What Is a Threat Intelligence Feed?
Last updated: October 1, 2026
A threat intelligence feed is a continuous, machine-readable stream of information about threats. Instead of sending a human an article to read, a feed delivers structured data that security tools can ingest, match, and act on automatically.
The simplest way to picture it is as a subscription. Rather than asking an analyst to check a vendor's website every morning, you point your SIEM, EDR, or platform at a feed endpoint and let it pull new intelligence on a schedule. If you are weighing that against a full analysis platform, see our comparison of threat intelligence feeds vs. platforms.
What Does a Threat Intelligence Feed Contain?
The exact contents depend on the provider, but a comprehensive feed typically carries a mix of atomic indicators and the context that makes them useful:
- Indicators of Compromise (IoCs): IPv4 and IPv6 addresses, domains and subdomains, URLs and URI patterns, and file hashes (MD5, SHA-1, SHA-256).
- Malware families: the tooling behind the activity, with associated indicators.
- Threat actors and campaigns: the groups responsible and the operations they run.
- Vulnerabilities: CVEs, exploitation status, and affected products.
- TTPs: behavior mapped to frameworks such as MITRE ATT&CK.
- Metadata: confidence scores, validity windows, and source provenance.
That last group is what separates a useful feed from a pile of raw values. An IP address with no context and no expiry is a future false positive. The same indicator with a linked actor, a confidence score, and a validity window is something your tools can automate safely.
Threat Intelligence Feed Formats
Feeds are delivered in several formats, and the format determines how much work you have to do on arrival:
- Flat files: CSV, JSON, or plain text lists. Simple and fast to ingest at scale, but usually indicator-only.
- STIX 2.1: the standard language for describing intelligence objects and their relationships. STIX is what lets a feed carry context, not just values.
- TAXII 2.1: the transport protocol that moves STIX between systems. A TAXII feed works with any compliant client out of the box.
- REST APIs: used when you need custom filtering, pagination, or programmatic access to the underlying objects.
A Worked Example
Imagine a feed publishes a new indicator for a phishing domain. In a flat CSV feed, you receive a line like this:
malicious-login.example.com,2026-09-28,phishing
In a structured STIX feed, the same indicator arrives as an object that names its type, its pattern, and when it is valid, and it can be linked to the campaign that uses it:
{
"type": "indicator",
"spec_version": "2.1",
"name": "Phishing domain for Campaign X",
"pattern": "[domain-name:value = 'malicious-login.example.com']",
"valid_from": "2026-09-28T00:00:00Z",
"valid_until": "2026-12-28T00:00:00Z",
"indicator_types": ["malicious-activity"]
}The difference matters. The CSV line can drive a blocklist. The STIX object can also answer why the domain is malicious, which campaign it belongs to, and when to stop blocking it.
Who Consumes Threat Intelligence Feeds?
- SIEM and SOAR: for correlation, alert enrichment, and automated response. See SIEM and SOAR integration.
- EDR and XDR: for endpoint blocking and detection. See EDR integration.
- Threat intelligence platforms: for the central knowledge graph, often via the OpenCTI connector.
- Firewalls and blocklists: for high-speed indicator ingestion through a lean endpoint such as the Threat Landscape IOC API.
Next Steps
Now that you know what a feed is, the next question is how to choose one. Our evaluation checklist walks through coverage, freshness, false positives, and provenance. If cost is the deciding factor, compare free vs. paid feeds.