Limits in ThreatStream

The table below contains the list of limits that ThreatStream enforces across the platform.

Feature Parameter Limit
Advanced Search Characters in an advanced search query 4,000
Custom Dashboards Dashboards per home screen

10

Widgets per dashboard 10
Import Characters in an URL 2048
Size of PDF file uploads 20 MB

Number of imports per hour per org

(with and without approval)

30
Feeds Observables ingested a day per feed 600,000
PassiveDNS Requests per minute per user 20
Rules Matches per 24-hour period

100,000

Investigations created per 24-hour period 50
Keywords in a rule 100
Characters in an advanced search rule 4,000
Rules per org 300
Time limit for retrospective search 90 days
Matches per retrospective search 10,000
Attack Surface Management Top-level domains configured per organization 10,000
IPs configured per organization (including CIDR ranges) 2,000
Sandbox Detonations a day per organization
  • Joe Sandbox via ThreatStream—2 default detonations once activated

  • Joe Sandbox via Individual Subscription—per your contract with Joe Sandbox

  • VMRay via Individual Subscription—per your contract with VMRay

Detonation file size 50 MB
Saved Search Filters Characters in a saved search filter 4,000
Tags Characters in a tag 2,000

Characters for total tags per observable in a snapshot

120,000
Tags for each instance per organization 200
TAXII Poll Default rate limit for TAXII poll requests per hour per organization 300
TAXII Push Default rate limit for TAXII push requests per hour per organization 120