Open source threat intelligence

Intelligence becomes more powerful when it is connected.

MISP gives teams one flexible platform to collect, enrich, correlate, automate, and securely share threat intelligence—from a single indicator to a community-wide knowledge base.

A complete intelligence lifecycle

Built for analysts, communities, and machines

Use structured, machine-readable intelligence without losing the human context behind it. MISP combines day-to-day analyst tools with scalable sharing and automation.

01

Structure & analyse

Turn atomic observations and rich reports into connected, actionable intelligence.

Flexible intelligence model

Describe everything from atomic indicators and selectors to linked objects, tactics, techniques, and detailed Markdown reports.

High-performance correlation

Reveal relationships through exact matches and advanced patterns, including fuzzy hashes and CIDR overlaps, with granular controls.

Analyst collaboration

Add opinions, relationships, comments, sightings, proposals, and counter-analysis directly to shared intelligence.

Context and vocabularies

Apply shareable taxonomies, warning lists, and MISP galaxies for threat actors, malware, ransomware, tools, and MITRE ATT&CK.

Visual exploration

Navigate correlations and build event graphs that connect events, objects, and attributes into a coherent picture.

02

Share & collaborate

Exchange intelligence with the right communities while retaining precise control over distribution.

Granular sharing controls

Use distribution levels and custom sharing groups, down to individual attributes, to match each organisation's sharing policy.

Real-time synchronisation

Automatically exchange events, attributes, and higher-level intelligence among MISP instances and trusted communities.

Delegated publishing

Delegate publication to a trusted community through a simple, pseudo-anonymous sharing mechanism.

Secure notifications

Sign and encrypt notifications with GnuPG or S/MIME according to each user's preferences.

Information integrity

Sign and validate shared information for diverse and sensitive information-sharing communities.

03

Automate & integrate

Connect MISP to your security stack and turn intelligence into repeatable, automated action.

Extensive REST API

Access all intelligence through an OpenAPI-described API, exhaustive restSearch capabilities, and the bundled PyMISP library.

Learn more

Custom workflows

Build automatic data pipelines for qualification, analysis, modification, and publication control.

Enrichment modules

Extend MISP with Python expansion, import, and export modules or connect your own services.

Learn more

Real-time streaming

Publish new events, indicators, sightings, and tagging changes through ZMQ or Kafka channels.

Built-in API tooling

Build, test, and analyse complex queries in the interface with a context-aware, templated API client.

04

Import & export

Move intelligence freely with open standards, common security formats, and adaptable modules.

Broad export support

Generate MISP JSON, STIX 1 and 2, OpenIOC, CSV, text, Suricata, Snort, Zeek, RPZ, forensic cache formats, and more.

Flexible ingestion

Import MISP, STIX, CSV, proprietary formats, URLs, batches, sandbox results, and bulk data through the UI or API.

Free-text conversion

Extract structured reports, objects, and attributes from unstructured text and externally hosted reports.

MISP Standard Format

Rely on a stable, backward-compatible format adopted by tools and organisations around the world.

Learn more

STIX interoperability

Import and export STIX 1 and 2 content through the actively maintained misp-stix library.

Learn more
05

Operate at scale

Deploy a robust platform with the controls and observability required by organisations of any size.

Deployment flexibility

Run MISP on-premise, in the cloud, or as a SaaS solution for teams and communities of any size.

Custom dashboards

Create and share composable dashboards or build bespoke monitoring views in a drag-and-drop interface.

Auditable logging

Track system and user activity with flexible logging formats and transports for centralised monitoring.

Customisable RBAC

Configure permissive internal deployments or tightly regulated community instances with role-based access controls.

Batteries included

Use tooling for backups, identity and authentication integration, leakage prevention, and system monitoring.

06

Open by design

Build on a transparent, community-owned foundation without proprietary lock-in.

Open-source commitment

MISP's contributor-owned licensing ensures the platform cannot be converted into a closed or proprietary product.

Open data model and API

Integrate without lock-in using documented formats, open standards, and a comprehensive API.

Extensible ecosystem

Adapt export modules, enrichment services, taxonomies, galaxies, object templates, and workflows to your needs.

Community-powered

Benefit from an international community that develops software, open standards, knowledge bases, and integrations together.

Start sharing smarter

Put collective intelligence to work.

Deploy MISP, connect your tools, and join a global ecosystem built around open collaboration.