Tools

Software and tools

MISP’s ecosystem includes applications, libraries, shared data models, and integrations for collecting, analysing, sharing, and using threat intelligence. This directory lists the MISP project’s software first, followed by CIRCL projects and third-party integrations.

Choose tools for your use case and check their installation instructions, supported MISP versions, and required service subscriptions. Inclusion here describes functionality; it does not imply that every project has the same maintenance or support policy.

Software within the MISP project

Core, enrichment, and conversion

Project Purpose
MISP The core threat intelligence platform for sharing, correlating, and managing events, indicators, sightings, and contextual information.
PyMISP The official Python client for the MISP REST API; also creates and manipulates MISP events and objects offline.
misp-modules Enrichment, expansion, import, export, and workflow modules. Can also run independently of MISP through its API and web interface.
misp-modules-cli Command-line access to misp-modules.
misp-stix The current Python library and command-line tools for conversion between MISP and STIX formats.
cti-transmute Web service for converting threat intelligence formats using misp-stix.
MISP-Taxii-Server OpenTAXII configuration and supporting tools for exchanging MISP data through TAXII. Check the repository’s supported protocol and dependencies before deployment.
mail_to_misp Creates MISP events from email, principally through mail-server workflows such as Postfix. The older desktop mail-client integrations are unmaintained.
misp-workbench A standalone MISP-compatible analysis stack for ingesting feeds, searching indicators, and generating correlations, with a Python API and Vue frontend.

Enrichment, import, export, and workflow module catalog

The misp-modules documentation and repository provide the module catalog, configuration, and dependencies. Consult that catalog instead of relying on a fixed list of individual Python files, which changes as integrations evolve.

  • Enrichment and expansion: passive DNS/SSL, vulnerability lookup, hash reputation, sandbox results, geolocation, and other contextual sources.
  • Import: external intelligence formats, email, documents, and analysis reports.
  • Export: supported intelligence and reporting formats.
  • Workflow actions: modules used by MISP’s automation workflows.

Some modules require a separate account, API key, paid service plan, or local dependency. Enable the modules appropriate to your deployment.

Data models, validation, and knowledge bases

These resources can also be used by tools that do not run a MISP instance.

Project Purpose
misp-taxonomies Machine-readable taxonomies for classifying intelligence and applying consistent tags.
misp-galaxy Contextual knowledge about threat actors, malware, techniques, tools, and other related entities.
misp-objects Object templates and relationship definitions for structured intelligence.
misp-warninglists Lists of common infrastructure and other values that help identify potential false positives.
misp-noticelist Notices about legal, privacy, policy, and technical implications of particular attributes or objects.
misp-decaying-models Default models for decaying indicator relevance over time.
misp-event-templates Reusable event templates for collecting consistently structured intelligence.
misp-workflow-blueprints Reusable blueprints for MISP’s built-in workflow engine.
misp-feedback Warninglist lookup engine with a daemon, HTTP/Unix-socket access, and command-line client.
misp-validation Prototype rule format and runtimes for language-independent attribute normalization and validation.
misp-engineering-bay Editors and supporting utilities for creating and validating MISP content and data structures.
misp-global-search Full-text search across MISP galaxies, objects, and taxonomies.
threat-intelligence-browser Browser for the MISP Galaxy threat intelligence knowledge base.
threat-actor-intelligence-server REST lookup of threat actors by name, synonym, or UUID using MISP Galaxy data.

Libraries and MCP interfaces

Project Purpose
RustMISP Rust client library for the MISP REST API.
LuaMISP Lua library for creating and manipulating MISP entities.
PyTaxonomies Python access to MISP taxonomies.
PyMISPGalaxies Python access to MISP Galaxy data.
PyMISPWarningLists Python access to MISP warninglists.
PyMISPObjectTemplates Python API for creating and updating MISP object templates.
PyIntel471 Python client for Intel 471’s API.
misp-mcp Model Context Protocol server providing read-only access to MISP events, attributes, objects, and reference data.
misp-galaxy-mcp Model Context Protocol server for searching the MISP Galaxy knowledge base.
ai-connector MISP AI module for event/report summarisation and related assistance; check its documentation for the required MISP feature branch and available use cases.

Investigation, detection, and reporting

Project Purpose
MISP-maltego Maltego transforms for MISP and exploration of MITRE ATT&CK data.
misp-wireshark Wireshark plugin that exports selected packet data in MISP format.
misp-ghidra Integration between Ghidra and MISP for reverse engineering workflows.
bsimvis Binary similarity analysis and visualisation using Ghidra analyzers and BSim.
evtx-toolkit Reads Windows EVTX/Sysmon records and converts them to JSON, MISP objects, and graph data.
misp-sighting-tools Generates sightings from sources such as network packet captures.
misp-sighting-server Standalone service for storing and looking up indicator sightings.
wazuh-integration Wazuh rules and scripts for checking file hashes against MISP and optionally reporting sightings.
misp-expansion Firefox/Chrome extension for looking up selected text or page URLs in MISP.
misp-dashboard Live overview of activity and intelligence from MISP instances.
misp-grafana Grafana dashboards using the MISP ZeroMQ stream and InfluxDB.
widget-collection Additional widgets for MISP’s built-in dashboards.
misp-pandoc-filter Work-in-progress Pandoc filter for turning MISP event reports into PDF documents.
misp-playbooks Jupyter-based operational playbooks using PyMISP for analysis, enrichment, and response.
matrix-misp-bot Basic MISP bot for Matrix.
misp-opendata Publishes and manages metadata for MISP-backed datasets on open-data portals.
misp-takedown Generates takedown notifications through RT/RTIR from MISP events.
yara-misp Exports MISP attributes as YARA rules.
yara-exporter MISP-hosted fork of the YARA exporter for THOR-compatible scanning rules.

Deployment, administration, and testing

Project Purpose
misp-docker Official Docker deployment for MISP and its associated services.
MISP-RPM RPM packaging for MISP.
misp-airgap Deployment and maintenance in air-gapped environments using LXD.
MISP-Fleet-Commander Web application for managing MISP instances and communities.
MISP-Fleet-Commander-Browser-Extension Registers MISP instances in Fleet Commander from the browser.
misp-guard Proxy addon for applying rules to MISP synchronisation traffic.
misp-bump Exchanges MISP synchronisation setup information using encrypted QR codes.
misp-monitoring Monitoring utilities and operational documentation for MISP servers.
misp-usage-statistics Collects and visualises MISP usage statistics.
MISP-sizer Hardware sizing calculator for MISP deployments.
ansible Ansible installation scripts; review supported operating systems and MISP versions.
misp-packer Packer-based virtual machine image builder; its documented image targets Ubuntu 18.04.
misp-cloud Cloud image generation, with AWS support documented in the repository.
misp-vagrant Vagrant deployment definitions for MISP project software.
misp-synchronisation Deploys multiple instances and tests their synchronisation behaviour.
misp_dockerized_testing Earlier Docker-based infrastructure for testing MISP instances.
misp-stix-tests STIX fixtures for testing conversion libraries.
dockerized_training_environment Container-based MISP training environment.
mail_to_misp_test Email fixtures for testing mail_to_misp.
pCraft Generates PCAPs from scripted scenarios for testing and exercises.
cexf Common Exercise Format for describing exercise injects and scenarios.
Synthetic-Exercise-World-Format Structured fictional countries, organisations, sectors, and threat actors for neutral exercises and CTI examples.

Experimental and historical tools

These repositories document earlier implementations or research approaches. Review their dependencies and compatibility before using them with a current MISP deployment.

Project Purpose and context
vintage-misp-workbench Original database export and correlation workbench. The current standalone analysis application is misp-workbench.
MISP-STIX-Converter Earlier MISP/STIX synchronisation implementation. Use misp-stix for the current conversion library.
MISPego Earlier Maltego transforms for adding entities to MISP events; also see MISP-maltego above.
docker-misp Archived Docker implementation; its README directs users to misp-docker.
x_old_misp_docker Older Docker implementation retained separately from misp-docker.
misp-graph Graphviz/GEXF export from MISP XML, with legacy Python dependencies.
data-processing Scripts for extracting and correlating intelligence from MISP data exports.
misp-search Command-line MISP search implementation hosted as a fork.
misp-bloomfilter Builds Bloom filters from MISP XML exports; consult its documented limitations on indicator confidentiality.
misp-privacy-aware-exchange and pypraware Research implementation and Python support for privacy-aware indicator exchange.
sacti MISP-hosted fork for securely aggregating and reporting sightings.
misp-darwin Work-in-progress rules for translating structured MISP intelligence into human-readable reports.

Specifications, training, and supporting repositories

Resource Purpose
misp-rfc and misp-standard.org MISP format specifications and the standards website.
misp-book User and administrator guide.
misp-training and misp-training-lea General training and material for law enforcement/CSIRT information sharing.
MISP-presentations Presentations about MISP.
best-practices-in-threat-intelligence Guidance for threat intelligence operations.
misp-compliance Legal, policy, and procedural templates for operating sharing communities.
misp-iconify and intelligence-icons Icons and visual material for intelligence sharing.
misp-website Source of this website.
cakephp, sachertortephp, and Cake-Resque Framework and background-job dependencies used by MISP.
cti-python-stix2 MISP’s fork of the Python STIX 2 library.
cti-toolkit MISP-hosted fork of the CERT Australia CTI Toolkit.
nginx-proxy MISP-hosted fork of a Docker reverse proxy.
SimpleQueue Experimental multiprocessing queue implementation extracted from AIL.
pdf_fonts Fonts for PyMISP PDF export.
SwiftCodes MISP-hosted fork of a bank identifier dataset.

The MISP organisation’s repository directory is the authoritative inventory for new projects and repository status.

CIRCL projects and services

CIRCL develops MISP and a wider set of security tools and services. The following table covers the projects in the CIRCL open source catalog. Some integrate directly with MISP; others support investigation, enrichment, incident response, or training alongside it.

Projects in the CIRCL catalog

Project Purpose and relationship to MISP Source code
MISP Threat intelligence sharing platform and standards ecosystem. See the MISP software directory above for its tools, libraries, and resources. MISP
AIL Framework Collects and analyses unstructured data to identify information leaks and cyber threats, with MISP event/object export. ail-framework
FlowIntel Investigation and case management with MISP taxonomies/galaxies, enrichment through misp-modules, and MISP export. flowintel
Cerebrate Trusted community and contact management, with interconnection and orchestration of tools such as MISP. cerebrate
Draugnet Submits threat reports to MISP communities without requiring a user account; submission tokens let reporters follow subsequent updates. draugnet
Lookyloo Captures websites and visualises their relationships; can look up indicators in MISP and export captures as MISP events. lookyloo
Pandora Analysis platform for examining suspicious files and understanding their contents and risks. pandora
hashlookup Known-file hash lookup and forensic tools for identifying legitimate files and reducing investigation noise. hashlookup tools
Rulezet Shares, evaluates, and manages detection rules such as YARA, Sigma, and Suricata, with MISP-compatible tag metadata. rulezet-core
Pivotick TypeScript network visualisation library for exploring relationships and interactively pivoting through connected data. Pivotick
Kunai Linux security monitoring and threat hunting with detailed system-event telemetry. kunai
FAnything Network fingerprint format and tooling for correlating protocol and implementation behaviour across SSH, TLS, QUIC, and other protocols. fanything
BinTriage Collection of projects for rapid binary triage and analysis. BinTriage repositories
D4 Project Distributed sensor and analysis framework for collecting and processing security observations and network telemetry. D4 repositories
Typo-squatting Finder Generates, resolves, and assesses look-alike domain names for investigating typo-squatting. Typosquatter repositories
Vulnerability-Lookup Aggregates and correlates vulnerability information and community observations. MISPSight transfers vulnerability sightings from MISP. vulnerability-lookup
GCVE Decentralised vulnerability identifier allocation and publication, with tooling for vulnerability management applications. GCVE repositories
cve-search Imports, indexes, and searches CVE/CPE information locally; accessible through MISP enrichment modules. cve-search
NGSOTI Training material and tools for security operations and threat intelligence. NGSOTI repositories
Neolea Digital forensics and information-sharing training for law enforcement and CSIRT communities. neolea-training-materials
SkillAegis Designs, runs, and monitors exercise scenarios for MISP and other security applications. SkillAegis

Additional CIRCL tools and services

Related services, libraries, and investigation tools are available through CIRCL and its project organisations. Review their individual documentation for access conditions, dependencies, and maintenance status.

Project or service Purpose and relationship to MISP
Lacus Browser capture service using Playwright, usable by AIL and other analysis applications.
hashlookup server and forensic analyser Known-file hash lookup API and analysis of files on forensic targets using CIRCL’s public service.
BGP Ranking Ranks autonomous systems using observed malicious activity.
IPASN History Historical IP-to-ASN lookup for investigating network infrastructure.
CIRCL Passive DNS Historical DNS observations for domains and IP addresses; available through misp-modules and PyPDNS.
CIRCL Passive SSL Observed TLS certificates and associated infrastructure, with MISP enrichment support.
CIRCLean USB document sanitisation, with the PyCIRCLean library and image builder.
URL Abuse URL review, investigation, and abuse reporting; also used by misp-takedown.
Email Abuse Email review and abuse reporting.
Douglas-Quaid Image similarity, correlation, and analysis; Carl-Hauser provides a related testing framework.
Drone Forensic Digital forensic resources and tooling for drones and UAVs.
CIRCL forensic tools Utilities for system forensic investigations.
Factual Rules Generator and Factual Rules Generates and publishes YARA rules for identifying legitimate installed software in forensic acquisitions.
ELF Insight Collects and aggregates information about ELF binaries.
ASN Description History Tracks changes in autonomous-system descriptions.
CIRCL threat intelligence workshop Hands-on notebooks for learning to use CIRCL tools and services.

The CIRCL projects directory links to project documentation and the full repository inventories of CIRCL’s project organisations.

Third-party integrations

These tools are developed by their respective communities or vendors. Check upstream documentation for the current integration, supported API, and product licensing.

Incident response, threat intelligence, and automation

Tool MISP integration
TheHive Incident response platform with MISP integration. Current versions are distributed by StrangeBee; the former public TheHive 3/4 repositories are no longer maintained or distributed.
Cortex MISP analyzer Looks up observables in MISP from Cortex analysis workflows.
IntelMQ Collects, processes, and exchanges security feeds, including MISP input/output bots.
Rapid7 InsightConnect MISP actions and triggers for automation workflows.
RTIR MISP extension Connects RTIR incident handling with MISP.
EclecticIQ Threat intelligence platform; consult the vendor’s current MISP connector documentation.
Hybrid Analysis Analysis reports and intelligence export in MISP format.
Joe Sandbox Sandbox analysis with MISP-format output and integration.

SIEM, detection, and hunting

Tool MISP integration
Elastic MISP integration Ingests threat intelligence through Elastic Agent. This is the current integration rather than the former standalone Filebeat MISP module.
misp42splunk Retrieves MISP intelligence in Splunk and sends data back through alert actions. Also available on Splunkbase.
TA-misp Splunk technology add-on for matching local data against MISP objects/attributes.
misp2sentinel Exports indicators to Microsoft Sentinel using the STIX objects Upload Indicators API. The repository’s older Microsoft Graph approach is deprecated.
Dovehawk Zeek intelligence integration that retrieves indicators from MISP and reports sightings.
misp_to_zeek Exports MISP indicators to Zeek’s intelligence framework.
surimisp Matches MISP indicators against Suricata events.
pymisp-suricata_search Retrieves MISP attributes and generates Suricata rules.
sigmai Generates Sigma rules from MISP indicators. For storing and exchanging existing Sigma rules, MISP also has native Sigma support.
MISP2CbR Converts MISP intelligence into a Carbon Black Response threat feed. Check compatibility with your product version.
MISP CrowdStrike scripts Scripts for exporting MISP indicators to CrowdStrike; review the supported CrowdStrike API before use.

Collection and analyst utilities

Tool MISP integration
misp-scraper Creates MISP events and reports from web pages; also used by the zsazsa CTI platform.
phish2MISP Collects information about phishing URLs and adds it to MISP.
vt2misp Adds VirusTotal results to MISP events as objects.
ja3toMISP Extracts JA3 fingerprints from PCAPs and adds them as MISP objects.
misp_btc Retrieves Bitcoin addresses from MISP and enriches them with transaction information.
misp-bulk-tag Applies tags in bulk through the MISP API.
MISP-PurgeEvents Administration script for deleting selected events. Review its cleanup instructions before use.
MISP-IOC-Validator Validates indicator formats and compares values with known false positives.
MISP-Extractor Retrieves intelligence and automates operations through the MISP API.
misp-extractor Exports selected attribute types to separate files.
BTG IOC search tool with MISP collection support.
threatingestor Extracts and aggregates indicators from feeds, including MISP output support.
ThreatPinchLookup Browser-based indicator lookup with a MISP connector; check browser compatibility.

Other API libraries

Use PyMISP for the official Python API client. Alternative clients expose different subsets of the MISP API.

Library Language and scope
golang-misp Go library focused on MISP search.
mispex Elixir wrapper for the MISP HTTP API.
mispy Alternative Python interface to MISP.

Archived integrations and older examples

These links are retained for users maintaining existing integrations. Archived projects do not receive upstream updates; older examples can depend on historical MISP or vendor APIs.

Integration Status or compatibility context
misp-rb Archived Ruby API wrapper.
DCSO tie2misp Archived importer for DCSO TIE intelligence.
otx_misp Archived OTX importer; also consult the OTX module in misp-modules.
CERT Australia CTI Toolkit Archived toolkit containing STIX/MISP conversion tools.
CERT-Bund yara-exporter Archived upstream YARA exporter; a MISP-hosted fork is listed above.
LOKI The Python scanner and its MISP receiver are deprecated upstream. Follow the repository’s successor guidance; do not assume identical MISP integration in the successor.
Viper 1.x Archived binary analysis framework with a MISP module. Its README points to Viper 2 for the refactor; verify integration availability there.
Cuckoo modified Earlier sandbox fork with a MISP reporting module. Review its runtime requirements before using it.
Automated Payload Test Controller Earlier PyMISP-based payload testing scripts with version-specific installation instructions.
FireMISP FireEye alert import scripts, moved from the former deralexxx repository.
PySight2MISP Historical FireEye/iSight API integration.
misp-to-autofocus Converts MISP intelligence to Autofocus queries; check availability of the target service.
MISP-MVISION-EDR Older McAfee MVISION EDR/OpenDXL integration, formerly linked as MISP-MAR.
OpenDXL-ATD-MISP Older McAfee ATD/OpenDXL collection workflow.
OpenDXL-MISP-IntelMQ-Output Earlier IntelMQ/OpenDXL bridge for MISP intelligence.
misp-to-sentinel Azure Function Earlier integration based on Microsoft’s Graph security API. For the STIX objects Upload Indicators API, see misp2sentinel above.