Hi Mitul Admin,
Are you ingesting the threat intelligence feeds directly, or using a solution that filters out false positives? In my experience, both free and paid feeds tend to generate a high number of false positives. This is largely due to the nature of indicators like URLs and IPs, they’re often short-lived, can be quickly burned, and may rotate back into legitimate use.
If you're primarily using these feeds for enrichment rather than detection, your current setup should be fine. However, if you're running detections without any filtering, you might experience a flood of alerts depending on how your queries are written.
You can also review - Microsoft Sentinel to STIX/TAXII threat intelligence feeds
If you find the answer above helpful, please "Accept the answer" to help anyone in the community who might have a similar question to quickly find the solution.