Skip to content

Argus CTI

RSS threat-feed collection and filtering for MISP.

Purpose

Argus CTI collects threat information from RSS feeds and turns relevant entries into structured MISP events. Configurable filters let the pipeline focus on selected sectors, vendors, vulnerabilities and incident types.

Pipeline

Stage Function
Collect Read configured RSS threat feeds.
Enrich Apply CTI labels through a Hugging Face inference module.
Filter Select entries using rules in configuration files.
Publish Push structured events into MISP.

Configuration

Feed sources and filtering rules live in YAML files. The pipeline runs through a Python command-line interface.

Technical notes & source

Read the full technical notes

View Argus CTI on GitHub