On this page
Overview
MISP is a self-hosted Cyber Threat Intelligence platform that structures indicators, malware samples, and incident context as events and exchanges them through sharing controls, taxonomies, galaxies, feeds, and a REST API.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Share indicators as contextual events
Attributes, objects, tags, taxonomies, and galaxies preserve relationships and analysis context beyond a flat IOC list.
Sources: [1]
Best fit
Fits multi-team and cross-organization threat-intelligence operations
Feeds, server synchronization, REST APIs, and formats such as STIX connect collection, enrichment, and distribution workflows for SOC and CSIRT teams.
Sources: [1]
Before adoption
Validate distribution boundaries before handling sensitive data
Incorrect distribution or sharing-group settings can overexpose indicators and incident context. Configure access control, TLS, mail, workers, database and attachment backups, and upgrades before internet exposure.
Sources: [1]
Official sources
- [1]MISP v2.5.48 README(2026-10-04)
- [2]MISP v2.5.48 release(2026-10-04)
- [3]MISP v2.5.48 license(2026-10-04)
Supplemental curator note
Design sharing groups, distribution, authentication, workers, and backups in a closed evaluation environment before loading operational data. These three steps only inspect the fixed source and PHP syntax; they do not install or exercise the MISP service.
Try it in 3 steps
- 1
Clone the reviewed release
Use the reviewed source instead of a moving branch.
git clone --branch v2.5.48 --depth 1 https://github.com/MISP/MISP.git misp-demo && cd misp-demo - 2
Fetch the referenced submodules
Populate libraries and modules referenced by the same checkout.
git submodule update --init --recursive - 3
Check core PHP syntax
With PHP 8.1 or newer and below 9.0, check the event path without starting a database or service.
php -l app/Model/Event.php && php -l app/Controller/EventsController.php
Growth
Growth trends · Last 30 days
6,567 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 280
- Open PRs
- 245
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- misp
- threat-sharing
- threat-hunting
- threatintel
- malware-analysis
- stix
- information-exchange
- fraud-management
- security
- cti
- cybersecurity
- fraud-detection
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- HashiCorp Vault36,337 Stars
1 shared tag(s) · 2 shared category(s)
manage secret storage, issuance, encryption, leases, and revocation under one policy model
Go - JumpServer31,708 Stars
1 shared tag(s) · 2 shared category(s)
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - Infisical29,591 Stars
1 shared tag(s) · 2 shared category(s)
manage secrets, certificates, and privileged access in one security platform
TypeScript - Cap7,924 Stars
1 shared tag(s) · 2 shared category(s)
self-host a privacy-focused CAPTCHA alternative built around proof-of-work and instrumentation challenges
JavaScript - Defguard2,857 Stars
1 shared tag(s) · 2 shared category(s)
combine WireGuard, identity, MFA, and firewall policy in a self-hosted access platform
Rust - Coolify62,563 Stars
1 shared tag(s) · 1 shared category(s) · Same language
Turn your own Linux servers into a Git/Docker-driven application platform
PHP
Report incorrect information
Tell us if any listing information is incorrect or outdated.