#misp

6 posts · Last used Aug 11

CTI-Transmute 1.5 released CTI-Transmute is an open-source service for converting threat intelligence between formats - MISP and STIX today, more to come - with a catalogue on top to store, share, comment on and evaluate the results. It wraps the misp-stix library behind a web UI and a public API. 🔗 https://www.misp-project.org/2026/08/11/cti-transmute-v1.5-released.html/ 🔗 https://cti-transmute.org/ #misp #cti #opensource #openstandard #mispstandard #stix #threatintel #threatintelligence #cybersecurity
0
0
0
0
Replying to
MISP Galaxy Threat Actor Explorer v1.0.0 released https://github.com/adulau/threat-actor-explorer #cti #cybersecurity #misp #threatintelligence #threatintel@misp@misp-community.org
7
0
5
0
When I added the threat-actor @misp@misp-community.org galaxy type on Mar 4, 2016, I didn’t expect that, years later, vendors would still invent new names for already known threat actors, avoid using UUIDs, reuse similar names for different actors, and create confusing names by mixing tools or software used by the actors. That’s why we continue the tedious work of maintaining a proper threat-actor database, with relationships to other galaxies such as MITRE ATT&CK, Malpedia, and more. After years of this monastic effort, we’re seeing the benefits—many open-source and proprietary tools now rely on the MISP galaxy, which serves as both an open standard and a public knowledge base. We also maintain a dedicated website for all MISP galaxies. Here’s an example from the threat-actor database: https://www.misp-galaxy.org/threat-actor/relations/fa80877c-f509-4daf-8b62-20aba1635f68/ :github: Repository https://github.com/MISP/misp-galaxy/ 🌐 Public website https://www.misp-galaxy.org/threat-actor/ If you’d like to become a monk (just kidding!) and contribute, feel free to open an issue or submit a pull request on the misp-galaxy repo. In MISP, you can directly benefit from all the galaxies, and you also have advanced functionalities like forking and maintaining an up-to-date private version of the threat-actor database. #threatintel #threatintelligence #opensource #tip #cti #misp
50
1
41
0
---------------- 🛠️ Tool =================== zsazsa CTI is a cyber threat intelligence program management and production platform built around MISP. It links collection, triage, analyst workflows, requirement management, publishing, and stakeholder delivery in a single integrated workflow. The platform targets teams that treat threat intelligence as an operational capability rather than a collection of loose documents and disconnected scripts. Analysts move from source events to validated intelligence products, align output to PIR and GIR priorities, distribute to stakeholders, and feed response back into program maturity signals. Key functional areas: Dashboard provides a live snapshot: active PIRs and GIRs, stakeholder counts, analyser freshness, the last 24 hours of processing, and scraper events awaiting triage. Stakeholders records who receives output, with role, organisation, TLP clearance, product subscriptions, and notification channels. Includes a power and interest matrix for engagement planning. Requirements (PIR and GIR) hold the intelligence questions driving collection, with scope, ownership, and distribution. Adding scope to a requirement highlights matching events in the data collection view. RFIs handle one-off requests from intake to closure, with SLA, owner, linked PIR or GIR, response confidence, attachments, notes, and feedback. Data collection is the cached view of everything arriving from the scraper MISP, other MISP servers, and manual or newsletter sources. Analysts browse and triage events, enrich them with scope from MISP galaxies, generate AI summaries, and start a product straight from a source event. Products form a searchable catalogue: Flash Intel Alerts, Vulnerability Advisories, Daily Threat Briefings, Threat Landscape Reports, Indicator Feeds, and Threat Actor Profiles. Statistics cover pipeline and program metrics, RFI and feedback figures, and a scope coverage view. A CTI-CMM maturity panel maps the program against levels CTI0 to CTI3. MISP integration All operational data resides in MISP using events, object templates, attributes, and event reports. This preserves auditability and allows teams to inspect raw records directly in MISP. The MISP event history serves as an audit trail for every change to a product, stakeholder, or requirement. Product content and supporting context sit together, so analysts move from collection evidence to published output without losing traceability. The built-in reference panel helps teams apply common intelligence concepts consistently, including the Admiralty Scale, TLP, and CTI evaluation criteria. Considerations The platform assumes you are already running or willing to adopt MISP as the backbone of your CTI stack. Teams without an existing MISP instance face additional deployment overhead. The AI summary feature in data collection is mentioned but the underlying model or service is not specified. Not independently verified. For CTI teams struggling with fragmented workflows, zsazsa provides a structured path from collection to delivery with built-in maturity measurement. The MISP-native design eliminates data silos between stages. 🔹 CTI #MISP #threat_intelligence #tool #zsazsa 🔗 Source: https://github.com/zsazsa-project/zsazsa
0
0
0
0
You've seen all posts