Silent Push assigns four key attributes to threat feeds:
Overlap
- The percentage of the feed's observables that are featured in other feeds/collections used by an organization.Originator
- The percentage of observables first reported since the feed or collection was added.Accuracy
- Calculated based on user feedback regarding false positives.False positive ratio
- The ratio of the number of false positives with the number of IoCs reported in the feed in the last 30 days.
To view a feeds attributes across any of the above categories:
-
Navigate to
Threat Intelligence Management > Feeds Comparison
-
The
Overlap
,Originator
,Accuracy
andFalse Positive Ratio
attributes are displayed on the far-right column of each individual feed