Warning lists to inform users of MISP about potential false-positives or other information in indicators
-
Updated
Jul 16, 2024 - Python
Warning lists to inform users of MISP about potential false-positives or other information in indicators
OpenCTI Connectors
Threat-Intel repository. API: https://github.com/davidonzo/apiosintDS
Import CrowdStrike Threat Intelligence into your instance of MISP
Clusters and elements to attach to MISP events or attributes (like threat actors)
A HIDS (host-based intrusion detection system) for verifying the integrity of a system.
The CRATOS proxy API integrates with your MISP instance and allows to extract indicators that can be consumed by security components such as SIEM, DNS, Proxies, Firewalls, EDR, NDR and other that can consume a file with indicators.
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Modules for expansion services, enrichment, import and export in MISP and other tools.
MISP Playbooks
Leveraging MISP indicators via a pDNS-based infrastructure as a poor man’s SOC.
This module installs and configures MISP (Malware Information Sharing Platform)
This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
Python library using the MISP Rest API
MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats
Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS.
Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other security tools.
Specifications used in the MISP project including MISP core format
Add a description, image, and links to the misp topic page so that developers can more easily learn about it.
To associate your repository with the misp topic, visit your repo's landing page and select "manage topics."