Cyber intelligence feeds give analysts structured scam indicators they can import, score, search, and link inside a CTI platform. People looking for cyber intelligence feeds usually want three things: what the feed contains, how the data is collected, and whether it arrives with enough context to use in operations.
This article uses Active Defense as the example. It runs AI decoy personas on Telegram and by e-mail, keeps scammers talking, and turns what they send into a feed for each customer.
It also points to weekly scam briefings from live conversations, explains what a threat-intelligence feed should include, and shows why scammers’ crypto wallets matter to fraud teams.
What threat-intelligence analysts expect from cyber intelligence feeds
Cyber intelligence feeds are structured collections of indicators plus the context needed to use them inside CTI platforms, enrichment pipelines, case management, and detection workflows. Analysts do not just want raw artifacts. They need data that can be searched, triaged, linked, and moved into existing processes without losing meaning.
In scam investigations, that usually means looking beyond domains and IPs. The infrastructure that matters often includes:
- crypto wallets
- bank details
- phone numbers
- e-mail addresses
- messenger accounts
- gift cards
- payment handles
- file hashes
- image hashes
What makes a feed useful is not volume alone. Analysts want to know what the indicator is, where it came from, how recent it is, how confident the provider is, and which other indicators seem connected to the same activity. Without that structure and context, a large feed can create more review work than operational value.
This matters even more for scams because the activity often moves across channels. A single operation may shift between e-mail, Telegram, payment requests, forwarded accounts, and reused images. So a useful feed should reflect the artifacts scammers actually hand over in conversations, not only infrastructure seen from outside.
That leads to the practical questions for the rest of this article: how the provider collects the data, how indicators are extracted and scored, how related chats are linked, and how the feed is delivered into analyst tooling.
How Active Defense collects scam indicators from live conversations
Active Defense collects scam indicators from live conversations by running AI decoy personas that keep scammers engaged on Telegram and by e-mail, then turning the artifacts those scammers send into a customer-specific intelligence feed. For analysts, that matters because the feed comes from direct interaction with scam operators rather than from passive monitoring alone.
From those conversations, the system extracts indicators including:
- crypto wallets for BTC, ETH, TRON, and SOL
- URLs
- e-mail addresses
- phone numbers
- messenger accounts
- bank details, including IBAN and SWIFT
- gift cards
- payment handles
- file hashes
- photo hashes
Conversation handling is supervised by default. Every reply sent to a scammer is drafted by AI and approved by a human operator before it is sent. Replies are also sent with typing pauses and in short messages, which helps maintain a natural conversation flow.
Collection quality also depends on what is preserved. Every incoming message is stored event-sourced the moment it arrives. If a scammer later uses "delete for everyone," the stored copy remains available for reconstruction from the recorded history. That is useful for analysts who need traceability across a full exchange rather than only what remains visible in a chat client.
Media handling follows the same approach. Photos, voice messages, and files are retained by SHA-256, and photos are also retained with a perceptual hash. In practice, that gives analysts both exact-match and near-match ways to track reused media across scam activity.
At first contact, a classifier checks each new chat. On messengers, if it is unsure, the chat is left alone. Taken together, this collection model produces scam indicators from live engagement and preserves the source material needed to review, reconstruct, and analyze what scammers actually sent.
What makes a scam-indicator feed usable in a CTI platform
A scam-indicator feed is usable in a CTI platform when the data arrives ready for analyst decisions, not cleanup. That means stable indicator types, clear confidence handling, and enough structure to support correlation rules, watchlists, and case views.
For scam work, the useful fields are often payment, contact, and media artifacts rather than only technical infrastructure. Analysts typically need to work with:
- crypto wallets
- bank details
- phone numbers
- e-mail addresses
- messenger accounts
- gift cards
- payment handles
- file hashes
- photo hashes
The feed also needs evidence preservation. In Active Defense, every message is stored the moment it arrives, so later chat deletion by the scammer does not remove the recorded copy. That matters when analysts need to review source material, compare earlier and later versions of a conversation, or explain why an indicator entered a case.
Media handling changes usability too. Photos, voice messages, and files are kept by SHA-256, and photos also get a perceptual hash. That supports both exact matches and reuse checks across scam cases.
Another requirement is a relationship model that helps analysts pivot. When chats share an indicator, a reused photo, or a forwarded account, Active Defense links them to one actor. That lets teams investigate clusters of activity instead of treating each artifact as unrelated.
Finally, the feed should fit import and schema work over time. Each customer gets their own feed with STIX 2.1 export, and the stored history means it can be rebuilt later. For teams mapping fields into CTI tooling, representing scam artifacts in STIX 2.1 is part of what makes the feed practical.
How STIX 2.1 export helps analysts operationalize the feed
For teams evaluating cyber intelligence feeds, STIX 2.1 export is mainly about operational fit. Analysts need a format their CTI platform can ingest without stripping out the fields that matter for scam work.
In this feed, each customer gets their own STIX 2.1 export. That gives analysts a structured handoff for the indicators collected from scam conversations and for the context attached to them.
What matters in practice is that the export supports common analyst tasks:
- loading indicators into a CTI platform
- keeping confidence scores with each item
- preserving links between related records
- reimporting data after parser or schema changes
That last point is useful because the feed can be rebuilt from stored history. If a team changes mappings, needs to backfill older data, or wants to rerun an import, the export does not depend only on what is still visible in a chat client.
For scam analysis, relationship data is part of the value. When chats share an indicator, a reused photo, or a forwarded account, they are linked to one actor. In a CTI platform, that gives analysts a way to work from grouped activity instead of a flat list of artifacts.
If you want a schema-level view of how STIX 2.1 fits scam-indicator feeds, that guide goes deeper into representation choices for this kind of data.
How to evaluate a scam-focused cyber intelligence feed before a pilot
A pilot should answer one question: will this cyber intelligence feed reduce analyst work after import, not create more of it. For a scam-focused feed, review the sample as an ingestion test, not just a content preview.
Check these points first:
- whether the feed is customer-specific
- whether STIX 2.1 export matches your CTI platform intake
- whether confidence scores are present on each indicator
- whether related records stay linked as one actor
- whether stored history supports rebuilds after mapping changes
- whether your team is comfortable with the review model
For Active Defense, the operating details matter during that review. The feed is customer-specific. It includes STIX 2.1 export. Stored history means the feed can be rebuilt later. The console and API run on Azure in Germany. Replies to scammers are drafted by AI and approved by a human operator by default.
Use the free feed sample for qualified leads to inspect field structure, confidence handling, and whether linked records survive the trip into your platform. Then use the 90-day pilot for up to 1,000 sessions at a fixed price to test workflow fit with live intake, triage, and correlation. If you need a checklist for platform fit, compare it against your CTI software requirements.
Questions analysts ask about scam-focused cyber intelligence feeds
Will the feed fit a CTI platform without custom cleanup?
Analysts usually want a feed they can load as structured data, not a spreadsheet of loose artifacts. For scam work, that means fields should stay consistent across payment, contact, and media indicators, with enough context to support search, triage, and correlation after import.
A useful review point is whether the feed arrives as:
- customer-specific data
- structured indicators with confidence scores
- linked records that preserve actor-level relationships
- STIX 2.1 export for platform intake
How much source evidence stays attached to an indicator?
Scam indicators are more useful when analysts can trace them back to what the scammer actually sent. Active Defense stores each incoming message the moment it arrives. If a scammer later uses "delete for everyone," that does not remove the stored copy.
For investigations, that helps when a team needs to revisit the original exchange, review the source behind an indicator, or rebuild data from preserved history.
Does the feed help with media reuse and scam-account overlap?
Yes, if the provider keeps media and account artifacts in a form that can be compared across chats. Active Defense retains photos, voice messages, and files by SHA-256, and photos also with a perceptual hash.
That gives analysts more than exact file matching. It also supports checks for reused photos, repeated files, and overlap between chats tied together by forwarded accounts or shared artifacts.
How is scammer engagement handled before data reaches the feed?
Collection method matters because it shapes what enters the feed. Active Defense runs AI decoy personas on Telegram and by e-mail. Replies are drafted by AI and approved by a human operator by default before they are sent.
At first contact, a classifier checks each new chat. On messengers, if it is unsure, the chat is left alone.
Turn scam conversations into usable intelligence
For scam investigations, useful cyber intelligence feeds do more than list artifacts. They give analysts structured, relevant indicators with confidence and relationship context, so the data can move into triage, search, enrichment, and case workflows without losing meaning.
Active Defense takes that approach by engaging scammers on Telegram and by e-mail, extracting and scoring scam indicators, linking related chats to one actor, and delivering a customer-specific feed with STIX 2.1 export.
If you are assessing fit for your team, the next steps are practical:
- review the home page for the free feed sample for qualified leads
- look at the 90-day pilot for up to 1,000 sessions at a fixed price
- use the sample to compare structure, scoring, and relationship data against your CTI workflow
For broader trend-level context, you can also read the monthly scam data reports.