Integrations

Threat Intelligence Feed Integration

Last updated: October 1, 2026

Integrating a threat intelligence feed is how the subscription turns into defense. The good news is that standards, not custom code, do most of the work. If a feed speaks STIX 2.1 over TAXII 2.1, most platforms can subscribe without a single line of glue code.

This page covers the integration options and how to choose between them. For step-by-step setup on specific platforms, follow the linked guides. If you are new to feeds themselves, start with what a threat intelligence feed is.

Integration Options Compared

MethodBest ForEffort
TAXII 2.1SIEM, EDR, TIP platforms that already speak the protocolLowest
Pre-built connectorOpenCTI and platforms with an official integrationLow
REST APICustom pipelines, filtering, blocklists, automationMedium
Flat fileLegacy tools with no native feed supportHighest

TAXII Integration in Four Steps

TAXII standardizes the transport, so the setup is the same across platforms. A typical connection involves:

  1. Point the client at the TAXII root URL. Use the server root, not a collection or discovery path.
  2. Select a collection. Collections separate content types, so you subscribe only to what you need.
  3. Authenticate. Most servers use HTTP Basic auth with your API key, or a bearer token.
  4. Set a polling interval. After the first sync, TAXII polling is incremental, pulling only what is new.

The OpenCTI TAXII guide shows the exact parameters for that platform, and the same shape applies everywhere.

Choose the Right Collection

Most commercial feeds expose at least two streams, and picking the wrong one is the most common integration mistake:

  • Indicators only: lean, deduplicated objects with validity windows. Ideal for SIEM correlation, EDR blocking, firewalls, and blocklists.
  • Full intelligence: the complete STIX object graph with actors, malware, campaigns, CVEs, TTPs, and relationships. Ideal for analysis, enrichment, and a TIP.

Many teams subscribe to both, using the lean stream for enforcement and the full stream for investigation. The Threat Landscape dual API is built around exactly this split.

Where to Send the Feed

  • SIEM and SOAR for correlation, enrichment, and automated response.
  • EDR for endpoint blocking and detection.
  • OpenCTI for the central knowledge graph, via connector or TAXII.

Common Integration Pitfalls

  • Pointing at a collection instead of the root: the client cannot discover collections and the connection fails.
  • Ignoring validity windows: feed into enforcement tools and stale indicators produce false positives.
  • Over-polling: incremental polling means a tight interval adds load without adding freshness.
  • Skipping deduplication: multiple feeds will overlap, so normalize before enforcement.

Next Steps

Ready to wire a feed in? See the Threat Landscape API reference for TAXII collections and REST endpoints, or return to feeds vs. platforms for the strategic picture.