• Last Updated
    Jun 30, 2026
  • Version
    1.0.0
  • Compatibility
    ThreatQ Versions >= 5.12.1
  • Kaspersky Threat Intelligence Portal Action Bundle

    ThreatQuotient

    Overview

    The Kaspersky Threat Intelligence Portal Action Bundle enables ThreatQ users to enrich supported indicators with reputation, classification, and contextual intelligence from the Kaspersky OpenTIP platform. The actions provide on-demand lookups for file hashes, IP addresses, URLs, and domains, returning threat context such as reputation, malware detection details, network ownership, categories, WHOIS information, and related metadata to support threat analysis, investigation, and triage.

    The integration provides the following actions:

    • Kaspersky – Lookup Malware - queries Kaspersky OpenTIP using a submitted file hash and returns file reputation, malware classification, contextual intelligence, optional detection details, and synonymous file hashes when available.
    • Kaspersky - Lookup IP Address - queries Kaspersky OpenTIP using a submitted IP address and returns reputation, threat classification, Autonomous System Number (ASN), and network ownership information to provide additional context for analysis and investigation.
    • Kaspersky - Lookup URL - queries Kaspersky OpenTIP using a submitted URL and returns reputation, threat categories, and WHOIS information for the associated hosting domain, providing additional context for threat analysis and investigation.
    • Kaspersky - Lookup FQDN - queries Kaspersky OpenTIP using a submitted fully qualified domain name (FQDN) and returns reputation, threat categories, and WHOIS registration information to provide additional context for threat analysis and investigation.

    The integration is compatible with the following indicator types:

    • IP Address
    • URL
    • FQDN
    • MD5
    • SHA-1
    • SHA-256

    The integration enriches indicators and indicator attributes.

    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

    Copyright © 2026, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy