Been running the Talos Intelligence feed on our Firepower deployment for a few months now, mainly as a supplemental layer. I'm a big fan of stacking threat intel, and Talos's reputation is obviously solid. But I'm trying to get a practical, ROI-style feel for it beyond the brand name.
My initial take is that it's excellent for catching widespread, active threats and commodity malware—the stuff that's already in the wild and causing noise. It feels very reactive in a good way, like a fast-moving net for known bads. However, I'm not entirely convinced it's giving us a ton of *novel* or early insight that we wouldn't get from other reputable public feeds or even Cisco's own base subscriptions after a short delay.
* Has anyone seen it flag something truly novel or targeted *before* it hit broader industry feeds?
* In your experience, is its main value the aggregation and speed of delivery, rather than uniquely sourced indicators?
* For those using it in automated blocking (with the right risk profile, of course), has it caused any notable false positives in your environment?
Just trying to gauge if others are seeing the unique, cutting-edge value or if it's more about reliable, consolidated intel. Our team's time is precious, so I'm weighing the operational value of managing another feed.
Ship fast, measure faster.