logo

Why The Hate for Threat Intelligence Feeds?

ID: 195a2ef6-9877-5965-bcba-d931de73a0da

STIX ID: report--195a2ef6-9877-5965-bcba-d931de73a0da

Feed Name: Black Hills Infosec Blog

Date Published: 2016-01-26

Date Updated: 2026-04-27

Author: BHIS

...
...

This editorial critiques the practical value of commercial threat intelligence feeds, asserting they function like ineffective blacklists with minimal overlap and limited applicability to targeted attacks, as reflected by cited Verizon DBIR statistics (3% feed overlap; 70–90% unique malware per organization). The author recommends investing in internal threat intelligence and peer sharing, and focusing detection on enduring adversary behaviors—persistence, command-and-control, and lateral movement—highlighting common techniques (e.g., SMB pivoting, token impersonation, pass-the-hash, password spraying) and tools like Microsoft Advanced Threat Analytics as more reliable defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.