Threat intelligence feeds: IOCs that meet your assets
Dual-Strike XISEM Threat Intelligence integrations ingest IOC feeds (hashes, domains, IPs, URLs) and match them against agent harvests, DNS logs, browsing sessions, and EDR exports. Matches elevate in Threat Center and can trigger COBRA² rules.
Route: Settings → Threat Intelligence · Support wiki → Threat intelligence feeds
Feed types
• Commercial TI — Partner feeds via API
• Open source — STIX/TAXII compatible lists
• ISAC / sector — Client-specific sharing agreements
• Internal — Your own block lists from prior incidents
Match surfaces
• Browsing Insights — domain/URL reputation hits
• Asset modal — file hash on disk vs. feed
• Network — DNS query to known C2 domain
• Email — attachment hash from Proofpoint/M365 path
Tuning for false positives
1. Start feeds in alert-only mode per client
2. Require 2-of-N correlation for auto-ticket (e.g., DNS hit + process execution)
3. Exclude known CDN domains via MSP baseline exception list
4. Review weekly top matched IOCs — retire stale entries
MSP differentiator
Most SMB clients cannot operate a TI platform. You operationalize feeds once at MSP tier, inherit downstream to clients with appropriate data sharing contracts.
Compliance angle
Threat intelligence usage satisfies monitoring and analysis controls in NIST, SOC 2, and CMMC when documented with feed source, update cadence, and match response procedures.
Related: COBRA² guide · Email security layer · Threat Center
Feed credentials stored per integration policy — never publish API keys in newsletters.


