Guide

Threat Intelligence Feed: What Should Be Included?

Learn what a threat intelligence feed should include, how analysts use it, and what to look for in indicator quality, context, and export formats.

Published 2026-10-05

A threat intelligence feed should include more than a list of indicators. This guide explains what a threat intelligence feed should contain and gives a practical checklist for analysts evaluating feeds for CTI platforms.

If you import records into a TIP, SIEM, or case-management workflow, you need data you can act on, not just volume. The real value comes from indicator coverage, confidence scoring, context, actor linking, export format, and provenance.

Active Defense runs AI decoy personas that keep scammers talking on Telegram and by e-mail and turns what they hand over into a threat-intelligence feed. Later sections will also point to weekly scam briefings and monthly scam data reports as supporting material for evaluation.

The core elements every threat intelligence feed should contain

A usable feed starts with indicators in formats analysts can action, deduplicate, enrich, and route into existing workflows. If a record cannot be matched cleanly inside a TIP, SIEM, or case-management process, it adds review time without adding much investigative value.

For scam-led investigations and abuse tracking, the core indicator families should include:

  • crypto wallets
  • bank details
  • phone numbers
  • messenger accounts
  • links
  • gift cards
  • payment handles
  • file and photo hashes

Breadth matters because scam operations move fast between channels and payment methods. A feed limited to domains or IPs can miss the parts of the operation analysts actually need to trace: where money is collected, which contact points are reused, and which lure assets appear again in later conversations. That is also why weekly scam briefings and monthly scam data reports can help teams see how varied scam infrastructure looks in practice.

Each indicator family serves a different defensive purpose. Wallets point to payment collection. Bank details show transfer destinations. Phone numbers and messenger accounts identify contact points used to continue or restart a scam. Links capture lure destinations and related infrastructure. Gift cards and payment handles show alternative cash-out paths. File and photo hashes help analysts find reused media and files across cases.

Good feeds also normalize fields so records can be matched consistently inside a CTI platform. That means the same type of observable should arrive in a predictable structure rather than as raw text copied from a chat.

Most important, inclusion should be driven by operational relevance, not raw count. Analysts need fields they can pivot on during triage and investigations. That is the standard a feed sample or pilot should be measured against.

Quality matters as much as coverage

A threat intelligence feed is only as useful as the analyst’s confidence in each record. Broad coverage helps, but if every extracted item arrives with the same weight, teams have to do too much manual sorting before they can decide what belongs in detections, blocking, or watchlists.

That is why a feed should score confidence per indicator. In practice, confidence scoring lets analysts:

  • filter noisy records
  • prioritize higher-confidence items for faster action
  • apply tiered handling in downstream systems
  • separate review queues from enforcement inputs

In Active Defense, each extracted indicator is scored with a confidence score. That score combines a structural check and an LLM assessment. The result is more useful than undifferentiated raw text copied from a conversation, because analysts can make more deliberate decisions about what to enrich, what to monitor, and what to escalate.

This matters especially in scam-led workflows, where a single chat may contain several different data types and not every extracted string should be treated the same way. A wallet, phone number, payment handle, or bank detail with a score is easier to route than a flat transcript with no assessment attached.

Provenance matters too. Every message is stored the moment it arrives, so the original source record is preserved even if the scammer later uses "delete for everyone." That durable history gives analysts something to review when a record needs validation, context, or reconstruction later.

For CTI teams, that preservation supports trust in the feed over time. It also makes the data easier to revisit as methods change, as records are rechecked against weekly scam briefings, or as analysts compare patterns with monthly scam data reports.

Context turns indicators into intelligence

A threat intelligence feed becomes more useful when it adds context around each observable. Analysts do not just need isolated wallets, phone numbers, links, or hashes. They need enough surrounding structure to understand why an item matters, how it was used, and how it fits into an actor’s workflow.

One of the most useful forms of context is relationship mapping. When chats share an indicator, a reused photo, or a forwarded account, those sessions can be linked to one actor. That turns a flat list of observables into something analysts can cluster and investigate as related activity rather than as separate records.

Operationally, actor-level linking helps teams:

  • group related sessions into one investigation
  • reduce duplicate cases
  • spot repeated tradecraft across conversations
  • see when several chats belong to the same scam operation

Photo and file reuse are especially strong pivots in scam investigations. The same lure assets often appear across many conversations, even when contact points or payment requests change. A feed that captures those relationships helps analysts move from single observables to campaign structure without exposing victim data or depending on isolated anecdotes. The weekly scam briefings and monthly scam data reports can also help teams compare those patterns over time.

This is also why rebuildability matters. As clustering logic improves, analysts may want to revisit older records and re-link activity that was not obvious at first. Feeds are more useful when they can be rebuilt from stored history instead of treated as disposable snapshots.

In Active Defense, each customer gets their own feed with STIX 2.1 export, which makes the data easier to ingest into standard CTI tooling.

Collection method affects what ends up in the feed

A threat intelligence feed reflects how the data was gathered. For analysts importing a threat intelligence feed into a CTI platform, collection method affects timeliness, context, and whether records are tied to a real exchange or just copied from elsewhere.

Active Defense collects through AI decoy personas that engage scammers on Telegram and by e-mail. The feed is built from what scammers send during those conversations, not from broad scraping. That changes the kind of records analysts receive.

In this model, scammers may reveal:

  • payment destinations
  • bank details
  • contact accounts
  • links
  • gift cards and payment handles
  • files, voice messages, and photos

That source matters because the feed keeps the surrounding interaction. Every message is stored the moment it arrives, so a later "delete for everyone" does not remove the copy used for review or export. Replies are drafted by AI and approved by a human operator by default before they are sent.

For teams evaluating source quality, weekly scam briefings show examples of patterns seen in live conversations, while monthly scam data reports help compare those patterns over time.

Operational details can matter too. The console and API run on Azure in Germany. If you want to inspect the feed structure before onboarding it, the home page covers evaluation options, including a free feed sample for qualified leads and a 90-day pilot for up to 1,000 sessions at a fixed price.

How analysts should evaluate a feed before onboarding it

Before onboarding any threat intelligence feed, use a checklist. Ask whether the data fits your ingestion format, your triage process, and the pivots your investigators actually use. A feed that looks rich in a demo can still create friction if records do not map cleanly into your existing workflow.

Start with sample records, not headline volume. Review whether each record gives you enough to work with:

  • complete fields
  • confidence scoring
  • normalized values
  • usable context
  • actor-linking value

That matters more than raw record count. Analysts need records they can search, compare, suppress, and escalate without rebuilding the source by hand.

It is also worth checking export format early. If the feed supports a standard export that maps cleanly into your CTI platform, onboarding gets simpler. In this case, STIX 2.1 is the relevant example to ask for because it is already part of the feed design described above.

Then test the workflow in practice. From a single record, how fast can your team search related indicators, pivot to linked activity, suppress duplicates, and open an investigation?

If you want to evaluate that directly, Active Defense offers a free feed sample and pilot for qualified leads, and there is a 90-day pilot for up to 1,000 sessions at a fixed price. For added evaluation context, review weekly scam briefings and monthly scam data reports to see live scam patterns and summary views alongside the feed itself.

Questions analysts ask about a threat intelligence feed

Can I trace an indicator back to the original scam message?

Analysts often need to review the source message behind an extracted record before they promote it into detections, casework, or watchlists. A feed is easier to trust when the underlying message history is preserved at receipt, rather than kept only as a summary or export artifact.

That matters in scam investigations because the sender may later remove content inside the chat. If the collection system stores each message when it arrives, the review trail remains intact for later analysis.

Does the feed support media and file pivots, not just text observables?

Many scam cases hinge on reused assets. A useful feed should let analysts pivot on more than text fields alone.

Look for support such as:

  • file hashes
  • photo hashes
  • links between chats that reuse the same photo
  • links between chats that reuse forwarded accounts

Those pivots help when lure images, attachments, or account handoffs recur across separate conversations. For examples of how those patterns show up, review the weekly scam briefings.

How is the feed delivered for one team versus another?

Feed design affects downstream handling. In Active Defense, each customer gets their own feed with STIX 2.1 export, so one team’s ingestion and review flow stays separate from another’s.

Teams that want to inspect field structure before onboarding can request a free feed sample or pilot.

What other material helps validate a feed before import?

Sample records are the first step, but many analysts also want a broader view of what the feed captures over time. The monthly scam data reports can help with that by giving a recurring summary to compare with sample feed data.

A useful feed should help analysts act, not just collect

A strong threat intelligence feed combines:

  • indicator breadth
  • confidence scoring
  • preserved source history
  • relationship mapping
  • a usable export format

That is what makes records easier to triage, pivot on, and move into casework. To assess that in practice, analysts can review the sample feed or pilot from Active Defense via the home page.

Get these indicators as a feed

Active Defense keeps scammers talking with AI decoys and turns what they hand over into a feed of scored indicators with STIX 2.1 export.