How to integrate Kaspersky Threat Intelligence Portal with Splunk Phantom

Latest update: September 04, 2019 ID: 15266
 
 
 
 

Kaspersky Threat Intelligence Portal for Splunk Phantom is a Splunk Phantom app that allows you to look up threat intelligence information about IP addresses, URLs, domains, and hashes on Kaspersky Threat Intelligence Portal, and gives you access to Kaspersky Advanced Persistent Threat (APT) Intelligence reports within Phantom UI or as a steps in Phantom Playbooks.

Kaspersky application for Phantom has the following features:

  • Looking up indicators: IP addresses, URLs, domains, and hashes
  • Receiving Kaspersky APT Intelligence reports that contain information about high profile cyber-espionage campaigns
  • Receiving detailed information about indicators

For more information about the application (functionality, features) read its documentation (online HTML-format).

For documentation, refer to Online Help.

To download the application, click this link.

 
 
 
 
 
Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.