← research
Verified retrospective22 April 2026Checked 11 October 20265 min read

More Threat Feeds Did Not Automatically Mean Better Intelligence

An April retrospective on source growth, silent failures, test coverage, and the point where feed count stopped being a useful quality measure.

ThreatWatchFeed qualityReliability
Many threat feeds narrowing into a smaller set of healthy unique signals
Many threat feeds narrowing into a smaller set of healthy unique signals. Editorial illustration.

I liked watching the source count climb until I realised the number could improve while the intelligence got worse.

ThreatWatch grew quickly in April. Adding sources was easy to measure and satisfying to report. The harder questions arrived later: Was a feed fresh? Did it produce anything unique? Did failure become visible, or did the source remain green because the request itself returned?

Question

When does adding another threat feed improve the product, and when does it only increase processing cost, duplication, and false confidence?

Method

I reviewed three points in the repository history: the source expansion, the test-coverage gate, and the fix that surfaced silent feed failures. I treated commit messages as an index, then inspected the affected code and tests to understand the actual control being added.

The comparison is qualitative. There was no controlled experiment in April that held every variable constant while adding feeds one at a time.

Evidence

One change expanded ThreatWatch from 142 to 164 active sources. That increased breadth, but source count alone said nothing about overlap or freshness. Multiple feeds can repeat one vendor advisory, syndicate the same article, or publish nothing new for weeks.

The coverage work raised the automated test baseline to at least 80 percent. Coverage is not a quality score, but the gate mattered because feed parsers and failure paths were multiplying. Without tests, every new source increased the surface for quiet breakage.

The strongest evidence came from the failure-handling change. ThreatWatch began surfacing silent feed failures and alerting on them. A feed that returned no useful records could no longer look healthy merely because an exception had been swallowed or an endpoint responded.

Finding

The useful unit is not a configured feed. It is a healthy, current, attributable piece of unique evidence. Source count can describe collection breadth, but it should not stand in for intelligence quality.

This changed the questions I ask first. I now want to know when a source last produced a valid item, how often it duplicates another source, whether its timestamps are trustworthy, and what disappears if it is removed. A smaller set of observable, complementary sources can be healthier than a long list of logos.

Limitations

The commits establish the engineering sequence, not a complete April feed-quality dataset. This retrospective does not calculate the unique contribution or failure rate of all 164 sources.

Automated tests and health signals also cannot decide editorial value by themselves. A low-volume source may still be essential when it covers a region or threat class no other source reaches. Human review remains part of curation.