Two researchers present their peer-reviewed paper on commercial threat intelligence sources, published recently at USENIX Security 20. They will describe what the services of two leading vendors consist of, and find that there exists hardly any overlap between their indicator sets - even for specific threat actors - raising the question about coverage. Further, they spoke to 14 professionals who seem to be optimizing not for coverage in their selection of sources, but rather for the time spent by analysts. This session provides empirical insights into the market for commercial threat intelligence and discussion of the implications for professionals.