Threat Intelligence Feeds: Which Ones Matter
Within 48 hours of the MOVEit vulnerability (CVE-2023-34362) disclosure in May 2023, threat intel feeds lit up with Cl0p-associated infrastructure indicators — C2 domains, exfiltration endpoints, and webshell hashes observed across early victims. Organizations that had operationalized those feeds blocked the C2 domains before exploitation attempts hit their perimeter. Organizations that treated threat intelligence as a compliance checkbox — subscribing to feeds that dumped into a TIP nobody queried — learned about Cl0p from their incident response retainer, weeks later, after data was already staged for extortion. The difference was not access to intelligence. It was operationalization.
Why Now: The Intelligence Curation Crisis
The volume of available threat intelligence has exploded. Open-source feeds, commercial providers, government sharing programs, industry ISACs, social media researchers, and AI-generated threat reports flood security teams with indicators. A decade ago, organizations lacked intelligence. Today, they drown in it.
AI-generated false intelligence compounds the problem. Fabricated CVE write-ups, hallucinated indicators, and synthetic threat reports mixing real tradecraft with invented details are appearing in open-source channels with increasing frequency. Without rigorous curation, organizations ingest false indicators that trigger false-positive alerts or crowd out legitimate intelligence in correlation platforms.
The Maersk/NotPetya incident ($300M in damages) remains the canonical example of intelligence that existed but was not operationalized — warnings about the compromised M.E.Doc update channel had surfaced in Ukrainian regional intelligence channels in the weeks before NotPetya's global spread, but most multinational organizations had no mechanism to act on regional intelligence sources.
Intelligence Levels: Strategic, Operational, Tactical
Threat intelligence serves different audiences at different abstraction levels. Most "feed" discussions focus exclusively on tactical indicators, but all three levels matter for a complete program.
Strategic Intelligence
Audience: CISO, board, risk committee Content: Threat landscape trends, geopolitical drivers, industry targeting patterns, risk forecasts Format: Written reports, briefings, annual assessments Action: Budget allocation, risk acceptance decisions, partnership investments, insurance adjustments Example: "Nation-state actors have shifted from espionage to pre-positioning in critical infrastructure. Defense industrial base targeting has increased 40% year-over-year."
Operational Intelligence
Audience: SOC managers, detection engineers, incident response leads Content: Campaign details — who is attacking, what sectors they target, what infrastructure they use, what TTPs they employ Format: Campaign reports, TTP profiles, threat actor dossiers Action: Detection rule priorities, hunting hypotheses, resource allocation, alert tuning Example: "Threat group X is targeting defense contractors via spearphishing with ISO attachments. Initial access leads to WMI persistence and DNS-over-HTTPS exfiltration."
Tactical Intelligence
Audience: Security tools (automated consumption), SOC analysts (manual investigation) Content: Machine-readable indicators — IP addresses, domains, file hashes, URLs, email addresses, YARA rules, SIGMA rules Format: STIX/TAXII, CSV, JSON, API feeds Action: Automated blocking, SIEM correlation, alert enrichment, forensic investigation Example: "Domain evil-c2[.]example associated with Cl0p infrastructure. SHA256 abc123... is the MOVEit webshell. IP 192.0.2.100 is an active exfiltration endpoint."
Feed Categories and Their Uses
| Category | Content | Primary Integration | Detection Value |
|---|---|---|---|
| IP reputation | Malicious IPs (C2, scanning, brute force, proxy) | Firewall, SIEM | Block known-bad connections; correlate with internal traffic |
| Domain reputation | Malicious and suspicious domains (C2, phishing, malware delivery) | DNS resolver, web proxy, SIEM | Sinkhole or block; detect resolution attempts |
| File hash (MD5/SHA256) | Known malware, tools, webshells | EDR, email gateway, SIEM | Block execution; detect presence on endpoints |
| URL | Phishing pages, malware download locations, exploit kit landing pages | Web proxy, email gateway | Block access; detect user navigation to malicious content |
| Vulnerability exploitation | Actively exploited CVEs, CISA KEV additions, EPSS scores | Vulnerability scanner, patch management | Prioritize remediation based on active exploitation |
| TTP / behavioral | ATT&CK technique indicators, behavioral patterns, detection logic | SIEM, EDR | Build detection rules for adversary behaviors beyond atomic indicators |
| Certificate | Malicious SSL/TLS certificates (C2 infrastructure, phishing) | Network inspection, proxy | Detect encrypted C2 traffic via certificate fingerprinting |
The Contrarian Truth About Feed Volume
More feeds is not better intel. Three curated, relevant feeds integrated into your detection pipeline beat fifteen feeds dumped into a TIP that nobody queries. Every feed you add introduces noise (false positives from stale indicators, duplicates, irrelevant industries), processing overhead (ingestion, deduplication, aging, storage), and maintenance burden (API keys, format changes, outages, renewal).
The organizations with effective threat intelligence programs are not the ones with the most feeds. They are the ones where every ingested indicator has a defined action path — it either triggers a detection, blocks traffic, enriches an alert, or informs a hunt. If an indicator enters your environment and has no consumption path, it is occupying storage and contributing nothing.
Evaluating Feed Quality
Before subscribing to any feed (free or commercial), evaluate against five dimensions:
Accuracy (Signal-to-Noise Ratio)
What percentage of indicators are truly malicious at the time of ingestion? Feeds that include residential proxies, shared hosting IPs, or CDN addresses generate false positives that erode analyst trust. Request accuracy metrics or trial the feed against your environment for 30 days before committing. A feed with 95% accuracy and 1,000 indicators is more operationally valuable than a feed with 60% accuracy and 100,000 indicators.
Timeliness (First-Seen to Feed-Published Latency)
How quickly do indicators appear in the feed after first observation in the wild? The MOVEit example demonstrates why this matters — C2 infrastructure changes within days. An indicator that appears in a feed 30 days after the campaign ended has historical forensic value but zero preventive value. For tactical blocking, same-day publication is the bar.
Relevance (Industry and Threat Alignment)
Does the feed cover threats targeting your specific industry, geography, and technology stack? A feed optimized for financial sector threats (banking trojans, ATM malware, SWIFT infrastructure) provides minimal value to a defense contractor facing nation-state espionage. Conversely, DoD-focused intelligence from DC3 or DIB-ISAC is irrelevant to a retail organization.
Context (Actionability Beyond the Indicator)
Does the feed provide context beyond the raw indicator value? Knowing that an IP is "malicious" is marginally useful. Knowing that it is a Cl0p exfiltration endpoint, first observed on May 31, 2023, associated with MOVEit exploitation, targeting organizations in the legal and healthcare sectors, with a confidence score of 95% — that is actionable intelligence. Context enables prioritization and informs response decisions.
Coverage (Comprehensiveness Within Scope)
How thorough is the feed within its claimed coverage area? A feed claiming to cover ransomware infrastructure that only includes indicators from public disclosures (missing the 70% of infrastructure identified through private research) has coverage gaps that create false confidence.
Key Feeds to Consider
Free and Open Source
- CISA KEV (Known Exploited Vulnerabilities) — Mandatory for federal; essential for everyone. Actively exploited CVEs with remediation deadlines. Integrates directly with vulnerability prioritization.
- AlienVault OTX (Open Threat Exchange) — Community-contributed indicators with campaign context. High volume, variable quality — requires curation.
- Abuse.ch (URLhaus, MalwareBazaar, ThreatFox, Feodo Tracker) — Focused feeds for malware infrastructure. URLhaus for malware distribution URLs; MalwareBazaar for file hashes; ThreatFox for IOCs across campaigns; Feodo for banking trojan C2.
- Emerging Threats (ET Open) — Suricata/Snort rules for network-based detection. Not indicators per se, but actionable detection content.
- PhishTank — Community-verified phishing URLs. Useful for email gateway and web proxy enrichment.
- CIRCL MISP feeds — Curated intelligence from Luxembourg's CERT, including OSINT aggregation and sector-specific sharing communities.
Commercial
- Recorded Future — Comprehensive intelligence platform with risk scoring, natural-language processing of dark web and open sources, and integration modules for most SIEMs. Strength: breadth and automated scoring. Weakness: volume requires discipline to not overwhelm.
- CrowdStrike Falcon Intelligence — Threat actor profiles grounded in CrowdStrike's incident response casework. Strength: high-confidence attribution and TTP detail. Strength for DIB: nation-state actor coverage is deep.
- Mandiant Advantage (now Google Threat Intelligence) — Intelligence derived from Mandiant's incident response engagements. Strength: adversary dossiers with validated TTPs. Weakness: publication lag (post-engagement).
- GreyNoise — Internet-wide scanning data that answers "is this IP targeting me specifically or scanning the entire internet?" Essential for reducing false positives from mass-scanning IPs that appear in other feeds.
- Flashpoint — Deep and dark web intelligence, threat actor communications monitoring. Strength: early warning of targeting discussions.
Government and Sector
- CISA AIS (Automated Indicator Sharing) — STIX/TAXII feed for federal stakeholders and critical infrastructure. Free for qualifying organizations.
- DC3 (DoD Cyber Crime Center) — DIB-specific intelligence sharing. Required awareness for defense contractors.
- FBI InfraGard — Critical infrastructure partnership with sector-specific intelligence.
- DIB-ISAC / Sector ISACs — Industry-specific peer sharing communities (FS-ISAC for financial, H-ISAC for healthcare, DIB-ISAC for defense) with highly curated intelligence.
Operationalizing Feeds: From Subscription to Action
Subscribing to a feed is not operationalization. Operationalization means every indicator has a defined consumption path:
Integration Architecture
| Integration Point | Feed Type Consumed | Automated Action | Human Action |
|---|---|---|---|
| SIEM | All tactical indicators | Correlate with internal logs; generate alerts on match | Investigate matches; hunt for related activity |
| Firewall / Web Proxy | IP and domain reputation | Block connections to known-bad infrastructure | Review blocks for false positives weekly |
| EDR | File hashes, behavioral indicators | Block execution; generate detection alerts | Investigate detections; scope impact |
| Email gateway | Sender reputation, URL, attachment hashes | Quarantine matching emails | Review quarantine for false positives |
| DNS resolver | Domain reputation | Sinkhole or NXDOMAIN malicious domains | Investigate resolution attempts |
| Vulnerability scanner | CISA KEV, exploitation intelligence | Elevate priority of actively exploited vulnerabilities | Accelerate patching for exploited CVEs |
| SOAR playbooks | All tactical indicators | Enrich alerts with matched intelligence | Consume enrichment in decision-making |
The Indicator Lifecycle
Indicators are not permanent. Infrastructure rotates, campaigns end, domains get sinkholed. An effective operationalization includes lifecycle management:
- Ingestion — Feed indicator enters your platform
- Validation — Cross-reference against other feeds; check for known false-positive sources (CDNs, shared hosting, residential IPs)
- Activation — Deploy to blocking/detection/correlation
- Aging — Reduce confidence score over time (IP addresses age fastest; file hashes age slowest)
- Retirement — Remove from active detection after defined TTL (typically 30-90 days for IPs, 180+ days for hashes)
- Archival — Retain for forensic lookback but remove from active blocking/correlation
Without lifecycle management, your indicator corpus grows unbounded, your SIEM correlation becomes slower, and your false-positive rate climbs as stale indicators match legitimate infrastructure that has since been reclaimed.
Avoiding Intelligence Overload
The failure mode is not insufficient intelligence — it is too much undifferentiated intelligence with no prioritization framework:
Symptom: TIP contains 500,000 indicators but analysts never query it Cause: No integration with detection pipeline; indicators are stored, not operationalized
Symptom: SIEM generates 200 threat intel match alerts per day, all low-fidelity Cause: Stale indicators matching legitimate traffic; no aging policy; irrelevant feeds
Symptom: Intelligence team produces weekly reports that nobody reads Cause: Reports describe threats abstractly without connecting to specific environmental risks or actions
Fix: Start with 3-5 feeds, integrate them fully into your detection and response pipeline, measure their value (matches that became true positive investigations), and expand only when existing feeds are fully operationalized and you can identify specific gaps.
Measuring Feed Value
Every feed should justify its operational and financial cost:
| Metric | What It Tells You | Action Threshold |
|---|---|---|
| True positive match rate | Feed accuracy in your environment | Below 2% true positive → review relevance |
| Mean time from first-seen to feed-published | Feed timeliness | Above 7 days for tactical indicators → insufficient for prevention |
| Unique indicators (not in other feeds) | Feed's marginal contribution | Below 5% unique → redundant; consider dropping |
| Matches that led to investigations | Feed's detection contribution | Zero in 90 days → not integrated or not relevant |
| False positive rate | Feed noise in your environment | Above 50% of matches → too noisy; tune or drop |
| Cost per true positive investigation | Economic efficiency | Compare across feeds to identify best value |
Key Takeaways
- Threat intelligence operationalization — not subscription — is what separates organizations that block Cl0p C2 domains in 48 hours from those that learn about Cl0p from their IR retainer weeks later
- Three curated, fully integrated feeds beat fifteen feeds dumped into an unqueried TIP; every indicator needs a defined action path (block, detect, enrich, or hunt)
- Evaluate feeds on accuracy, timeliness, relevance, context, and coverage — not indicator volume, which measures noise as readily as signal
- Indicator lifecycle management (ingestion, validation, activation, aging, retirement) prevents your detection pipeline from drowning in stale indicators that match legitimate traffic
- AI-generated false intelligence is an emerging threat to feed quality; curation discipline matters more than ever
- Government feeds (CISA KEV, AIS, DC3, sector ISACs) are free, highly relevant, and underutilized — start there before purchasing commercial alternatives
Frequently Asked Questions
How many threat intelligence feeds does a mid-size organization actually need?
Start with five: CISA KEV (vulnerability exploitation), one malware infrastructure feed (Abuse.ch ThreatFox or MalwareBazaar), one IP/domain reputation feed (your SIEM vendor's included feed or GreyNoise), your sector ISAC, and one commercial feed matched to your threat profile. Fully operationalize these before adding more. Most organizations that subscribe to 15+ feeds are operationalizing 3-4 of them — the rest are compliance decoration.
Should we build a Threat Intelligence Platform (TIP) or use our SIEM for correlation?
If your SIEM supports IOC matching natively (most modern platforms do), start there. A dedicated TIP adds value when you need: indicator lifecycle management beyond what your SIEM provides, multi-source deduplication, confidence scoring, analyst collaboration on intelligence analysis, or STIX/TAXII hub-and-spoke sharing with partners. For organizations below 5,000 endpoints, the SIEM's built-in correlation typically suffices. Above that scale, or with complex sharing requirements, a TIP earns its cost.
How do we handle threat intel that conflicts between feeds?
Conflicting intelligence (one feed marks an IP as malicious, another as benign, a third has no opinion) is normal and expected. Resolution framework: (1) weight by confidence score if available, (2) weight by source reputation and methodology, (3) check GreyNoise or similar for mass-scanning context, (4) check indicator age — newer observation wins for dynamic infrastructure, (5) if still ambiguous, treat as suspicious (alert and investigate) rather than malicious (auto-block). Document your resolution logic so it applies consistently.
What is the difference between IOCs and TTPs, and which should we prioritize?
IOCs (Indicators of Compromise) are atomic forensic artifacts — specific IPs, domains, hashes — that identify known-bad infrastructure. Easy to operationalize (direct matching) but easy for adversaries to change (infrastructure rotation). TTPs (Tactics, Techniques, and Procedures) describe adversary behaviors — how they persist, move laterally, and exfiltrate. Harder to operationalize (require behavioral detection rules) but harder for adversaries to change. Prioritize both: TTP-based detection provides durable coverage; IOC-based detection provides immediate but ephemeral coverage.
How do we justify the cost of commercial threat intelligence to leadership?
Track three numbers: (1) proactive blocks from threat intel correlation (events that never became incidents), (2) enrichment time saved per investigation (analyst hours), (3) mean time to detect for intel-correlated alerts vs non-correlated. The Log4Shell (CVE-2021-44228) response is the case study — organizations with operationalized feeds deployed blocking rules within hours; those without spent days identifying exposure.
How Advisedly Helps
Advisedly integrates threat intelligence feeds into a unified security and compliance platform, correlating indicators with your SIEM log data and vulnerability scan results while the live CVE feed incorporates exploitation intelligence to prioritize actively exploited vulnerabilities — deduplicating and aging indicators automatically so your detection pipeline stays current without drowning in stale noise. Contact begin@advisedly.ai
<!-- LI hook: Three curated threat intel feeds integrated into detection beat fifteen feeds nobody queries -->