Threat intelligence feeds
Q-Feeds delivers curated cyber threat intelligence feeds: continuously updated lists of malicious IP addresses, domains and URLs you can pull straight into your firewall, SIEM or DNS filter. Start free, scale when you are ready.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 3Feed types: IP, URL, DNS
- 100%Made in Europe
What are threat intelligence feeds?
A threat intelligence feed is a continuously updated stream of indicators of compromise (IOCs): the IP addresses, domains and URLs that attackers use for phishing, malware, botnets and command-and-control. Your security tools consume the feed and block those indicators automatically.
Q-Feeds combines commercial, open-source and governmental sources into one curated set. We remove noise and duplicates, so you enforce real threats instead of chasing false positives. The feeds refresh every 20 minutes, which keeps your defences current without manual list management.
You can pull the same intelligence into a firewall, a SIEM, a DNS resolver or your own tooling over open standards, so a single subscription hardens your whole stack.
Which threat feeds you can use
Malicious IP feeds
Block inbound and outbound traffic to known-malicious hosts, botnets and command-and-control servers.
Malicious URL feeds
Stop access to phishing pages, malware downloads and other harmful links in your web filter.
Malicious domain feeds
Feed malicious domains into your DNS filter to block phishing and C2 domains at resolution time.
Curated categories
Pick focused feeds for phishing, botnets, malware, mobile and dark web threats, so you only enforce what is relevant.
Why choose Q-Feeds threat intelligence
-
Curated, low-noise intelligence
Indicators are cross-referenced across many sources and cleaned, so you block real threats and cut false positives.
-
Refreshed every 20 minutes
Feeds update automatically, so your tools stay ahead of fast-moving campaigns.
-
Multi-source coverage
Commercial, OSINT and governmental sources combined remove single-vendor blind spots.
-
Open standards
Consume feeds over HTTPS, plain blocklists or TAXII/STIX 2.1, so they fit almost any tool.
Put your threat feeds to work
Firewall threat feeds
Enforce blocklists on Fortinet, Palo Alto, Sophos, OPNsense and more.
SIEM feeds
Correlate curated IOCs with your logs in Splunk, Sentinel and other SIEMs.
TAXII / STIX feeds
Consume or self-host feeds over the open TAXII 2.1 standard.
Threat Lookup
Investigate any indicator with MITRE ATT&CK mapping and a malicious score.
Frequently asked questions about threat intelligence feeds
What is a threat intelligence feed?
A threat intelligence feed is a continuously updated list of indicators of compromise, such as malicious IP addresses, domains and URLs, that your security tools use to block known-bad traffic automatically.
What are the best threat intelligence feeds?
The most useful feeds are curated from many independent sources, refreshed frequently and low on false positives. Q-Feeds combines commercial, OSINT and governmental intelligence and refreshes every 20 minutes.
Are there free threat intelligence feeds?
Yes. The Q-Feeds Community edition is free and lets you test our IP, URL and domain feeds before upgrading to Plus or Premium for faster, premium intelligence.
How do I integrate a threat feed?
You point your firewall, SIEM or DNS filter at your personal Q-Feeds feed URL, or consume it over TAXII/STIX 2.1. Our knowledge base has step-by-step guides for each platform.
What is the difference between IP, URL and domain feeds?
IP feeds block traffic to malicious hosts, URL feeds block harmful links in a web filter, and domain feeds block bad domains at DNS resolution. Most organisations use all three together.
How often are the feeds updated?
Premium feeds refresh every 20 minutes, so your tools always enforce current intelligence without any manual updates.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access