Argus CTI
RSS threat-feed collection and filtering for MISP.
Purpose
Argus CTI collects threat information from RSS feeds and turns relevant entries into structured MISP events. Configurable filters let the pipeline focus on selected sectors, vendors, vulnerabilities and incident types.
Pipeline
| Stage | Function |
|---|---|
| Collect | Read configured RSS threat feeds. |
| Enrich | Apply CTI labels through a Hugging Face inference module. |
| Filter | Select entries using rules in configuration files. |
| Publish | Push structured events into MISP. |
Configuration
Feed sources and filtering rules live in YAML files. The pipeline runs through a Python command-line interface.