The latest Kaspersky Threat Intelligence Portal update accelerates and simplifies daily operations for SOC teams and threat analysts. AI summarisation and MCP connectivity for third-party AI tools unlock the full potential of Kaspersky's threat intelligence, built on over 25 petabytes of proprietary threat context. Automated smart searches across open-source intelligence (OSINT) deliver additional visibility into potential risks. While modern Security Operations Centers (SOCs) struggle with thousands of daily alerts and understaffing, attacker breakout times continue to dramatically decrease. As the cyber race has been rapidly accelerated by AI, security teams often lack the time and expertise to manually classify complex technical logs or build custom API integrations. To deliver the highly sought-after speed and productivity to defenders, Kaspersky has embedded AI features into its industry-leading Threat Intelligence portfolio. This update expands Kaspersky Threat Intelligence capabilities on two practical fronts: enabling analysts to quickly digest large volumes of human-readable threat data and making services accessible to third-party AI-based applications.
AI summarisation of human-readable threat intelligence
During active investigations, threat hunting, and the tracking of threat actors or campaigns, analysts often have to review hundreds of Indicators of Compromise (IoCs) and long, complex reports. The new AI summarisation feature solves this by condensing massive amounts of human-readable data into short, clear summaries with just a single click.
Summarisation can significantly reduce the amount of information that requires human review for each indicator, helping analysts decide in minutes which items need deeper investigation. This tool automatically processes available information so analysts can identify useful content, including IoCs and rules. Shorter summaries make threat data easier to work with for less-experienced analysts and reduce the workload for highly skilled staff. For each summary block, Kaspersky has deliberately selected the source datasets that feed the resulting summary. This is intended to reduce review time while preserving the context analysts rely on to assess the information presented.
AI summarisation and search capabilities are also available for IoCs identified via open-source intelligence (OSINT) searches. This allows analysts to examine all data related to a requested entity, prioritise it, and receive an overview that surfaces relevant information.
Model Context Protocol support for third-party AI integrations
Integration via the Model Context Protocol (MCP) allows organisations to connect their own or third-party AI applications directly to the Kaspersky Threat Intelligence Portal. Unlike rigid traditional APIs, the MCP connection is specifically built to allow AI models to make flexible, dynamic queries and access external threat data exactly when and how they need it. This standardised integration gives corporate AI applications real-time access to Kaspersky’s global intelligence, enabling smarter automated workflows and highly adaptable threat analysis.
“Kaspersky's Threat Intelligence portfolio has long been recognised for the exceptional quality and coverage of its data. For nearly 30 years, we have built a robust foundation of elite intelligence, extensively leveraging AI and machine learning to collect and classify threat data. Today, our focus is on unlocking its full potential for all our customers. The primary opportunity we bring with new AI features is to reduce the time between receiving information and understanding how to act on it. Ultimately, these capabilities will maximise the efficiency of corporate threat intelligence investments, saving teams hours of complex analysis and significantly enhancing the accuracy of security workflows,” says Alexander Mazikin, Head of Threat Intelligence Product Line at Kaspersky.
Customers can immediately leverage new AI-functionality features using their regular Kaspersky Threat Lookup license, which includes a standard quota of requests. For organisations requiring higher volumes, additional requests can be scaled and purchased on demand.
More details are available on Threat Intelligence Portal page.