Which threat intelligence feeds actually earn their keep

DCDaniel C. · Head of Security Operations
Threat Intelligence·9 min read

Renewal prep, last quarter: four feed subscriptions, six figures across the set. I ran the test I run on every vendor line and named one decision each feed changed in ninety days. Two cleared the bar; I cut the other two.

Which threat intelligence feeds actually earn their keep

Renewal prep, last quarter. I pulled the threat intelligence line: four feed subscriptions, mid five figures on the cheapest, six figures across the set. Then I ran the exercise I run on every vendor line, which is naming one decision each of these changed in the last ninety days. Two cleared it, one with a detection we shipped and one with a block that fired during a live intrusion attempt. The other two had been piping indicators into a security information and event management (SIEM) index that, when I checked the query logs, nobody had queried since March.

I kept two and cut two, and the sorting logic fits on an index card. A feed earns its keep when it clears the relevance, timeliness, and workflow tests below. In renewal reviews, I often see feeds fail all three at once.

In Brief:

  • A threat intelligence feed is a data subscription; the thing worth paying for is a decision reached earlier, or with more confidence, than your own telemetry allows.
  • In renewal reviews, feeds often fail because they miss one or more of those tests.
  • Premium feeds can barely overlap with each other or with free sources, so stacking subscriptions widens coverage far less than the invoices suggest.
  • For many mid-market security operations centers (SOCs), a sector information sharing and analysis center (ISAC) seat plus the intelligence already bundled with the endpoint detection and response (EDR) and SIEM is the place to start before buying a second premium contract.

What a threat intelligence feed is actually paying for

The textbook definition: a machine-readable stream of indicators, Internet Protocol (IP) addresses, domains, hashes, sometimes tactics, techniques, and procedures (TTPs), delivered on a schedule. That's true and useless, because the stream is only the delivery mechanism. A cyber threat intelligence (CTI) program can be valued in principle while failing to drive decisions anyone can name. Left unchecked, a program runs on perceived value rather than demonstrated value, and renewal exposes the difference.

The subscription buys a decision your team reaches sooner or with more confidence: patch this edge device tonight or block this infrastructure before it shows up in your own telemetry. When I audit our own spend, I ask what we did because of it. A feed nobody wired to anything is a data hoard with an invoice attached.

Most feeds fail the same three tests

I use the same tests in every renewal call because a feed can look useful in a vendor demo and still fail once it meets your telemetry.

Relevance to your sector and your stack, or it's someone else's threat

Feeds barely overlap. Premium vendors often overlap on only a small fraction of indicators, even for threat actors both claim to track, and the overlap with large open blocklists can be smaller still. Vendors pitch that as a reason to buy more feeds. I read it the other way: each feed is a narrow window shaped by where that vendor's collection infrastructure sits, and the only window worth paying for is the one facing your vertical and your technology.

Relevance to stack is the half I see buyers skip. A feed heavy on commodity Windows malware hashes does little for an estate that's mostly SaaS and cloud workloads, the same mismatch I keep finding in cloud-native security tooling. Before renewing, pull a quarter's worth of the feed's indicators and check what fraction could even appear in your telemetry. If most of it describes infrastructure you don't run and actors that don't target your sector, you're paying to monitor someone else's threat model.

Timeliness measured against how fast the indicators decay

Indicators are perishable. Command-and-control (C2) infrastructure commonly burns down within days. Phishing domains often die within hours of going live, and a file hash stops matching the moment the attacker recompiles. The exact window varies by indicator type and threat category, but by the time some indicators of compromise (IOCs) are published, the attacker activity they describe may already have peaked. A feed on that schedule is selling history.

Adversaries have compressed the window further. Exploitation often begins before defenders have a clean patching window. Access-broker handoffs can happen almost immediately, and vulnerability exploitation is now the leading initial-access vector in Verizon's DBIR, at 31% of breaches and rising. So ask the vendor for the median lag between first observation and publication. If they can't answer, assume it's longer than the indicators live.

A live path into a detection or block, or it never changed an outcome

Security operations remains one of the core CTI use cases because useful intelligence has to reach daily defensive workflows. A feed that terminates in a dashboard or a weekly PDF usually has no path to an outcome, and in my experience that's the default state: the integration project that would wire it into blocking or enrichment stays on the roadmap while the invoice auto-renews.

There are two common ways to wire a feed into alerting. Raw indicator matching against logs is the cheap path, but a threat-intel match that pages someone at 3 a.m. is functionally a signature, and it needs signature-grade fidelity that most feeds can't deliver. The better path runs the feed into your detection engineering backlog: analysts turn TTPs and campaign reporting into rules, and every rule is a countable artifact you can trace back to the subscription at renewal.

Where each category of feed earns its budget

I judge feed categories against those tests and against what I've actually paid for each. IOC volume, sector context, finished analysis, and workflow fit are not interchangeable. A feed that wins in one column can still fail the renewal if the workflow around it is wrong.

Premium commercial feeds you pay real money for

Premium contracts earn budget through intelligence: attribution, actor tracking, dark-web visibility, and finished reporting a lean team can't produce internally. These contracts get expensive quickly once scope and seats stack up, so my bar is concrete. A premium feed needs a named owner who turns its reporting into detections and hunt hypotheses, and it needs to map to intelligence requirements we wrote down before the demo. Without that owner, the money buys a nicer inbox.

In my renewal reviews, premium feeds most often fail when the product is undifferentiated IOC volume. If a vendor's primary product is a bulk indicator stream, I expect quantity over quality with minimal context, and I expect the noise cost to land on analysts. One well-scoped premium subscription with an owner beats two without one; given how little vendors overlap, the second contract buys another narrow window on a different slice of the problem.

Sector ISAC and government feeds most SOCs underuse

Dollar for dollar, sector ISACs are often the best line on the sheet for a regulated mid-market company. Entry tiers can be cheap relative to premium commercial contracts. They carry sector context commodity feeds can't replicate: who's being hit in your vertical this week, with what, and what worked. Judge them on that context and the peer sharing, because raw IOC hit rate is the wrong yardstick for this category.

Government feeds need more skepticism. Free government sharing programs can still lack the context a working SOC needs, and participation or funding models can change over time. State and local teams in particular should reprice those lines rather than assume yesterday's economics still hold. A free feed that wastes triage time still costs money.

Community and open-source feeds worth wiring in

The vetted open-source stack is stronger than its price implies. abuse.ch's platforms and ET Open are common starting points because they cover malware and intrusion detection system (IDS) rules without a commercial-feed invoice. AlienVault Open Threat Exchange (OTX) is another frequent source for public-report IOCs. A Malware Information Sharing Platform (MISP) instance can aggregate all of it, and the sharing communities around MISP can give a mid-market SOC a practical collaboration layer. For a mid-market SOC, that stack plus disciplined tuning covers most of what a bulk commercial IOC subscription sells.

Free feeds cost tuning time. Turn on a few at a time and watch false-positive rates for a couple of months before adding more, skip the aggressive versions of blocklists that maintainers warn can generate false positives, and prune dead or stale sources as their status changes. Free feeds fail the same three tests paid ones do; they just fail cheaper.

The feeds already bundled with your EDR and SIEM

Before renewing anything standalone, inventory what you already pay for. Microsoft and CrowdStrike both have threat-intelligence features, connectors, frameworks, or modules that may already be present in your stack depending on licensing. Splunk does too. The mistake I see most is buying standalone feeds before exhausting the intelligence and enrichment paths already sitting inside tools you already own.

Bundled intelligence often has one structural advantage: it's already wired into alert triage and enrichment, which means it passes the third test on day one. I treat its weakness as opacity, since vendors deduplicate and anonymize before delivery, and that makes the bundled layer's real contribution hard to measure. My rule is to exhaust the bundled tier first and make any standalone purchase justify itself against what the stack already provides.

The subscriptions that quietly don't earn their keep

The cuts are rarely dramatic failures. I keep finding feeds piped into indexes nobody queries. I also find SOC-tour dashboards and sources whose net value has gone negative because chasing false positives costs more analyst hours than the threats they surface. That last one compounds, because a noisy feed deepens the alert fatigue you bought tooling to reduce.

There's also a ceiling no freshness service-level agreement (SLA) fixes. Intrusions that run through valid credentials and approved SaaS integrations may generate useful IP-and-hash indicators only after the fact. Living-off-the-land behavior has the same problem. An IP-and-hash subscription can't see that intrusion class no matter how current it is, and that limit belongs in every renewal conversation.

The question that settles a feed at renewal

Every credible approach to CTI value reduces to the same move: measure decisions changed. So at renewal I put one question to whoever owns the feed: name a decision this feed changed last quarter. A shipped detection, a block that fired in production, a hunt it opened, a patch we pulled forward. If the answer is a coverage claim or an indicator count, the feed hasn't earned the line, and the money moves to an ISAC seat or detection engineering hours that will.

I asked that question four times this cycle and cut two subscriptions on the answers. Three months on, nobody has asked where they went. That is the signal I trust at renewal.

Frequently asked questions about threat intelligence feeds

How do you measure whether a threat intelligence feed is worth the money?

Count outcomes. Include detections deployed from the feed's reporting and matches in your telemetry confirmed as true positives, and give extra weight to blocks or patches it triggered. Compare each feed's unique contribution against what your bundled tooling and free sources already provide. A feed that can't show a changed decision within a quarter is a cut candidate.

How long do threat intelligence indicators stay valid?

It varies by type, but decay is fast across the board. C2 IP infrastructure often lives only days, phishing domains frequently die within hours, and file hashes stop matching as soon as the malware is recompiled. That's why a feed's publication lag matters as much as its content, and why decay rules exist to expire stale IOCs automatically.

Should threat intel feeds go straight into SIEM alerting?

Generally no. A raw threat-intel match in alerting behaves like a signature, and most feed indicators lack the fidelity to page a human without a heavy false-positive tax. Route feeds into enrichment and the detection engineering process instead, and reserve direct alerting for a small set of high-confidence, well-curated sources.

Are free threat intelligence feeds good enough for a mid-market SOC?

abuse.ch and ET Open are vetted, actively maintained sources used by commercial vendors themselves, and OTX belongs in that same free indicator set. Free sources rarely provide attribution, finished analysis, or sector-specific context, which is where paid ISAC or premium spend belongs. Free sources cost tuning discipline.

Is a sector ISAC membership worth the cost?

For regulated verticals, usually, and entry tiers are cheap relative to premium contracts. Judge an ISAC on sector context and peer sharing rather than raw indicator hit rate. Treat it as one input in a broader intelligence program.


About the author

DCDaniel C. is a security operations leader with over a decade of experience building and scaling SOC capabilities for cloud-native companies. He has led security teams through multiple stages of growth — from early-stage environments with minimal tooling to mature organizations operating 24/7 security operations with distributed teams. His experience includes designing SOC architectures, evaluating and managing MDR providers, and building internal detection and response capabilities. Daniel has been responsible for vendor selection across SIEM, EDR, and XDR platforms, as well as defining SLAs, response models, and escalation frameworks. He has also worked closely with executive leadership on budgeting, board reporting, and aligning security operations with broader business risk. He writes about the practical decisions security leaders face — including build vs buy tradeoffs, how to evaluate security vendors, and what it actually takes to run an effective security operations function at scale

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Which threat intelligence feeds actually earn their keep | Future of SecOps