Malware
Threat feed
Threat feed is a published stream of known-bad indicators: hosts, URLs, IP addresses, and file hashes, updated as new ones are found. You load it into a tool that blocks or alerts.
How it is measured
Evaluate a feed by freshness, coverage, and error rate. How old is the oldest entry? How many entries are still active? How many hits turn out to be false? Format matters too: plain text lists, CSV, STIX/TAXII, or an API.
Test before you enforce: run the feed in alert-only mode against a week of DNS or proxy logs and review every match. Count matches per day, and check how many were real.
Worked example
A small agency pulls a free feed of 60,000 malicious domains into its DNS filter. On the first day it blocks 'cdn-unpkg-mirror.example', a real hit, and also a link shortener the client's marketing team uses, which the feed listed because a spam campaign abused it.
A week in alert-only mode would have caught the shortener. After allowing it and setting the feed to refresh every 6 hours, the agency has one confirmed infected laptop and no complaints from marketing.
How it differs
The Tarsier Threat Index is one curated list used by Hack Check for a specific job: judging pages. A threat feed is the general kind of thing, from many vendors and communities, in different formats and levels of trust. A feed is data you ingest; the index is a particular maintained set with an owner.
Common errors
Enabling block mode on day one. Never refreshing the feed. Assuming bigger is better when stale entries cause false blocks. Combining feeds without removing duplicates. Treating a hit on a shared host as proof the whole domain is bad.
In practice
Pick one or two feeds with a stated source and update time. Run alert-only for a week, tune, then block. Keep an allowlist for legitimate domains, and review hits from the highest-risk machines first.