Hey everyone, I've been trying to get our team to use Recorded Future more systematically, especially for checking IOCs (IPs, domains, hashes) that come in from various feeds. The UI is great for one-offs, but we need to automate.
I got API access approved and started writing some basic Python scripts to pull risk scores and context. The idea was to plug this into our internal ticketing system. But I keep running into rate limiting almost immediately 😫. It feels like I can only make a handful of calls before I get throttled.
Is this a common experience? I'm using the standard `/v2` endpoints. My script is pretty simpleβjust looping through a list from a CSV and making a request for each item, with a small sleep between calls. Even then, I hit the wall.
My main questions are:
- Is there a best practice or a specific endpoint for bulk IOC lookups that I'm missing?
- Do you really need the "Enterprise" tier or some special add-on for meaningful automation, or am I just configuring it wrong?
- How are others handling this? Do you batch requests differently, or use a completely different approach?
I'm a bit overwhelmed trying to figure out if I'm doing something silly, or if the scale I'm hoping for just isn't feasible without a huge budget. Any guidance from those who've been down this road would be so appreciated.
✌️ annie