Threat Intelligence Feeds vs. Threat Intelligence Platforms
Last updated: October 1, 2026
The phrase threat intelligence feed is used for two very different products: a raw list of IP addresses and file hashes, and a fully structured stream that explains an attack. The difference decides whether a feed saves your team time or creates more work. This page draws that line, then shows where a Threat Intelligence Platform (TIP) fits.
What Is a Threat Intelligence Feed?
A threat intelligence feed is a continuous, machine-readable stream of threat data. At one end of the market, it is an indicator list: IP addresses, domain names, URLs, and file hashes with no explanation attached. At the other end, it is a structured stream that pairs each indicator with context: the malware family that uses it, the threat actor behind the campaign, the CVE being exploited, a confidence score, and an expiry window.
Both are called "threat intelligence feeds," and that is the source of most confusion. One tells you what to block. The other tells you why it matters. The rest of this page is about that distinction.
Structured feeds use STIX 2.1, the standard language for describing intelligence objects and the relationships between them. Transport is handled either by a REST API or by TAXII 2.1, the protocol built specifically to move STIX between systems. Flat files (CSV, JSON, plain text) are simpler to ingest but usually carry indicators only.
What Is Inside a Threat Intelligence Feed?
The contents vary by vendor and by tier, but a comprehensive threat intelligence feed typically carries:
- Indicators: IPv4 and IPv6 addresses, domains and subdomains, URLs and URI patterns, and file hashes (MD5, SHA-1, SHA-256).
- Malware families: named tooling and its associated indicators.
- Threat actors and campaigns: the groups behind activity and the operations they run.
- Vulnerabilities: CVEs, exploitation status, and affected products.
- TTPs: adversary behavior mapped to MITRE ATT&CK.
- Context and provenance: confidence scores, validity windows, and source attribution so every indicator can be traced back to its origin.
Types of Threat Intelligence Feed
Feeds are usually grouped by where the data comes from and how it is delivered.
- OSINT feeds: aggregated from public sources. Free and broad, but noisy, heavily duplicated, and light on context.
- Commercial feeds: curated by a vendor, with scoring, deduplication, context, and support behind them.
- Darknet and underground feeds: sourced from forums, marketplaces, and closed channels, useful for early warning.
- Internal and ISAC feeds: indicators shared within a sector or across trusted peers.
- STIX and TAXII feeds: structured and standardized, so they integrate with any compliant platform.
The Limitations of Indicator Lists
An indicator list is useful, and it does one job well: it drives blocking and detection. Its limits appear the moment you need to make a decision about an indicator:
- High Noise-to-Signal Ratio: Lists often include outdated or irrelevant indicators, leading to false positives in your security monitoring tools.
- Lack of Context: A list may tell you an IP is bad, but not why. Is it a scanner, a command-and-control (C2) server, or a compromised legitimate site?
- Manual Processing: Analysts must manually parse, deduplicate, and verify the data before it can be used defensively.
- Volume: Subscribing to several lists quickly produces duplicate indicators and alert fatigue across every downstream tool.
None of this is a problem with feeds. It is a problem with contextless data, and it is exactly what a contextual feed is built to solve.
The Value of a Threat Intelligence Platform (TIP)
A Threat Intelligence Platform is a central repository for your intelligence. It ingests many feeds, normalizes the data, and correlates the results into actionable insights automatically.
Where an indicator list gives you a bare IP address, a TIP adds the surrounding context: the associated Threat Actor, the malware family, typical Tactics, Techniques, and Procedures (TTPs), and a confidence score. In other words, a good feed supplies that context, and a TIP is where an analyst works with it.
Threat Intelligence Feed vs. Platform vs. API
These three pieces are often confused, but they play different roles. The feed carries intelligence, the platform is where an analyst works with it, and an API is how the feed is delivered to your tools.
| Capability | Indicator List | Contextual Feed | Platform (TIP) |
|---|---|---|---|
| Primary role | Deliver indicators | Deliver indicators with context | Analyze and prioritize |
| Context | None | Rich, linked objects | Rich, linked objects |
| Deduplication | Manual | Handled by the source | Automatic |
| Best for | Quick blocking | Detection, enrichment, automation | Analysis and reporting |
How to Evaluate a Threat Intelligence Feed
Not every feed is worth the integration effort. Before you commit, score candidates against these criteria:
- Coverage: Does it track the actors, malware, and sectors that actually target you?
- Freshness: How quickly are new indicators published and expired?
- False-positive rate: Does the vendor measure and publish it?
- Context: Are indicators linked to actors, malware, and TTPs, or delivered as bare values?
- Standards: Does it speak STIX 2.1 and TAXII 2.1 so you avoid proprietary lock-in?
- Provenance: Can you trace an indicator back to its original source?
- Validity windows: Do indicators expire, or does stale data accumulate in your blocklists?
- Integration: Does it fit your SIEM, EDR, and TIP without custom glue code?
Integrating a Threat Intelligence Feed
Integration is where the feed earns its keep. The same threat intelligence feed can drive several systems at once:
- Your EDR for endpoint blocking and detection.
- Your SIEM and SOAR for correlation, enrichment, and automated response.
- Your TIP, whether through the OpenCTI connector or TAXII feeds, for the central knowledge graph.
If your stack already speaks TAXII 2.1, you can point it at a Threat Intelligence API and start consuming intelligence in minutes, with no custom connector to deploy or maintain.
Contextual Intelligence from Threat Landscape
Most vendors sell you an indicator list. Threat Landscape sells structured intelligence: every indicator arrives as a native STIX 2.1 object linked to the actor, campaign, malware, TTPs, confidence score, validity window, and original source that explain it. That is the difference between a blacklist and knowing why an indicator matters.
It is delivered one source, two ways. The Threat Landscape API exposes the full contextual feed over REST and TAXII 2.1, alongside a lean IOC feed for enforcement. The Threat Landscape Platform is the analyst workspace over the same source, with graph visualization, digests, and a built-in AI Assistant.
Frequently Asked Questions
What is a threat intelligence feed?
A threat intelligence feed is a continuous, machine-readable stream of threat data. In practice the term covers two different products: an indicator list (raw IPs, domains, URLs, and file hashes with no context) and a contextual feed (structured objects that pair each indicator with the actor, campaign, malware, and TTPs behind it). Both are consumed by security tools over an API, TAXII, or flat files such as CSV and JSON.
What is the difference between an IOC feed and a threat intelligence feed?
An IOC feed is a lean, deduplicated stream of indicators built for enforcement: IPs, domains, URLs, and hashes that you pipe into an EDR, SIEM, firewall, or blocklist. A threat intelligence feed adds the why: the threat actor, campaign, malware family, and TTPs, usually as STIX 2.1 objects. The IOC feed is an output you act on; the intelligence feed is what makes the action informed.
Are threat intelligence feeds free?
Some are. Open-source (OSINT) feeds are free, but they tend to be high-volume, duplicated across sources, and light on context, which increases false positives and analyst triage time. Commercial feeds add curation, scoring, validity windows, and provenance, at a cost. Many teams run a hybrid: free feeds for breadth and a commercial threat intelligence feed for the high-confidence, contextual layer.
What is the difference between a threat intelligence feed and a platform?
A feed supplies intelligence to your tools automatically. A platform is where an analyst works with it: search, graph visualization, enrichment, and reporting. They answer different questions and most teams use both, ideally from one source.
What is a TAXII feed?
TAXII (Trusted Automated eXchange of Intelligence Information) is the transport protocol used to share STIX-structured threat intelligence between systems. A TAXII feed is simply threat intelligence served over TAXII 2.0 or 2.1, so any compliant client such as a SIEM, EDR, or TIP can subscribe and poll it without custom code.
What data is inside a threat intelligence feed?
A contextual feed carries indicators of compromise (IPv4 and IPv6 addresses, domains, URLs, and file hashes) plus malware families, threat actors, campaigns, CVEs, MITRE ATT&CK techniques, confidence scores, validity windows, and source provenance. An indicator list carries the indicators only.
How do I integrate a threat intelligence feed?
Most teams consume feeds over a REST API or TAXII 2.1. TAXII integrates directly with platforms such as Microsoft Sentinel, Splunk, OpenCTI, and most EDRs. REST is used when you need custom filtering or want to pipe indicators into a firewall, blocklist, or automation pipeline.
See a Feed With the Context Included
Threat Landscape delivers native STIX 2.1 intelligence with the actor, campaign, malware, and TTPs attached, plus a lean IOC feed for enforcement. REST, TAXII 2.1, and MCP.