OSS TanbouSign in with GitHub

share threat indicators, events, and taxonomies across organizations for analysis and automation

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
6,567
Primary language
PHP
License
AGPL-3.0
Repository last updated
Oct 3, 2026
On this page

Overview

MISP is a self-hosted Cyber Threat Intelligence platform that structures indicators, malware samples, and incident context as events and exchanges them through sharing controls, taxonomies, galaxies, feeds, and a REST API.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Share indicators as contextual events

Attributes, objects, tags, taxonomies, and galaxies preserve relationships and analysis context beyond a flat IOC list.

Sources: [1]

Best fit

Fits multi-team and cross-organization threat-intelligence operations

Feeds, server synchronization, REST APIs, and formats such as STIX connect collection, enrichment, and distribution workflows for SOC and CSIRT teams.

Sources: [1]

Before adoption

Validate distribution boundaries before handling sensitive data

Incorrect distribution or sharing-group settings can overexpose indicators and incident context. Configure access control, TLS, mail, workers, database and attachment backups, and upgrades before internet exposure.

Sources: [1]

Official sources

  1. [1]MISP v2.5.48 README(2026-10-04)
  2. [2]MISP v2.5.48 release(2026-10-04)
  3. [3]MISP v2.5.48 license(2026-10-04)
Supplemental curator note

Design sharing groups, distribution, authentication, workers, and backups in a closed evaluation environment before loading operational data. These three steps only inspect the fixed source and PHP syntax; they do not install or exercise the MISP service.

Try it in 3 steps

  1. 1

    Clone the reviewed release

    Use the reviewed source instead of a moving branch.

    git clone --branch v2.5.48 --depth 1 https://github.com/MISP/MISP.git misp-demo && cd misp-demo
  2. 2

    Fetch the referenced submodules

    Populate libraries and modules referenced by the same checkout.

    git submodule update --init --recursive
  3. 3

    Check core PHP syntax

    With PHP 8.1 or newer and below 9.0, check the event path without starting a database or service.

    php -l app/Model/Event.php && php -l app/Controller/EventsController.php
Check the official README

Growth

Growth trends · Last 30 days

6,567 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
280
Open PRs
245

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • misp
  • threat-sharing
  • threat-hunting
  • threatintel
  • malware-analysis
  • stix
  • information-exchange
  • fraud-management
  • security
  • cti
  • cybersecurity
  • fraud-detection
Stars
6,567
Forks
1,642
Watchers
282
Open issues
2,700
Contributors
286
Owner type
Organization
Primary language
PHP
License
AGPL-3.0
Repository last updated
Oct 3, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?