A short definition
A threat intelligence feed is a continuously updated list of indicators of compromise (IOCs): the IP addresses, domains and URLs that attackers use for phishing, malware, botnets and command-and-control. Security tools read the feed and block those indicators automatically, so known-bad traffic is stopped without manual work.
What is inside a feed
- Malicious IP feeds block traffic to and from known-bad hosts, botnets and C2 servers.
- Malicious URL feeds stop access to phishing pages and malware downloads in a web filter.
- Malicious domain feeds block bad domains at DNS resolution, before a connection is made.
- Curated categories let you enforce only what is relevant, such as phishing, ransomware or mobile threats.
How feeds are delivered
The same intelligence can reach your stack in several ways:
- Plain blocklists over HTTPS, pulled on a schedule.
- Firewall-native mechanisms such as FortiGate External Connectors, Palo Alto External Dynamic Lists or pfBlockerNG aliases.
- The open TAXII/STIX 2.1 standard, so any compatible SIEM, TIP or SOAR can subscribe.
Free versus paid feeds
Free and open-source feeds are a good way to start, but they vary in quality and freshness. Paid, curated feeds add cross-referencing across many sources, faster refresh cycles and fewer false positives. Q-Feeds offers a free Community edition and paid Plus and Premium tiers that refresh every 20 minutes.
How to choose a good feed
- Curation: indicators are cross-checked across many sources and cleaned.
- Freshness: frequent refresh keeps you ahead of fast-moving campaigns.
- Coverage: commercial, OSINT and governmental sources remove blind spots.
- Low noise: a low false-positive rate means you block threats, not legitimate traffic.
Put your feeds to work
Once you have a feed, enforce it where it matters: on your firewall, in your SIEM, or over TAXII/STIX. See the threat intelligence feeds overview for the full picture.