls get overloaded with a large number of Indicators of Compromise (IoC), and the fact that threat data is provided in different formats only worsens the situation.
To make it easier for enterprises to keep up to date with the latest threats, Kaspersky CyberTrace retrieves continuously updated threat data feeds from multiple threat intelligence sources – including Kaspersky Lab, other vendors, open source intelligence or even custom sources – and automatically and rapidly matches them with incoming security events, offloading SIEMs from this high-load operation.
If IoC from threat intelligence feeds are found in any log source within an organisation’s environment, Kaspersky CyberTrace automatically sends alerts to SIEMs for ongoing monitoring and validation to reveal additional contextual evidence for the security incidents. The tool integrates smoothly with a variety of SIEMs, including IBM QRadar, Splunk, ArcSight ESM, LogRhythm, RSA NetWitness, and McAfee ESM, as well as other security controls such as firewalls and gateways.
Kaspersky CyberTrace helps prioritise tasks by giving analysts a set of instruments for conducting alert triage and response through categorisation and validation of identified matches. On-demand lookup of indicators or scanning of logs and files enables advanced in-depth threat investigation, which accelerates forensic and threat hunting activities. The tool also provides feed usage statistics to measure the effectiveness of feeds and their relevance for a certain environment.
“Being aware of the most relevant zero-days, emerging threats and advanced attack vectors is key to an effective cybersecurity strategy. However, manually collecting, analysing and sharing threat data doesn’t provide the level of responsiveness required by an enterprise.
“There’s a need for a centralised point for accessible data sources and task automation. Kaspersky CyberTrace helps organisations better understand their risks, increase the productivity of their security teams and ensure a more robust protection against cyberthreats”, said David Emm, principal security researcher at Kaspersky Lab UK.
Kaspersky CyberTrace is available for customers for free globally and can be downloaded here. To learn more about the tool, please visit our official website.
About Kaspersky Lab
Kaspersky Lab is a global cybersecurity company, which has been operating in the market for over 20 years. Kaspersky Lab’s deep threat intelligence and security expertise is constantly transforming into next generation security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky Lab technologies and we help 270,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.