Skip to main content

Introduction

Ver. 06/03/2026

This plugin retrieves the 500 most frequent IPs from the last 30 days of MISP events and generates a SIEM rule to detect traffic from those IPs.

Type: Server Plugin