Hub
Security

Kaspersky CyberTrace ArcSight CEF Detections

Kaspersky CyberTrace 4.0 detection events, each recording that an event from an endpoint matched a URL or file hash from Kaspersky Threat Data Feeds, in the CEF pattern Kaspersky documents for ArcSight, placed in event.original of ECS JSON. 84 endpoints produce about 510 detections a day, about 12 an hour at night and 30 an hour from 06:00 to 17:00 UTC. Recurring episodes show one endpoint and user matching a malicious URL, then a file MD5, then the same URL again.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/security-kaspersky-cybertrace/generator.yml \
  --id cybertrace \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
KL_Malicious_URLURL from the Malicious URL Data Feed58.3% of detectionsthreat
KL_Malicious_Hash_MD5File MD5 from the Malicious Hash Data Feed20.3% of detectionsthreat
KL_Phishing_URLURL from the Phishing URL Data Feed21.4% of detectionsthreat

Realism Features

  • 84 endpoints produce detections independently, each at its own activity level; together they produce about 12 an hour at night and 30 an hour from 06:00 to 17:00 UTC, about 510 a day. User endpoints are about three times as active from 06:00 to 17:00 UTC as from 20:00 to 06:00, with 17:00-20:00 in between, and fewer users have detections at night; six service-account endpoints (svc-sccm and svc-build, three each) produce about 90 a day evenly around the clock. Most endpoints have one user, and about one in five are shared hosts with several users. The rate and the shares are scenario assumptions, not Kaspersky measurements.
  • Incidents are malicious or phishing URL matches often repeated within seconds, phishing redirects with two phishing URLs within seconds, downloads (a malicious URL, then a file MD5 a minute or two later, often followed by other malicious URLs over the next minutes), hash-first detections (sometimes rescanned, sometimes followed by a malicious URL contact), and beacon-like repeats of one malicious URL two to six times usually over 15 minutes to two hours. In live output, most later detections of an incident keep their own @timestamp but arrive after it: a median of about 4 minutes, rarely up to about 35 minutes, and up to an hour at night.
  • Indicators carry fixed feed record fields (mask, first and last seen dates, popularity, threat name, category or industry, file hashes and size). Domains use reserved .test, .example and .invalid names, and addresses are documentation or RFC 1918 ranges.
  • The header, extension key order and cs5/cn3/cs6 labels follow the CyberTrace 4.0 ArcSight integration procedure, with actionable fields in the CEF keys it lists per feed. The actionable field order, the - for an empty field and the cs6 record context layout follow the complete CyberTrace 5.3 record; no complete 4.0 record was found, so 4.0 byte parity is not established. URL record context omits nested feed fields (files, whois, geo, IP).
  • For URL detections the matched indicator is the feed record mask, an interpretation of the documentation. sourceServiceName and sproc stand for the incoming event source, externalId is the endpoint's own event counter, and hash detections carry dst=-. @timestamp is the Eventum event time because the pattern has no time field, and confidence is always 100. Detection events only: no Feed Service alerts, raw endpoint telemetry or TCP transport.
  • Episode endpoints and users are drawn in proportion to their ordinary detection volume at that hour, among pairs with at least about 1.4 incidents a day, and continue their ordinary detections during the episode; episode detections take the place of about as many ordinary ones, so the daily volume and hour curve are the same in both modes. An ordinary match that would complete the URL, MD5, same URL sequence for one endpoint and user within one hour of the first URL match is reported for another URL of the same feed, at the same time and for the same endpoint and user, also after an episode; a match more than one hour after the first is not changed. The chain suggests the host went back to the resource it fetched a detected file from; CyberTrace detections alone do not prove that the URL delivered that file.

Sample Output

{
  "@timestamp": "2026-09-02T17:51:33.754684+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "indicator_match",
    "category": [
      "threat"
    ],
    "code": "KL_Malicious_Hash_MD5",
    "dataset": "kaspersky.cybertrace",
    "kind": "alert",
    "original": "CEF:0|Kaspersky|Kaspersky CyberTrace for ArcSight|2.0|2|CyberTrace Detection Event|8| reason=KL_Malicious_Hash_MD5 dst=- src=10.20.8.54 fileHash=0866B4C3F67DE4BF91804B67F6354CC2 request=- sourceServiceName=ExampleVendor sproc=EndpointSecurity suser=y.nikitin msg=CyberTrace detected KL_Malicious_Hash_MD5 externalId=3509109 flexString1=19.11.2025 14:17 flexString2=07.04.2026 18:38 cn2=1 cs3=Trojan-Spy.Win32.Agent.gen cs4=https://cdn-cdn50.example/doc/view fsize=77520 cs5Label=MatchedIndicator cs5=0866B4C3F67DE4BF91804B67F6354CC2 cn3Label=Confidence cn3=100 cs6Label=Context cs6=MD5:0866B4C3F67DE4BF91804B67F6354CC2 SHA1:C7CE1F47139A080304ACFB26168532493C4BCD3B SHA256:002730128AB1FD01D1B2BAC652C45F183DA6BC5CC0FDD7A5F981C665FB022A40 file_size:77520 first_seen:19.11.2025 14:17 last_seen:07.04.2026 18:38 popularity:1 threat:Trojan-Spy.Win32.Agent.gen ",
    "severity": 8,
    "type": [
      "indicator"
    ]
  },
  "file": {
    "hash": {
      "md5": "0866b4c3f67de4bf91804b67f6354cc2",
      "sha1": "c7ce1f47139a080304acfb26168532493c4bcd3b",
      "sha256": "002730128ab1fd01d1b2bac652c45f183da6bc5cc0fdd7a5f981c665fb022a40"
    },
    "size": 77520
  },
  "kaspersky": {
    "cybertrace": {
      "confidence": 100,
      "external_id": 3509109,
      "matched_indicator": "0866B4C3F67DE4BF91804B67F6354CC2",
      "record_context": "MD5:0866B4C3F67DE4BF91804B67F6354CC2 SHA1:C7CE1F47139A080304ACFB26168532493C4BCD3B SHA256:002730128AB1FD01D1B2BAC652C45F183DA6BC5CC0FDD7A5F981C665FB022A40 file_size:77520 first_seen:19.11.2025 14:17 last_seen:07.04.2026 18:38 popularity:1 threat:Trojan-Spy.Win32.Agent.gen "
    }
  },
  "observer": {
    "product": "Kaspersky CyberTrace for ArcSight",
    "vendor": "Kaspersky"
  },
  "related": {
    "hash": [
      "0866b4c3f67de4bf91804b67f6354cc2",
      "c7ce1f47139a080304acfb26168532493c4bcd3b",
      "002730128ab1fd01d1b2bac652c45f183da6bc5cc0fdd7a5f981c665fb022a40"
    ],
    "ip": [
      "10.20.8.54"
    ],
    "user": [
      "y.nikitin"
    ]
  },
  "source": {
    "ip": "10.20.8.54"
  },
  "user": {
    "name": "y.nikitin"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd the recurring URL, file hash, same URL episode; false produces background only
anomaly_interval_hours24Hours from the start of one episode to the time the next is due, minimum 3

Related Generators