Kaspersky Threat Intelligence Portal

Web · API

Freedom report

Two barsScore 6.4

  • Free tierA free tier is on its own pricing page
  • Runs widely1 of 6 device platforms
  • DocumentedPlans, terms and facts published

Kaspersky Threat Intelligence Portal is a cloud investigation workspace for security teams working with cyberthreat intelligence. It supports indicator enrichment, malware analysis, threat actor and campaign tracking, and incident response. Threat Lookup connects related threats in Kaspersky's knowledge base, while Threat Analysis examines suspicious files using multiple analysis layers. AI features summarize information for triage and investigation; KIRA also supports OSINT search and relationship tracing. Actor profiles link updated tactics, techniques, procedures, campaigns and indicators when related Kaspersky reports are published. Remote MCP connects compatible assistants such as Claude and ChatGPT to portal data. Users can look up IP addresses, file hashes, domains and web addresses, and registered users can submit web addresses to a sandbox for a page-activity report. The REST API supports web-address lookups with an API token and file submissions for sandbox analysis, up to a documented maximum of 256 MB. Listed connectors include Maltego, MISP, Splunk Enterprise Security, IBM QRadar and Elastic SIEM. Free access includes limited suspicious-file and URL executions; some report sections may lack data, and full reports require demo access.

Who it is for

Kaspersky presents the portal for SOC teams, threat analysts and threat hunters, including incident response and threat-hunting use cases.

What is good

  • Supports indicator enrichment and incident response
  • AI features summarize threat information and trace relationships
  • REST API supports web-address lookups and file submissions
  • Connectors include Maltego, MISP and Splunk Enterprise Security

What to know first

  • Free access limits suspicious-file and URL executions
  • Some report sections may have no data
  • Full reports require demo access
  • Submitted samples must not be confidential or commercially sensitive

Verdict

The portal combines lookup, file and URL analysis, investigation features and integrations for security teams. Free access is limited, and its general-access terms restrict the types and use of submitted samples.

Get started with Kaspersky Threat Intelligence Portal

  1. Visit the Threat Intelligence Portal website.
  2. Register for general access to use its available threat intelligence features.
  3. Submit an API token for REST API web address lookups.
  4. Use the portal to look up indicators or submit files and URLs for analysis.
  5. Request trial access by submitting contact information and selecting the demo request option.
  6. Connect compatible assistants through Remote MCP or use a listed connector.

What the free plan stops at

Free access includes a limited number of suspicious-file and URL executions in Kaspersky Cloud Sandbox. General access provides general information about submitted objects, while some report sections may contain no data and full reports require demo access.

Questions about Kaspersky Threat Intelligence Portal

Is Kaspersky Threat Intelligence Portal free?

Kaspersky offers a free version with access to curated threat intelligence. Registered users receive a limited number of suspicious-file and URL executions in Cloud Sandbox.

How can a team request trial access?

Users can submit contact information and select the demo request option to request trial access.

Which platforms are supported?

The portal lists web and API access and is deployed in the cloud.

What can the REST API do?

It supports web address lookups with an API token and file submissions for sandbox analysis. The documented maximum file size is 256 MB.

Which security tools can it connect to?

Listed connectors include Maltego, MISP, Splunk Enterprise Security, IBM QRadar and Elastic SIEM. Remote MCP also connects compatible assistants such as Claude and ChatGPT.

What are the sample submission terms?

Submitted samples must not be confidential or commercially sensitive. The general access terms grant Kaspersky rights to use, store, edit, reproduce, distribute and delete sample contents.

Kaspersky Threat Intelligence Portal plans and pricing

All plans
Free access Free Free access to curated features Limited features · limited number of suspicious files and URLs for Cloud Sandbox opentip.kaspersky.com · 8 Oct 2026

Compared on threat intelligence platforms

Free plan
Yes
Indicator enrichment
Yes
STIX/TAXII support
Yes
Report management
Yes
Deployment
cloud

Best Kaspersky Threat Intelligence Portal alternatives

See all 20