Open source threat intelligence: what's usable, what's noise

DCDaniel C. · Head of Security Operations
Threat Intelligence·8 min read

Open-source threat intelligence is worth using when it produces measurable incremental value. It's noise when it adds stale, duplicated, low-confidence indicators that raise alert volume without changing an outcome. Here's the six-measure test I run before renewing, adding, or automating any feed.

Open source threat intelligence is worth using when it produces measurable incremental value: confirmed detections you would otherwise miss, earlier detection of real activity, or context that reduces investigation time. It's noise when it adds stale, duplicated, low-confidence indicators that raise alert volume without changing an outcome.

Before you renew, add, or automate a feed, evaluate it in shadow mode against six measures: incremental detections, time advantage, precision, analyst cost, data reliability, and handling constraints. Feed volume and raw indicator uniqueness are diagnostic signals, not proof of value.

In one study of open CTI feeds, indicators were listed an average of 21 days after becoming active, and a separate study found only 2.5%–4.0% overlap between two commercial vendors' indicators for 22 threat actors both claimed to track. Neither finding proves every feed is late or redundant; they show why you test your own stack rather than buy on volume.

In brief:

  • A feed's value comes from incremental detections, timing advantage, precision, and context, not from indicator volume or uniqueness alone.
  • Overlap across open feeds runs low in the research that's measured it, but low overlap doesn't prove unique indicators are noise. It means you have to check what that uniqueness actually catches.
  • Connector health determines what you're even measuring. Authentication changes, deprecated endpoints, and empty datasets can silently zero out a feed's contribution before it ever reaches a scoring exercise.
  • Commercial feeds face the same coverage and overlap problems as open ones; the difference customers pay for is curation and analyst time, not automatically better accuracy.

The decision rule: what qualifies as usable intelligence

A feed earns its slot when it clears one of five bars: earlier detection than another source, even without being unique; a high-confidence prevention control like a narrowly scoped netblock list; attribution or enrichment that shortens investigation time; support for retrospective hunting even without triggering the original alert; or coverage of a threat model your evaluation window didn't happen to test.

Uniqueness by itself proves none of this. A unique match can be a correct detection or an erroneous one, and low overlap between feeds is a property of the ecosystem, not a verdict on quality.

The six measures that replace a binary keep-or-cut test

Score every feed on a net-value basis: incremental incident impact, plus time-to-detect benefit, plus enrichment benefit, minus false-positive cost, maintenance cost, and handling risk. You don't need to force this into a dollar figure, but the framework below turns it into six answerable questions.

Measure

The question to answer

Incremental detection

Which confirmed incidents would this source have caught that your existing controls didn't?

Time advantage

For incidents detected elsewhere, how much sooner did this source surface usable evidence?

Precision

Of the feed-attributed matches you reviewed, how many were true positive, benign, indeterminate, or untriaged?

Operational cost

How many alerts, analyst minutes, tickets, and rule-maintenance hours did it generate?

Reliability

What share of scheduled pulls succeeded, delivered current data, and passed a schema and volume check?

Handling

Are license, TLP, privacy, retention, and redistribution terms compatible with how you intend to use it?

What the research can, and can't, tell you

Studies of selected open and commercial feeds found low overlap in the populations they studied. Griffioen, Booij, and Doerr measured 24 open source feeds over 14 months and found only 6.2% of indicators reappeared on a second feed. Bouwman et al.'s USENIX study of two commercial vendors found an average overlap of just 2.5% to 4.0% across 22 shared threat actors, with overlaps showing up in the other vendor's feed roughly a month later.

Neither result generalizes cleanly. They describe the specific feeds and vendors studied, not every feed you might run, and low overlap doesn't establish that unique indicators are noise. It establishes that you can't assume a second feed is corroborating the first, so you have to measure what each one actually catches. Extreme uniqueness is a reason to investigate a feed's precision and provenance, not proof of poor precision on its own.

Timeliness, and why hashes age differently than IPs

Griffioen et al. also found indicators were listed an average of 21 days after they became active, with most already active for at least 20 days before listing. Indicators commonly arrive after infrastructure has already been active for days or weeks in the feeds these studies measured, so validate timeliness by indicator type and use case before relying on a feed for prevention rather than retrospective work.

Hashes are a specific case: precise but fragile against repacking, so a hash can go stale for prevention while still earning its keep in retrospective search. David Bianco's Pyramid of Pain is the right frame: responding at the level of tactics, techniques, and procedures forces adversaries "to do the most time-consuming thing possible: learn new behaviors." That's a reason to weight TTP-level detection higher, not a claim that hash and IP feeds are worthless.

Audit connector health before you trust any score

A broken connector can leave ingestion incomplete without producing an obvious error: authentication requirements change, integrations lag, once-useful datasets go empty, and endpoints get deprecated, all silently. Connector audits routinely turn up expired credentials, deprecated endpoints, or datasets that have quietly stopped returning content, and a feed that returns nothing generates no alerts to complain about, so nobody notices until someone checks.

What holds up under the six-measure test still needs the right handling. Spamhaus DROP suits high-confidence network ranges, appropriate for enforcement after your own change-control testing rather than as an automatic blocklist. ThreatFox removes indicators of compromise (IOCs) older than six months, citing false-positive risk from reassigned cloud infrastructure. A source with no expiry signal shifts lifetime-management work onto your team.

Commercial feeds face the same coverage problem, priced differently

I have approved renewals on the assumption that more paid sources meant more coverage. A closer review showed otherwise: the USENIX study above found two market-leading vendors overlapped by only 2.5% to 4.0% on shared threat actors, with matches appearing in the second feed about a month later. That's not evidence commercial intelligence is unreliable; it's evidence "commercial" doesn't automatically mean "comprehensive" or "faster."

A smaller feed can reduce alert volume, but volume alone doesn't establish accuracy or coverage. It may just mean fewer analyst hours triaging, a real benefit but a different claim. Teams need both commercial intelligence and internal threat-tracking capability. The honest case for paying is enrichment depth and reduced analyst hours, harder to replicate in open source at scale. A pitch deck leading with volume alone isn't establishing coverage, timeliness, or accuracy.

Run every feed through a shadow-mode evaluation, not a before-and-after

Baselining mean time to detect before and after turning on a feed is a weak design, since attacker activity, telemetry, and staffing all shift underneath the comparison at once. Run the feed in shadow mode instead: compare its attributed alerts against existing detections over a fixed period, label outcomes, and measure incremental true positives, time advantage, false-positive burden, and reliability directly.

Basic hygiene closes part of this gap before scoring starts. MISP warninglists flag known-good or commonly misleading values, like public domain name system (DNS) resolvers and certain well-known domains, before they generate noisy matches. MISP's decaying models let you define indicator lifetimes and exclude decayed attributes, with refresh behavior configured to your workflow, not assumed. Treat each feed as a line item that defends itself or gets cut.

The renewal decision

For every feed, land on one of four calls: retain, tune scope or confidence thresholds, demote to enrichment and hunting rather than automated blocking, or remove it. This week, pull the list of every source flowing into your security information and event management (SIEM) system, and treat each one as a line item in your next threat intelligence renewal.

Connector audits routinely find sources that have gone quietly empty or duplicative long before anyone reviews the contract. Free data that clogs your queue was never free.

Frequently asked questions about open source threat intelligence

What are the best open source threat intelligence feeds for specific use cases?

Match the feed to the use case rather than picking a single best option. Spamhaus DROP suits high-confidence network blocking after your own testing. ET Open supplies IDS rules. The abuse.ch suite covers malicious URLs and malware with indicator enrichment. AlienVault OTX works as a broad community intelligence source. Confirm that any selected feed is active, its authentication is current, and its dataset is actually returning content before making it load-bearing.

Should you block directly on open source threat feeds?

Rarely, and only on high-confidence curated lists built for that purpose, after your own change-control testing. Raw IP and domain feeds can produce shared-infrastructure false positives, since an address can carry both malicious and benign activity and still be unsuitable for automatic blocking. Lower-confidence or incident-specific IOC collections work better as watchlists for monitoring and investigation than as blocking rules.

How long should IOCs stay active before you expire them?

There's no universal retention period. Set expiration by indicator type, source confidence, sightings, infrastructure volatility, and the cost of a false match. ThreatFox, for example, expires IOCs older than six months specifically because of false-positive risk from reassigned cloud infrastructure. Keep aged IOCs available for retrospective hunting even after you stop using them for real-time detection.

Is commercial threat intelligence more accurate than open source?

Not automatically. Commercial and open source intelligence both vary in accuracy, and a 2020 study of two market-leading vendors found only 2.5% to 4.0% overlap across the 22 threat actors both claimed to track. What buyers call "more accurate" commercial feeds often reflects smaller, curated sets producing fewer absolute alerts, not necessarily better coverage. The commercial value case is enrichment depth and analyst-hour savings, not automatically better indicators.


About the author

DCDaniel C. is a security operations leader with over a decade of experience building and scaling SOC capabilities for cloud-native companies. He has led security teams through multiple stages of growth — from early-stage environments with minimal tooling to mature organizations operating 24/7 security operations with distributed teams. His experience includes designing SOC architectures, evaluating and managing MDR providers, and building internal detection and response capabilities. Daniel has been responsible for vendor selection across SIEM, EDR, and XDR platforms, as well as defining SLAs, response models, and escalation frameworks. He has also worked closely with executive leadership on budgeting, board reporting, and aligning security operations with broader business risk. He writes about the practical decisions security leaders face — including build vs buy tradeoffs, how to evaluate security vendors, and what it actually takes to run an effective security operations function at scale

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Open source threat intelligence: what's usable, what's noise | Future of SecOps