DirectoryCybersecurityMISP

MISP

Open Source

Open source platform for sharing and analyzing cyber threat intelligence

Visit Website

About MISP

MISP is an open source threat intelligence platform designed to collect, store, distribute, and share structured cyber security indicators and threat information. It is built primarily for incident analysts, security professionals, and malware researchers to support their daily operations in efficiently sharing and analyzing threat data. The platform enables organizations to automate the correlation and export of indicators of compromise (IOCs) to various security tools such as IDS and SIEM systems, enhancing threat detection and response capabilities.

MISP emphasizes simplicity and collaboration, allowing users to share threat intelligence within trusted communities to improve collective defense against targeted attacks, financial fraud, and counter-terrorism. It supports rich metadata tagging, visualization dashboards, and integration with open standards like STIX and OpenIOC. The platform also includes extensive taxonomies and galaxy clusters such as MITRE ATT&CK, enabling contextual threat analysis. MISP’s open standards and community-driven approach make it a valuable resource for enterprises seeking to leverage threat intelligence for proactive security operations.

Key Capabilities

  • Structured storage and sharing of threat intelligence
  • Automated correlation and export of IOCs
  • Integration with IDS, SIEM, and other security tools
  • Rich visualization and dashboard options
  • Support for open standards and taxonomies

Integrations

STIXOpenIOCIDS and SIEM systems

Related Buyer Guides

Independent evaluation frameworks for this category.

API Security Platforms
The API is now the primary attack surface, and a WAF pointed at it isn't API security. Evaluate Salt, Akamai (Noname), Imperva, F5, Traceable, Wallarm, Cequence, and Data Theorem on whether they actually discover your shadow APIs and catch BOLA and business-logic abuse at runtime — not just sign endpoints off as “protected.”
Attack Surface Management (ASM / CTEM)
Evaluate Wiz, CrowdStrike Falcon Surface, Microsoft Defender EASM, Cortex Xpanse, Censys, CyCognito, Tenable, and runZero across EASM, CAASM, and platform-embedded camps — judged on discovery accuracy and how cleanly the surface feeds prioritization, not how many assets it claims to find.
Cloud Access Security Broker (CASB)
Evaluate Netskope, Microsoft Defender for Cloud Apps, Zscaler, and Palo Alto for SaaS security, shadow IT discovery, and data protection.

This profile was compiled by CIOPages from public sources with AI assistance, and may be incomplete or out of date. It is informational only and not an endorsement. Represent this vendor? or .

Quick Facts

www.misp-project.org
CategoryCybersecurity
PricingOpen Source
DeploymentOn-Premises, Open Source
Target SizeEnterprise