MISP’s ecosystem includes applications, libraries, shared data models, and integrations for collecting, analysing, sharing, and using threat intelligence. This directory lists the MISP project’s software first, followed by CIRCL projects and third-party integrations.
Choose tools for your use case and check their installation instructions, supported MISP versions, and required service subscriptions. Inclusion here describes functionality; it does not imply that every project has the same maintenance or support policy.
Software within the MISP project
Core, enrichment, and conversion
| Project |
Purpose |
| MISP |
The core threat intelligence platform for sharing, correlating, and managing events, indicators, sightings, and contextual information. |
| PyMISP |
The official Python client for the MISP REST API; also creates and manipulates MISP events and objects offline. |
| misp-modules |
Enrichment, expansion, import, export, and workflow modules. Can also run independently of MISP through its API and web interface. |
| misp-modules-cli |
Command-line access to misp-modules. |
| misp-stix |
The current Python library and command-line tools for conversion between MISP and STIX formats. |
| cti-transmute |
Web service for converting threat intelligence formats using misp-stix. |
| MISP-Taxii-Server |
OpenTAXII configuration and supporting tools for exchanging MISP data through TAXII. Check the repository’s supported protocol and dependencies before deployment. |
| mail_to_misp |
Creates MISP events from email, principally through mail-server workflows such as Postfix. The older desktop mail-client integrations are unmaintained. |
| misp-workbench |
A standalone MISP-compatible analysis stack for ingesting feeds, searching indicators, and generating correlations, with a Python API and Vue frontend. |
Enrichment, import, export, and workflow module catalog
The misp-modules documentation and repository provide the module catalog, configuration, and dependencies. Consult that catalog instead of relying on a fixed list of individual Python files, which changes as integrations evolve.
- Enrichment and expansion: passive DNS/SSL, vulnerability lookup, hash reputation, sandbox results, geolocation, and other contextual sources.
- Import: external intelligence formats, email, documents, and analysis reports.
- Export: supported intelligence and reporting formats.
- Workflow actions: modules used by MISP’s automation workflows.
Some modules require a separate account, API key, paid service plan, or local dependency. Enable the modules appropriate to your deployment.
Data models, validation, and knowledge bases
These resources can also be used by tools that do not run a MISP instance.
| Project |
Purpose |
| misp-taxonomies |
Machine-readable taxonomies for classifying intelligence and applying consistent tags. |
| misp-galaxy |
Contextual knowledge about threat actors, malware, techniques, tools, and other related entities. |
| misp-objects |
Object templates and relationship definitions for structured intelligence. |
| misp-warninglists |
Lists of common infrastructure and other values that help identify potential false positives. |
| misp-noticelist |
Notices about legal, privacy, policy, and technical implications of particular attributes or objects. |
| misp-decaying-models |
Default models for decaying indicator relevance over time. |
| misp-event-templates |
Reusable event templates for collecting consistently structured intelligence. |
| misp-workflow-blueprints |
Reusable blueprints for MISP’s built-in workflow engine. |
| misp-feedback |
Warninglist lookup engine with a daemon, HTTP/Unix-socket access, and command-line client. |
| misp-validation |
Prototype rule format and runtimes for language-independent attribute normalization and validation. |
| misp-engineering-bay |
Editors and supporting utilities for creating and validating MISP content and data structures. |
| misp-global-search |
Full-text search across MISP galaxies, objects, and taxonomies. |
| threat-intelligence-browser |
Browser for the MISP Galaxy threat intelligence knowledge base. |
| threat-actor-intelligence-server |
REST lookup of threat actors by name, synonym, or UUID using MISP Galaxy data. |
Libraries and MCP interfaces
| Project |
Purpose |
| RustMISP |
Rust client library for the MISP REST API. |
| LuaMISP |
Lua library for creating and manipulating MISP entities. |
| PyTaxonomies |
Python access to MISP taxonomies. |
| PyMISPGalaxies |
Python access to MISP Galaxy data. |
| PyMISPWarningLists |
Python access to MISP warninglists. |
| PyMISPObjectTemplates |
Python API for creating and updating MISP object templates. |
| PyIntel471 |
Python client for Intel 471’s API. |
| misp-mcp |
Model Context Protocol server providing read-only access to MISP events, attributes, objects, and reference data. |
| misp-galaxy-mcp |
Model Context Protocol server for searching the MISP Galaxy knowledge base. |
| ai-connector |
MISP AI module for event/report summarisation and related assistance; check its documentation for the required MISP feature branch and available use cases. |
Investigation, detection, and reporting
| Project |
Purpose |
| MISP-maltego |
Maltego transforms for MISP and exploration of MITRE ATT&CK data. |
| misp-wireshark |
Wireshark plugin that exports selected packet data in MISP format. |
| misp-ghidra |
Integration between Ghidra and MISP for reverse engineering workflows. |
| bsimvis |
Binary similarity analysis and visualisation using Ghidra analyzers and BSim. |
| evtx-toolkit |
Reads Windows EVTX/Sysmon records and converts them to JSON, MISP objects, and graph data. |
| misp-sighting-tools |
Generates sightings from sources such as network packet captures. |
| misp-sighting-server |
Standalone service for storing and looking up indicator sightings. |
| wazuh-integration |
Wazuh rules and scripts for checking file hashes against MISP and optionally reporting sightings. |
| misp-expansion |
Firefox/Chrome extension for looking up selected text or page URLs in MISP. |
| misp-dashboard |
Live overview of activity and intelligence from MISP instances. |
| misp-grafana |
Grafana dashboards using the MISP ZeroMQ stream and InfluxDB. |
| widget-collection |
Additional widgets for MISP’s built-in dashboards. |
| misp-pandoc-filter |
Work-in-progress Pandoc filter for turning MISP event reports into PDF documents. |
| misp-playbooks |
Jupyter-based operational playbooks using PyMISP for analysis, enrichment, and response. |
| matrix-misp-bot |
Basic MISP bot for Matrix. |
| misp-opendata |
Publishes and manages metadata for MISP-backed datasets on open-data portals. |
| misp-takedown |
Generates takedown notifications through RT/RTIR from MISP events. |
| yara-misp |
Exports MISP attributes as YARA rules. |
| yara-exporter |
MISP-hosted fork of the YARA exporter for THOR-compatible scanning rules. |
Deployment, administration, and testing
| Project |
Purpose |
| misp-docker |
Official Docker deployment for MISP and its associated services. |
| MISP-RPM |
RPM packaging for MISP. |
| misp-airgap |
Deployment and maintenance in air-gapped environments using LXD. |
| MISP-Fleet-Commander |
Web application for managing MISP instances and communities. |
| MISP-Fleet-Commander-Browser-Extension |
Registers MISP instances in Fleet Commander from the browser. |
| misp-guard |
Proxy addon for applying rules to MISP synchronisation traffic. |
| misp-bump |
Exchanges MISP synchronisation setup information using encrypted QR codes. |
| misp-monitoring |
Monitoring utilities and operational documentation for MISP servers. |
| misp-usage-statistics |
Collects and visualises MISP usage statistics. |
| MISP-sizer |
Hardware sizing calculator for MISP deployments. |
| ansible |
Ansible installation scripts; review supported operating systems and MISP versions. |
| misp-packer |
Packer-based virtual machine image builder; its documented image targets Ubuntu 18.04. |
| misp-cloud |
Cloud image generation, with AWS support documented in the repository. |
| misp-vagrant |
Vagrant deployment definitions for MISP project software. |
| misp-synchronisation |
Deploys multiple instances and tests their synchronisation behaviour. |
| misp_dockerized_testing |
Earlier Docker-based infrastructure for testing MISP instances. |
| misp-stix-tests |
STIX fixtures for testing conversion libraries. |
| dockerized_training_environment |
Container-based MISP training environment. |
| mail_to_misp_test |
Email fixtures for testing mail_to_misp. |
| pCraft |
Generates PCAPs from scripted scenarios for testing and exercises. |
| cexf |
Common Exercise Format for describing exercise injects and scenarios. |
| Synthetic-Exercise-World-Format |
Structured fictional countries, organisations, sectors, and threat actors for neutral exercises and CTI examples. |
These repositories document earlier implementations or research approaches. Review their dependencies and compatibility before using them with a current MISP deployment.
| Project |
Purpose and context |
| vintage-misp-workbench |
Original database export and correlation workbench. The current standalone analysis application is misp-workbench. |
| MISP-STIX-Converter |
Earlier MISP/STIX synchronisation implementation. Use misp-stix for the current conversion library. |
| MISPego |
Earlier Maltego transforms for adding entities to MISP events; also see MISP-maltego above. |
| docker-misp |
Archived Docker implementation; its README directs users to misp-docker. |
| x_old_misp_docker |
Older Docker implementation retained separately from misp-docker. |
| misp-graph |
Graphviz/GEXF export from MISP XML, with legacy Python dependencies. |
| data-processing |
Scripts for extracting and correlating intelligence from MISP data exports. |
| misp-search |
Command-line MISP search implementation hosted as a fork. |
| misp-bloomfilter |
Builds Bloom filters from MISP XML exports; consult its documented limitations on indicator confidentiality. |
| misp-privacy-aware-exchange and pypraware |
Research implementation and Python support for privacy-aware indicator exchange. |
| sacti |
MISP-hosted fork for securely aggregating and reporting sightings. |
| misp-darwin |
Work-in-progress rules for translating structured MISP intelligence into human-readable reports. |
Specifications, training, and supporting repositories
The MISP organisation’s repository directory is the authoritative inventory for new projects and repository status.
CIRCL projects and services
CIRCL develops MISP and a wider set of security tools and services. The following table covers the projects in the CIRCL open source catalog. Some integrate directly with MISP; others support investigation, enrichment, incident response, or training alongside it.
Projects in the CIRCL catalog
| Project |
Purpose and relationship to MISP |
Source code |
| MISP |
Threat intelligence sharing platform and standards ecosystem. See the MISP software directory above for its tools, libraries, and resources. |
MISP |
| AIL Framework |
Collects and analyses unstructured data to identify information leaks and cyber threats, with MISP event/object export. |
ail-framework |
| FlowIntel |
Investigation and case management with MISP taxonomies/galaxies, enrichment through misp-modules, and MISP export. |
flowintel |
| Cerebrate |
Trusted community and contact management, with interconnection and orchestration of tools such as MISP. |
cerebrate |
| Draugnet |
Submits threat reports to MISP communities without requiring a user account; submission tokens let reporters follow subsequent updates. |
draugnet |
| Lookyloo |
Captures websites and visualises their relationships; can look up indicators in MISP and export captures as MISP events. |
lookyloo |
| Pandora |
Analysis platform for examining suspicious files and understanding their contents and risks. |
pandora |
| hashlookup |
Known-file hash lookup and forensic tools for identifying legitimate files and reducing investigation noise. |
hashlookup tools |
| Rulezet |
Shares, evaluates, and manages detection rules such as YARA, Sigma, and Suricata, with MISP-compatible tag metadata. |
rulezet-core |
| Pivotick |
TypeScript network visualisation library for exploring relationships and interactively pivoting through connected data. |
Pivotick |
| Kunai |
Linux security monitoring and threat hunting with detailed system-event telemetry. |
kunai |
| FAnything |
Network fingerprint format and tooling for correlating protocol and implementation behaviour across SSH, TLS, QUIC, and other protocols. |
fanything |
| BinTriage |
Collection of projects for rapid binary triage and analysis. |
BinTriage repositories |
| D4 Project |
Distributed sensor and analysis framework for collecting and processing security observations and network telemetry. |
D4 repositories |
| Typo-squatting Finder |
Generates, resolves, and assesses look-alike domain names for investigating typo-squatting. |
Typosquatter repositories |
| Vulnerability-Lookup |
Aggregates and correlates vulnerability information and community observations. MISPSight transfers vulnerability sightings from MISP. |
vulnerability-lookup |
| GCVE |
Decentralised vulnerability identifier allocation and publication, with tooling for vulnerability management applications. |
GCVE repositories |
| cve-search |
Imports, indexes, and searches CVE/CPE information locally; accessible through MISP enrichment modules. |
cve-search |
| NGSOTI |
Training material and tools for security operations and threat intelligence. |
NGSOTI repositories |
| Neolea |
Digital forensics and information-sharing training for law enforcement and CSIRT communities. |
neolea-training-materials |
| SkillAegis |
Designs, runs, and monitors exercise scenarios for MISP and other security applications. |
SkillAegis |
Related services, libraries, and investigation tools are available through CIRCL and its project organisations. Review their individual documentation for access conditions, dependencies, and maintenance status.
The CIRCL projects directory links to project documentation and the full repository inventories of CIRCL’s project organisations.
Third-party integrations
These tools are developed by their respective communities or vendors. Check upstream documentation for the current integration, supported API, and product licensing.
Incident response, threat intelligence, and automation
| Tool |
MISP integration |
| TheHive |
Incident response platform with MISP integration. Current versions are distributed by StrangeBee; the former public TheHive 3/4 repositories are no longer maintained or distributed. |
| Cortex MISP analyzer |
Looks up observables in MISP from Cortex analysis workflows. |
| IntelMQ |
Collects, processes, and exchanges security feeds, including MISP input/output bots. |
| Rapid7 InsightConnect |
MISP actions and triggers for automation workflows. |
| RTIR MISP extension |
Connects RTIR incident handling with MISP. |
| EclecticIQ |
Threat intelligence platform; consult the vendor’s current MISP connector documentation. |
| Hybrid Analysis |
Analysis reports and intelligence export in MISP format. |
| Joe Sandbox |
Sandbox analysis with MISP-format output and integration. |
SIEM, detection, and hunting
| Tool |
MISP integration |
| Elastic MISP integration |
Ingests threat intelligence through Elastic Agent. This is the current integration rather than the former standalone Filebeat MISP module. |
| misp42splunk |
Retrieves MISP intelligence in Splunk and sends data back through alert actions. Also available on Splunkbase. |
| TA-misp |
Splunk technology add-on for matching local data against MISP objects/attributes. |
| misp2sentinel |
Exports indicators to Microsoft Sentinel using the STIX objects Upload Indicators API. The repository’s older Microsoft Graph approach is deprecated. |
| Dovehawk |
Zeek intelligence integration that retrieves indicators from MISP and reports sightings. |
| misp_to_zeek |
Exports MISP indicators to Zeek’s intelligence framework. |
| surimisp |
Matches MISP indicators against Suricata events. |
| pymisp-suricata_search |
Retrieves MISP attributes and generates Suricata rules. |
| sigmai |
Generates Sigma rules from MISP indicators. For storing and exchanging existing Sigma rules, MISP also has native Sigma support. |
| MISP2CbR |
Converts MISP intelligence into a Carbon Black Response threat feed. Check compatibility with your product version. |
| MISP CrowdStrike scripts |
Scripts for exporting MISP indicators to CrowdStrike; review the supported CrowdStrike API before use. |
Collection and analyst utilities
| Tool |
MISP integration |
| misp-scraper |
Creates MISP events and reports from web pages; also used by the zsazsa CTI platform. |
| phish2MISP |
Collects information about phishing URLs and adds it to MISP. |
| vt2misp |
Adds VirusTotal results to MISP events as objects. |
| ja3toMISP |
Extracts JA3 fingerprints from PCAPs and adds them as MISP objects. |
| misp_btc |
Retrieves Bitcoin addresses from MISP and enriches them with transaction information. |
| misp-bulk-tag |
Applies tags in bulk through the MISP API. |
| MISP-PurgeEvents |
Administration script for deleting selected events. Review its cleanup instructions before use. |
| MISP-IOC-Validator |
Validates indicator formats and compares values with known false positives. |
| MISP-Extractor |
Retrieves intelligence and automates operations through the MISP API. |
| misp-extractor |
Exports selected attribute types to separate files. |
| BTG |
IOC search tool with MISP collection support. |
| threatingestor |
Extracts and aggregates indicators from feeds, including MISP output support. |
| ThreatPinchLookup |
Browser-based indicator lookup with a MISP connector; check browser compatibility. |
Other API libraries
Use PyMISP for the official Python API client. Alternative clients expose different subsets of the MISP API.
| Library |
Language and scope |
| golang-misp |
Go library focused on MISP search. |
| mispex |
Elixir wrapper for the MISP HTTP API. |
| mispy |
Alternative Python interface to MISP. |
Archived integrations and older examples
These links are retained for users maintaining existing integrations. Archived projects do not receive upstream updates; older examples can depend on historical MISP or vendor APIs.
| Integration |
Status or compatibility context |
| misp-rb |
Archived Ruby API wrapper. |
| DCSO tie2misp |
Archived importer for DCSO TIE intelligence. |
| otx_misp |
Archived OTX importer; also consult the OTX module in misp-modules. |
| CERT Australia CTI Toolkit |
Archived toolkit containing STIX/MISP conversion tools. |
| CERT-Bund yara-exporter |
Archived upstream YARA exporter; a MISP-hosted fork is listed above. |
| LOKI |
The Python scanner and its MISP receiver are deprecated upstream. Follow the repository’s successor guidance; do not assume identical MISP integration in the successor. |
| Viper 1.x |
Archived binary analysis framework with a MISP module. Its README points to Viper 2 for the refactor; verify integration availability there. |
| Cuckoo modified |
Earlier sandbox fork with a MISP reporting module. Review its runtime requirements before using it. |
| Automated Payload Test Controller |
Earlier PyMISP-based payload testing scripts with version-specific installation instructions. |
| FireMISP |
FireEye alert import scripts, moved from the former deralexxx repository. |
| PySight2MISP |
Historical FireEye/iSight API integration. |
| misp-to-autofocus |
Converts MISP intelligence to Autofocus queries; check availability of the target service. |
| MISP-MVISION-EDR |
Older McAfee MVISION EDR/OpenDXL integration, formerly linked as MISP-MAR. |
| OpenDXL-ATD-MISP |
Older McAfee ATD/OpenDXL collection workflow. |
| OpenDXL-MISP-IntelMQ-Output |
Earlier IntelMQ/OpenDXL bridge for MISP intelligence. |
| misp-to-sentinel Azure Function |
Earlier integration based on Microsoft’s Graph security API. For the STIX objects Upload Indicators API, see misp2sentinel above. |