The key is Automation

Isn’t it sad to have a lot of data and not use it because it’s too much work? Thanks to MISP you can store your IOCs in a structured manner, and thus enjoy the correlation, automated exports for IDS, or SIEM, in STIX or OpenIOC and synchronize to other MISPs. You can now leverage the value of your data without effort and in an automated manner. Check out MISP features.

Simplify Threats

The primary goal of MISP is to be used. This is why simplicity is the driving force behind the project. Storing and especially using information about threats and malware should not be difficult. MISP is there to help you get the maximum out of your data without unmanageable complexity.

By giving you will receive

Sharing is key to fast and effective detection of attacks. Quite often similar organizations are targeted by the same Threat Actor, in the same or different Campaign. MISP will make it easier for you to share with, but also to receive from trusted partners and trust-groups. Sharing also enabled collaborative analysis and prevents you from doing the work someone else already did before.
Join one of the existing MISP communities.

Threat Intelligence

Threat Intelligence is much more than Indicators of Compromise. This is why MISP provides metadata tagging, feeds, visualization and even allows you to integrate with other tools for further analysis thanks to its open protocols and data formats.

Visualization

Having access to a large amount of Threat information through MISP Threat Sharing communities gives you outstanding opportunities to aggregate this information and take the process of trying to understand how all this data fits together telling a broader story to the next level. We are transforming technical data or indicators of compromise (IOCs) into cyber threat intelligence. MISP comes with many visualization options helping analysts find the answers they are looking for.

Open & Free

The MISP Threat Sharing ecosystem is all about accessibility and interoperability: The software is free to use, data format and API are completely open standards and for support you can rely on community and professional services.

Want to test and evaluate MISP?

Download now

Initiatives

The MISP Threat Sharing project consists of multiple initiatives, from software to facilitate threat analysis and sharing to freely usable structured Cyber Threat Information and Taxonomies.

Do you want to join a community?

MISP is an open source software and it is also a large community of MISP users creating, maintaining and operating communities of users or organizations sharing information about threats or cyber security indicators worldwide.

Find communities

From our blog

In addition to the news stories below, check out the press, events, hackathon, MISP Summit pages and full news archive.

MISP 2.4.204 and 2.5.6 released including new features, performance improvements and many other improvements.

on January 13, 2025

Combined Release Notes: MISP v2.5.6 & v2.4.204 (2025-01-03)

The MISP team is excited to announce the release of MISP v2.5.6 and MISP v2.4.204. These updates bring several new features, fixes, and performance improvements to enhance the platform’s usability and efficiency. Here’s a summary of the key changes:

Continue reading

MISP 2.4.203 and 2.5.5 released including new features, improvements and many security improvements.

on January 12, 2025

MISP Software Release: Combined Updates for v2.4.203 and v2.5.5

Introduction

We are thrilled to announce the release of MISP v2.4.203 and MISP v2.5.5, bringing a range of new features, improvements, and fixes to enhance the platform’s performance, usability, and security. These updates reflect our ongoing commitment to providing a robust and reliable open-source threat intelligence platform for the community.

Continue reading

MISP 2.4.202 and 2.5.4 released with numerous enhancements including analyst data, bug fixes, and security improvements

on December 24, 2024

Changes

Configuration

  • Base URL Setting: Added a new setting to skip base URL coercion for the framework. This resolves issues when running MISP under a subdirectory but may have adverse effects for other setups.

Settings

  • REST Client Settings: Enhanced security by tightening REST client-related settings:
    • rest_client_baseurl is now CLI-only.
    • Updated rest_client_enable_arbitrary_urls description for clarity.
  • Removed Unused Setting: Security.disable_form_security, a legacy setting for testing purposes, has been removed.

Updates

  • Taxonomies, Warning Lists, Objects, Galaxy: Updated to their latest versions.
  • MISP-STIX and PyMISP: Updated to the latest versions.

Analyst Data

  • Analyst Data objects like Notes and Opinions are now flattened lists attached to their data layer instead of nested.
  • Improved handling of analyst data in various endpoints and views.
  • Added new metrics for analyst data and event reports.

UI

  • Minor tweaks and improvements.

Attributes

  • Support for adding combinations of tag collection tags and other tags simultaneously.

Statistics

  • Added metrics for analyst data and event reports.

CI

  • Path fixes and branch updates.

Fixes

Security

  • Resolved multiple vulnerabilities:
    • Stored XSS in JsonTool::encode() used in JavaScript.
    • Tightened template elements endpoint to prevent abuse.
    • File upload process improved to prevent abuse.
    • Prevented TOTP secret logging in audit logs.
  • Updated encoding in the upload_file view element.

Analyst Data

  • Addressed issues with nested data handling and JSON export.
  • Fixed data fetching inconsistencies and restored functionality for viewing nested analyst data.
  • Adjusted deleted flag behavior to improve results consistency.

Miscellaneous

  • Corrected variable definition, CLI arguments, and template index naming.

Other

  • Merge Requests: Integrated various feature and fix branches into 2.4-develop.
  • Community Additions: Added Threatmon MISP Community.
  • Custom Image Path Check: Updated image path validation logic.

This release includes several critical security fixes, updates, and enhancements, improving the overall functionality and stability of MISP. Users are encouraged to update promptly to benefit from the latest improvements and security measures.

Continue reading

MISP v2.5.3 and v2.4.201 released with numerous enhancements, bug fixes, and security improvements to strengthen threat information sharing capabilities.

on December 22, 2024

We are excited to announce the latest updates to MISP with versions v2.5.3 and v2.4.201, which bring numerous enhancements, bug fixes, and security improvements to strengthen threat information sharing capabilities. As with any security release, we highly recommend that you update ASAP and inform your partners to do the same.

Continue reading