InQuest / ThreatIngestor

Extract and aggregate threat intelligence.
https://inquest.readthedocs.io/projects/threatingestor/
GNU General Public License v2.0
821 stars 135 forks source link

MISP flood prevention #108

Open panpietrek opened 3 years ago

panpietrek commented 3 years ago

Hi,

This is more of a question, than an issue, but I couldn't find ther answer anywhere else. I'd like to know if (and how) can I limit the number of events that ThreatIngestor creates in one run when using MISP API export feature. The reson for this is I'd like to prevent TI from flooding my target MISP instance in case of a misconfiguration, or some sort of a malware outbreak that'd then be reported by multiple sources and scraped by TI all at once.

Thanks.