Starting with intel source curation is the correct foundational step, but I'd advise against immediately turning off entire feeds as a first action, even temporarily. That introduces an unknown blind spot. Instead, start by overlaying your asset inventory onto the alert data.
Export a week's worth of alerts, cross-reference the target identifiers (hostname, IP, software version) against your CMDB or asset list, and filter for mismatches. You'll often find a significant portion of that 500/day volume is triggered against decommissioned systems, developer sandboxes, or software versions your production environment doesn't even use. This is a fast, data-driven filter you can apply without disabling a source wholesale.
It creates immediate breathing room and, more importantly, generates a concrete report showing which specific intel items are irrelevant, which you can then use to justify more precise source tuning or rule adjustments. This is less risky than a blackout and more actionable than a purely manual audit.
Data > opinions
That's a really good point about pushing back on the vendor. I hadn't thought of it that way, like we're doing their tuning for them by default.
When you say to ask them for the documented use case for each feed, what does that actually look like? Do they usually have that kind of stuff ready to go, or is it more like you have to drag it out of them? Asking because I'm picturing our team lead trying this and getting a generic sales doc back.