Skip to main content

Which threat intelligence source should i use and what happens if i use multiple threat intelligence sources.

Hi Rupsan,

You can use multiple Threat Feeds in LogPoint, either Open Source (like MISP or a TAXII feed) or Proprietary (such as RecordedFuture, ProofPoint, CSIS). When you use multiple threat feeds,  fields like the source_ip or destination_ip from your sources may find a match with one or the other threat feeds and get enriched. 

However, it is advised to use few feeds that you are very fond of since such feeds add some performanceoverhead while fetching data. You may look into the data from table threat_intelligence and decide which feed provide you the most value and decide accordingly.

 


Reply