Sample feeds: These are all observables seen.
Indicator of Compromise (IOC) feeds: These are observables seen
via business intelligence. IOCs are used to indicate that the system has
been affected by some form of malware.
Curated feeds: These are highly curated and high-confidence feeds.Table 11-7 shows the differences between these feeds.
Table 11-7 Threat Grid FeedsSample FeedsIOC FeedsCurated FeedsVersion /v2 /v2 /v3Endpoi
nt/sam
ples/f
eeds//iocs/fee
ds//feeds/Content All
obser
vables
are
seenObserva
bles are
seen in
all BIsObservables are seen as
part of a trusted high-
confidence BI triggeringPre-
whitelis
tedNo No YesFilterab
le to
only
you/org
?Yes Yes NoOutput
Format
sJSON JSON JSON/CSV/Snort/STIXSay that you want to retrieve all the curated feeds via
API. The curated feed types are shown in Table 11-8.
Table 11-8 Curated Feed Types