# What is a Threat Intelligence Feed?

> A threat intelligence feed is a machine-readable stream of indicators, observations, or reports from external or internal sources, consumed into security tools to inform detection and blocking.

- Canonical URL: https://yellowcube.eu/glossary/threat-intelligence-feed/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Feeds may deliver indicators of compromise, attacker infrastructure, vulnerability information, tactic and technique mappings, or finished analyst reports. Formats and transports vary; quality depends on source collection, timeliness, confidence scoring, expiration handling, and how well the data fits the consumer’s environment.

### Key points

- **Evaluation before enabling:** Check source credibility, update cadence, false-positive history, overlap with other feeds, and what each indicator actually asserts.
- **Consumption with context:** Match feed items to local telemetry, asset criticality, and confidence thresholds rather than blocking on raw indicators alone.
- **Important limitation:** A feed is input, not judgment. Stale, low-confidence, or irrelevant indicators can create false positives, missed detections, or a false sense of coverage.

### Related terms

[Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Threat intelligence platform (TIP)](<https://yellowcube.eu/glossary/threat-intelligence-platform/>) · [Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/>) · [Security information and event management (SIEM)](<https://yellowcube.eu/glossary/security-information-and-event-management/>) · [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Open-source intelligence (OSINT)](<https://yellowcube.eu/glossary/open-source-intelligence/>) · [STIX and TAXII](<https://yellowcube.eu/glossary/stix-and-taxii/>)

### Sources

[NIST SP 800-150, Guide to Cyber Threat Information Sharing](https://csrc.nist.gov/pubs/sp/800/150/final) · [MITRE ATT&CK](https://attack.mitre.org/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

