# Kaspersky Threat Intelligence

> Use this tool when you need to access and analyze threat intelligence data to stay ahead of emerging threats. Kaspersky Threat Intelligence solves problems related to threat detection, incident response, and security research by providing a repository of threat data and tools for standardizing and querying this data. It takes in inputs such as STIX objects and URLs, and outputs standardized threat intelligence feeds and relationships, making it ideal for security analysts, threat researchers, and SOC teams.

Canonical page: https://skillsregistry.net/skills/kaspersky-threat-intelligence  
JSON: https://api.skillsregistry.net/v1/skills/kaspersky-threat-intelligence

## Description

Multi-component threat intelligence repository by Kaspersky Lab containing three distinct tools: a Python-based OpenCTI connector that imports threat intelligence data from Kaspersky's TAXII server at taxii.tip.kaspersky.com with STIX object transformation and relationship generation, a Go-based URL normalization utility for standardizing URLs by removing default ports and decoding parameters, and an OpenTIP MCP server that provides conversational access to Kaspersky's threat intelligence platform. The OpenCTI connector analyzes STIX object descriptions to generate additional threat intelligence relationships and supports configurable data feeds, update intervals, and object expansion, while the MCP component enables AI assistants to query threat data through natural language interactions, serving security analysts, threat researchers, and SOC teams requiring programmatic access to Kaspersky's commercial threat intelligence feeds.

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-05-05

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/kaspersky-threat-intelligence)
- **Repository:** <https://github.com/kasperskylab/threat-intelligence/tree/HEAD/opentip-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "kaspersky-threat-intelligence"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/kaspersky-threat-intelligence` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/kaspersky-threat-intelligence/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
