Kaspersky Hunt Hub has been officially launched as part of a major update to the company’s Threat Intelligence Portal, bringing unprecedented transparency to cybersecurity threat detection. The new platform addresses the growing need for security teams to understand not just what threats exist, but how and why they are detected.
According to the Kaspersky Security Bulletin 2025 report, detection systems discovered an average of 500,000 malicious files per day in 2025, marking a 7% increase compared to the previous year. As cyberattacks become more sophisticated and frequent, security teams require more than alerts – they need clarity and actionable intelligence.
What Makes Kaspersky Hunt Hub Revolutionary
The newly launched platform is designed to address growing market demand for greater transparency and deeper insight into how modern detection technologies work. Integrated into the Threat Landscape section of the Threat Intelligence Portal, Kaspersky Hunt Hub provides centralized access to the company’s threat hunting expertise and detection knowledge.
The platform includes Kaspersky Next EDR Expert hunts, also known as indicators of attack (IoA) or detection rules. All portal users can explore the catalogue of hunts and their descriptions, while Kaspersky Next EDR Expert customers gain extended access to detailed recommendations and detection logic presented in a convenient, SIGMA-like format.
Enhanced MITRE ATT&CK Coverage
As part of the update, the MITRE ATT&CK coverage map within the Threat Landscape has been significantly enhanced. The portal now brings together product coverage across SIEM, EDR, NDR and Sandbox solutions, MITRE ATT&CK techniques with scoring, coverage percentages, and related Kaspersky Next EDR Expert hunts in a single, unified view.
This enables organizations to assess how well their security stack covers relevant attack techniques and identify potential gaps in protection. Each hunt is mapped to relevant MITRE ATT&CK tactics and techniques and linked to known threat actors, giving analysts clear context behind every detection.
Expanded Vulnerabilities Database
The Vulnerabilities section has also been expanded, with the CVE database now covering nearly 300,000 vulnerabilities. In addition, the portal provides more detailed information on vulnerabilities that have been exploited in real-world attacks, helping organizations prioritize remediation efforts based on actual threat activity.
“With the launch of Hunt Hub in the Kaspersky Threat Intelligence Portal, we are opening up our detection expertise and giving analysts clear visibility into how and why threats are detected. This transparency helps organizations move from reactive alert handling to informed threat hunting and proactive risk management.”
Nikita Nazarov, Head of Threat Exploration at Kaspersky
Future Outlook for Threat Intelligence
By making detection logic visible and structured, the platform effectively removes the “black box” from threat detection. It allows security teams not only to respond to alerts, but also to understand why a detection was triggered and which threat it is designed to uncover – improving trust in security technologies and increasing the efficiency of threat investigation processes.
This development represents a significant shift in how cybersecurity vendors approach transparency, potentially setting a new industry standard for threat intelligence platforms. Organizations can now make more informed decisions about their security posture and threat response strategies.





