MISP Favicon

MISP

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform designed for sharing, storing, and correlating indicators of compromise and threat data.

Threat Intelligence IOC Management Collaborative Sharing Threat Correlation

Overview

MISP is an open-source threat intelligence platform developed by the Belgian government's CIRCL. It enables organizations to share, store, and correlate indicators of compromise (IOCs) and threat intelligence in a structured manner. MISP supports distributed sharing models, automated correlation, and integration with various security tools. It is widely used by government agencies, financial institutions, ISACs, and security teams for threat intelligence sharing and collaborative defense.

Primary Use Cases

Sharing structured threat intelligence across trusted communities and information sharing groups.
Correlating and enriching indicators of compromise to identify threat actor campaigns.
Integrating threat intelligence into SIEM and security tools for automated detection.

Frequently Asked Questions

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform originally developed by CIRCL, the computer emergency response team of Luxembourg. It provides a flexible and scalable solution for sharing, storing, and correlating threat intelligence data.

Yes, MISP is completely free and open-source under the AGPLv3 license. The source code is available on GitHub, allowing organizations to deploy, customize, and contribute to the platform without licensing costs. This has contributed to its widespread adoption across various sectors.

MISP supports a wide range of threat data types including indicators of compromise (hashes, domains, IPs, URLs), threat actor profiles, campaign information, vulnerability references, and intelligence reports. The platform uses a flexible data model that can be extended with custom attributes to accommodate specific organizational needs.

MISP supports distributed sharing through a federation model where organizations can connect MISP instances together, creating trusted sharing communities with controlled access. The platform includes granular access controls, sharing groups, and different sharing models (public, private, community) to ensure secure and appropriate sharing of threat intelligence.

MISP provides extensive integration capabilities through its REST API, MISP standard format (MISPy), and various plugins. It integrates with SIEM platforms, IDS/IPS systems, firewalls, SOAR tools, and other threat intelligence platforms. MISP supports automated feed consumption, event publishing, and synchronization with external systems for seamless threat intelligence workflows.

Metadata

Official Website Visit Website
Category Info

Platforms and tools for sharing, analyzing, and managing threat intelligence data and indicators of compromise.

Added On

August 18, 2026

Last Updated

August 18, 2026

Threat Intelligence

ThreatConnect is a comprehensive threat intelligence platform acquired by Dataminr in 2025, offering TI Ops, Risk Quantifier, and Polarity c...

Threat Intelligence

Bitsight is a leading enterprise cyber threat intelligence platform that monitors over 40 million organizations globally with AI-enriched OS...

Threat Intelligence

SOCRadar Free Tools is a comprehensive OSINT platform offering free threat intelligence tools for SOC analysts and security professionals.