awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
MISP avatar

MISP/MISP

0
View on GitHub↗
6,360 stars·1,597 forks·PHP·AGPL-3.0·38 viewswww.misp-project.org↗

MISP

MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities.

The platform distinguishes itself through granular sharing group models that allow per-attribute visibility controls, a workflow automation pipeline for qualifying and publishing threat data, and support for multiple deployment methods including Ansible, Docker, Puppet, and RPM packages. It offers bidirectional TAXII exchange, scheduled push capabilities, and a reverse proxy compatibility layer for large event synchronization. The platform also includes background worker queues for asynchronous processing and plugin-based data format support.

Beyond its core sharing and correlation functions, MISP provides capabilities for importing indicators from PDF reports, managing feed duplication and correlation bloat, and navigating threat data graphically through event graph visualizations. It includes administrative tools for resetting credentials and wiping all data, as well as security hardening measures such as authentication bypass configuration and certificate trust store management. The platform ships with comprehensive documentation in multiple formats and training materials for learning its capabilities.

Features

  • Threat Intelligence Platforms - An open-source platform for collecting, storing, and sharing structured threat intelligence and indicators of compromise.
  • Distribution Controls - Ships granular sharing group models with per-attribute visibility controls for distributing structured threat data.
  • Programmatic Threat Intelligence Interfaces - Ships a documented REST API for programmatic query, creation, update, and deletion of threat data.
  • REST APIs - Provides a documented REST API with OpenAPI specification for programmatic threat intelligence access.
  • Threat Intelligence - Provides a REST API for programmatic querying, creation, and updating of threat intelligence data.
  • Correlation Engines - Provides an attribute-based correlation engine that automatically links matching indicators across events to reveal hidden attack patterns.
  • Threat Object Models - Provides a flexible object model for structuring and linking detailed threat intelligence data.
  • Granular Content Sharing - Distributes events and attributes with per-attribute visibility settings and community controls across instances.
  • Distributed Event Synchronization - Transfers published events to configured remote instances subject to distribution rules and push settings.
  • Threat Data Stores - Persists structured threat data in a flexible object model with cross-referencing capabilities.
  • REST APIs - Provides a full REST API with OpenAPI specification for programmatic interaction with the threat intelligence platform.
  • Threat Intelligence - Provides a documented OpenAPI REST interface for automated threat data retrieval and submission.
  • OpenAPI Specifications - Ships an OpenAPI specification that documents the entire REST API for programmatic threat intelligence access.
  • Security Event Correlation - Ships an attribute-based correlation engine that links matching indicators across events to reveal hidden relationships.
  • Threat Event Pushes - Ships a distributed synchronization protocol for pushing events to remote MISP instances.
  • Threat Intelligence Synchronizers - Implements a distributed synchronization protocol for exchanging events and attributes between instances with advanced filtering.
  • Threat Indicator Correlators - Links matching indicators across events using exact matches, fuzzy hashing, and CIDR blocks to reveal hidden relationships.
  • Distributed Synchronization Protocols - Implements a distributed synchronization protocol for transferring published events between configured remote instances.
  • Threat Intelligence REST APIs - Provides a programmatic OpenAPI interface to query, create, update, and delete threat data using standard HTTP methods.
  • Workflow Automation Pipelines - Runs customizable workflows to qualify, analyze, and publish threat data without manual intervention.
  • Threat Data Workflow Pipelines - Runs customizable pipelines that qualify, analyze, modify, and control publication of threat data automatically.
  • TAXII Exchanges - Implements bidirectional TAXII exchange for receiving and pushing threat intelligence data.
  • Threat - Runs customizable workflows that qualify, analyze, modify, and control publication of threat data automatically.
  • Threat Data Pushes - Ships a scheduled push mechanism for distributing threat intelligence to TAXII servers.
  • Threat Intelligence Format Integrations - Ships formal specifications for JSON, taxonomy, galaxy, and object template formats to enable tool compatibility.
  • Security Tool Integration APIs - Exchanges threat data with NIDS, SIEMs, and other systems via STIX and REST API formats.
  • Message Queue Workers - Processes scheduled tasks and data operations asynchronously through a dedicated background worker queue system.
  • Threat Relationship Visualizations - Provides event graph visualizations for exploring events, correlations, and object relationships.
  • Threat Intelligence Format Specifications - Publishes formal specifications for JSON, taxonomy, galaxy, and object template formats for tool interoperability.
  • Threat Intelligence - Defines formal specifications for JSON, taxonomy, galaxy, and object template formats for threat intelligence exchange.
  • File Format Plugin Support - Uses plugin-based architecture to support JSON, taxonomy, galaxy, and object template data formats.
  • Threat Intelligence - Platform for sharing and collaborating on malware intelligence.
  • Security Lab Environments - Platform for sharing indicators of compromise and threat intelligence.
  • Development And Analysis Tools - Threat intelligence platform with YARA support.
  • Malware Analysis - A platform for sharing threat intelligence and malware indicators.

Star history

Star history chart for misp/mispStar history chart for misp/misp

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with MISP

These projects share indexed features with MISP. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • opencti-platform/openctiOpenCTI-Platform avatar

    OpenCTI-Platform/opencti

    8,812View on GitHub↗

    OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical security data. It functions as a threat intelligence visualization tool and an enterprise security data orchestrator that maps relationships between threat actors, malware, and vulnerabilities. The platform utilizes the STIX and TAXII standards for data representation and exchange, allowing for the sharing and receiving of standardized intelligence bundles. It distinguishes itself by converting complex security information into visual relationship diagrams and geographic maps to ide

    TypeScriptcticybercybersecurity
    View on GitHub↗8,812
  • inquest/threatingestorInQuest avatar

    InQuest/ThreatIngestor

    917View on GitHub↗

    Extract and aggregate threat intelligence.

    Python
    View on GitHub↗917
  • alexandreborges/malwoverviewalexandreborges avatar

    alexandreborges/malwoverview

    3,882View on GitHub↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    View on GitHub↗3,882
  • thehive-project/thehiveTheHive-Project avatar

    TheHive-Project/TheHive

    3,891View on GitHub↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    View on GitHub↗3,891
Compare all 30 related projects→

Frequently asked questions

What does misp/misp do?

MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for…

What are the main features of misp/misp?

The main features of misp/misp are: Threat Intelligence Platforms, Distribution Controls, Programmatic Threat Intelligence Interfaces, REST APIs, Threat Intelligence, Correlation Engines, Threat Object Models, Granular Content Sharing.

Which projects share features with misp/misp?

Projects with overlapping indexed features include: opencti-platform/opencti — OpenCTI is a cyber threat intelligence platform and knowledge base used to store, manage, and analyze technical… inquest/threatingestor — Extract and aggregate threat intelligence. alexandreborges/malwoverview — This project is a Python command-line security tool and malware analysis framework designed for threat intelligence… thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… dtag-dev-sec/tpotce — T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based…