Learn the basics

What are threat intelligence feeds?

A plain-language guide to threat intelligence feeds: what they contain, how they are delivered, the difference between free and paid, and how to put them to work in your firewall, SIEM and DNS.

A short definition

A threat intelligence feed is a continuously updated list of indicators of compromise (IOCs): the IP addresses, domains and URLs that attackers use for phishing, malware, botnets and command-and-control. Security tools read the feed and block those indicators automatically, so known-bad traffic is stopped without manual work.

What is inside a feed

  • Malicious IP feeds block traffic to and from known-bad hosts, botnets and C2 servers.
  • Malicious URL feeds stop access to phishing pages and malware downloads in a web filter.
  • Malicious domain feeds block bad domains at DNS resolution, before a connection is made.
  • Curated categories let you enforce only what is relevant, such as phishing, ransomware or mobile threats.

How feeds are delivered

The same intelligence can reach your stack in several ways:

  • Plain blocklists over HTTPS, pulled on a schedule.
  • Firewall-native mechanisms such as FortiGate External Connectors, Palo Alto External Dynamic Lists or pfBlockerNG aliases.
  • The open TAXII/STIX 2.1 standard, so any compatible SIEM, TIP or SOAR can subscribe.

Free versus paid feeds

Free and open-source feeds are a good way to start, but they vary in quality and freshness. Paid, curated feeds add cross-referencing across many sources, faster refresh cycles and fewer false positives. Q-Feeds offers a free Community edition and paid Plus and Premium tiers that refresh every 20 minutes.

How to choose a good feed

  • Curation: indicators are cross-checked across many sources and cleaned.
  • Freshness: frequent refresh keeps you ahead of fast-moving campaigns.
  • Coverage: commercial, OSINT and governmental sources remove blind spots.
  • Low noise: a low false-positive rate means you block threats, not legitimate traffic.

Put your feeds to work

Once you have a feed, enforce it where it matters: on your firewall, in your SIEM, or over TAXII/STIX. See the threat intelligence feeds overview for the full picture.

Explore Q-Feeds threat feeds

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access