Skip to content
Notifications
Clear all

Has anyone done a direct speed test of indicator enrichment vs. API calls?

1 Posts
1 Users
0 Reactions
24 Views
(@devops_journeyman)
Reputable Member
Joined: 5 months ago
Posts: 216
Topic starter   [#17315]

I've been working on integrating ThreatConnect into a security automation pipeline, and I'm hitting a design decision point. My use case involves enriching a high volume of observables (IPs, domains, hashes) from our SIEM alerts.

The TC documentation talks about using the native "indicator" objects within the platform for enrichment, which seems to be the intended method. However, I can also write scripts that directly call the `/api/v2/indicators` endpoint for the same data.

I'm leaning towards the direct API calls for better control, but I'm worried about performance and rate limiting. Before I build the whole flow, I wanted to ask if anyone has benchmarked these two approaches?

Specifically:
* Is there a noticeable speed difference when enriching a batch of 50-100 indicators using the TC platform's built-in enrichment features versus a scripted loop of individual REST API calls?
* How does the bulk indicator endpoint (`/api/v2/indicators/batch`) compare?
* Any gotchas with API tuning? For example, are there specific `fields` or `includes` parameters that drastically slow down the response if requested?

Here's a stripped-down version of the direct API loop I was prototyping:

```python
import requests
from requests.auth import HTTPBasicAuth

session = requests.Session()
session.auth = HTTPBasicAuth('', '')

indicators = ['1.2.3.4', 'malicious-domain.com', 'abc123def...']
for ioc in indicators:
response = session.get(
'https://instance.threatconnect.com/api/v2/indicators',
params={'summary': 'true', 'fields': 'rating,confidence,threatAssess'},
data={'indicator': ioc}
)
# ... parse response
```

My gut says the native enrichment might do smarter caching or bulk fetches under the hood, but the API feels more flexible for a pipeline built in Python. Has anyone done the legwork to compare? Real-world numbers or even anecdotal "it felt faster" experiences would be super helpful.



   
Quote