Optimize threat intelligence feeds by filtering and enhancing objects before they're delivered to your workspace

Mitul Admin 0 Reputation points
2025-06-16T10:54:00.3533333+00:00

We would like to optimize Threat intelligence feed as it spikes esteems as we have setup daily cap of 4gb ingestion.

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 1,935 Reputation points Microsoft Employee
    2025-06-17T10:47:28.0866667+00:00

    Hi Mitul Admin,

    Are you ingesting the threat intelligence feeds directly, or using a solution that filters out false positives? In my experience, both free and paid feeds tend to generate a high number of false positives. This is largely due to the nature of indicators like URLs and IPs, they’re often short-lived, can be quickly burned, and may rotate back into legitimate use.

    If you're primarily using these feeds for enrichment rather than detection, your current setup should be fine. However, if you're running detections without any filtering, you might experience a flood of alerts depending on how your queries are written.

    You can also review - Microsoft Sentinel to STIX/TAXII threat intelligence feeds

    If you find the answer above helpful, please "Accept the answer" to help anyone in the community who might have a similar question to quickly find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.