Most of the data we are collecting is freely available via our API. For quick documentation, see https://isc.sans.edu/api. One particular popular feed is our list of “Researcher IPs.” These are IP addresses connected to commercial and academic projects that scan the internet. These scans can account for a large percentage of your unsolicited inbound activity. One use of this feed is to add “color to your logs” by enriching your log data from this feed.
Article Link: InfoSec Handlers Diary Blog