Enterprise IOC Feed
4 min
the enterprise ioc feed turns research into proactive defense it strengthens your threat detection and response posture by pushing intelligence directly into your security stack feeds deliver threat intelligence from flare into your existing security tooling (siem, soar, edr, tip, or firewalls) in industry standard stix 2 1 format via the taxii 2 1 protocol the enterprise ioc feed is delivered as two taxii feeds flare cti feed carries the intelligence objects themselves, including indicators, malware, threat actors, campaigns, and the other entity types flare cti relationship feed carries the stix relationships that connect those objects to one another, for example linking an indicator to the malware, campaign, and threat actor it belongs to both feeds use the same configuration they use taxii 2 1, with basic authentication using your flare api key each feed points to its own taxii endpoint and collection, which flare provides for more information, see our intelligence feeds api documentation https //api docs flare io/guides/ioc feeds key features broad ioc coverage support for the core indicator types security teams rely on, such as, domains, urls, ips, file hashes, campaigns, threat actor profiles, and intrusion sets stix/taxii delivery all feeds use stix 2 1 for the intelligence format and taxii 2 1 as the transport protocol this is the industry standard and most siems, soars, tips, and edrs support it natively your existing tooling can consume these feeds without custom integration work stix object relationships indicators are delivered with their full relationship context intact an indicator links to the campaign it belongs to, which links to the threat actor behind it, which links to the associated malware family your tip receives queryable, traversable intelligence, not a flat list access to this feature requires an add on please reach out to your csm for more information trials for trial accounts, once the cti module is enabled, these ioc feeds will begin populating from the moment the tenant is created it does not backfill historical intelligence, so objects published before the feed existed will not appear in the collection walkthrough click through the following product tour to learn how to integrate the enterprise ioc feed into your existing security stack