home.social

#misp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #misp, aggregated by home.social.

fetched live
  1. A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick.

    Source code: github.com/adulau/threat-actor
    Online (in-browser): foo.be/threat-actor-explorer/m
    Discussions and feedback: discourse.ossbase.org/t/playin

    @misp

    #misp #cti #threatintelligence #opensource #threatactor #cybersecurity

  2. A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick.

    Source code: github.com/adulau/threat-actor
    Online (in-browser): foo.be/threat-actor-explorer/m
    Discussions and feedback: discourse.ossbase.org/t/playin

    @misp

    #misp #cti #threatintelligence #opensource #threatactor #cybersecurity

  3. Not sure I’m allowed to leak this yet, but the new MISP dashboard is kind of crazy.

    We didn’t just refresh the old one, we rewrote it completely, and it comes with a whole set of new features and capabilities that change the game quite a bit.

    #misp #cti #dashboard #opensource

    @misp

  4. Not sure I’m allowed to leak this yet, but the new MISP dashboard is kind of crazy.

    We didn’t just refresh the old one, we rewrote it completely, and it comes with a whole set of new features and capabilities that change the game quite a bit.

    #misp #cti #dashboard #opensource

    @misp

  5. Yesterday, in our very warm office, an interesting discussion emerged: there was no dedicated taxonomy for evaluating Cyber Threat Intelligence (CTI) in MISP.

    So, we created one called: cti-evaluation

    🔗 misp-project.org/taxonomies.ht

    My colleagues Théo Geffe and Christian Studer then took it one step further by implementing it in CTI-transmute.

    From discussion to a first implementation and tests in less than 48 hours, not too bad! Feedback on the taxonomy is more than welcome. And you can already test it live on cti-transmute.org

    🔗 cti-transmute.org/convert/deta

    #cti #misp #cybersecurity #threatintelligence #opensource #threatintel

    @misp
    @circl

  6. Yesterday, in our very warm office, an interesting discussion emerged: there was no dedicated taxonomy for evaluating Cyber Threat Intelligence (CTI) in MISP.

    So, we created one called: cti-evaluation

    🔗 misp-project.org/taxonomies.ht

    My colleagues Théo Geffe and Christian Studer then took it one step further by implementing it in CTI-transmute.

    From discussion to a first implementation and tests in less than 48 hours, not too bad! Feedback on the taxonomy is more than welcome. And you can already test it live on cti-transmute.org

    🔗 cti-transmute.org/convert/deta

    #cti #misp #cybersecurity #threatintelligence #opensource #threatintel

    @misp
    @circl

  7. This release includes a major new feature: a graph visualisation for the MISP standard and STIX format, making it easier to explore, understand, and present CTI data structures directly from JSON.

    CTI Transmute is an online service available at cti-transmute.org and also an open source project available on GitHub.

    The FIRST CTI 2026 conference in Munich was a great source of feedback for this release. Many of the improvements and new features introduced in v1.2 came directly from discussions, demonstrations, and feedback gathered during the event. Thank you to everyone who tested, commented, challenged ideas, and shared practical use cases.

    #cti #stix #misp #standard #interoperability #cybersecurity

    🔗 Release notes CTI Transmute github.com/MISP/cti-transmute
    🔗 Release notes misp-stix github.com/MISP/misp-stix/rele

  8. This release includes a major new feature: a graph visualisation for the MISP standard and STIX format, making it easier to explore, understand, and present CTI data structures directly from JSON.

    CTI Transmute is an online service available at cti-transmute.org and also an open source project available on GitHub.

    The FIRST CTI 2026 conference in Munich was a great source of feedback for this release. Many of the improvements and new features introduced in v1.2 came directly from discussions, demonstrations, and feedback gathered during the event. Thank you to everyone who tested, commented, challenged ideas, and shared practical use cases.

    #cti #stix #misp #standard #interoperability #cybersecurity

    🔗 Release notes CTI Transmute github.com/MISP/cti-transmute
    🔗 Release notes misp-stix github.com/MISP/misp-stix/rele

  9. The Synthetic Exercise World Format provides fictional countries, companies, sectors, and threat actors with structured metadata for neutral CTI examples, exercises, interoperability tests, and standards documentation without referencing real-world sensitive entities.

    I just released version 1.0.

    #cti #opensource #misp #cybersecurity #threatintelligence #threatintel

    🔗 GitHub - github.com/MISP/Synthetic-Exer

  10. The Synthetic Exercise World Format provides fictional countries, companies, sectors, and threat actors with structured metadata for neutral CTI examples, exercises, interoperability tests, and standards documentation without referencing real-world sensitive entities.

    I just released version 1.0.

    #cti #opensource #misp #cybersecurity #threatintelligence #threatintel

    🔗 GitHub - github.com/MISP/Synthetic-Exer

  11. Drone and UAV Forensic

    This repository is designed to accelerate the forensic analysis of DIY FPV drones and to help automate technical reporting from seized or recovered artifacts.

    The goal is pragmatic: extract useful evidence faster, normalize outputs, and produce data that can be reused in reports or shared into investigative platforms such as MISP.

    🔗 github.com/CIRCL/Drone-Forensic

    #drone #uav #opensource #dfir #threatintelligence #threatintel #misp #digitalforensics

    @circl
    @misp

  12. Drone and UAV Forensic

    This repository is designed to accelerate the forensic analysis of DIY FPV drones and to help automate technical reporting from seized or recovered artifacts.

    The goal is pragmatic: extract useful evidence faster, normalize outputs, and produce data that can be reused in reports or shared into investigative platforms such as MISP.

    🔗 github.com/CIRCL/Drone-Forensic

    #drone #uav #opensource #dfir #threatintelligence #threatintel #misp #digitalforensics

    @circl
    @misp

  13. Excited to share that the MITRE Fight Fraud Framework™ (F3) is now included in the default MISP galaxy and available across all MISP instances.

    F3 is a curated knowledge base of tactics and techniques used by financial fraud actors, helping analysts structure, share, and enrich fraud-related intelligence more effectively.

    A great step forward for the MISP community and for teams tracking financial fraud.

    🔗 github.com/MISP/misp-galaxy

    @misp
    @circl

    #misp #financialfraud #threatintel #threatintelligence #opensource
    #financial

  14. Excited to share that the MITRE Fight Fraud Framework™ (F3) is now included in the default MISP galaxy and available across all MISP instances.

    F3 is a curated knowledge base of tactics and techniques used by financial fraud actors, helping analysts structure, share, and enrich fraud-related intelligence more effectively.

    A great step forward for the MISP community and for teams tracking financial fraud.

    🔗 github.com/MISP/misp-galaxy

    @misp
    @circl

    #misp #financialfraud #threatintel #threatintelligence #opensource
    #financial

  15. @threatchain general purpose siem, malcolm ids, debian server, opnsense - good combo imo, good licensing,. I may just refactor and use 500gb drives so cost will not be the limiting factor, you can use debian blends too but even some of these specialized apps won't have included forensics-full and this has a ton of super usefull sw, when you have the persistence partition going corner case use cases can be covered better than say something like a bootable iso #rational clear case #mw #smw #yacy 3jenkins #ntop-ng #misp #cms #lamp server #sbom #addons #app armor #selinux #ufw #fail2ban #hardened debian #pentoo

  16. @threatchain general purpose siem, malcolm ids, debian server, opnsense - good combo imo, good licensing,. I may just refactor and use 500gb drives so cost will not be the limiting factor, you can use debian blends too but even some of these specialized apps won't have included forensics-full and this has a ton of super usefull sw, when you have the persistence partition going corner case use cases can be covered better than say something like a bootable iso #rational clear case #mw #smw #yacy 3jenkins #ntop-ng #misp #cms #lamp server #sbom #addons #app armor #selinux #ufw #fail2ban #hardened debian #pentoo

  17. What really impresses me is the creativity still thriving around the MISP project. I maintain MISP warning-lists for years to help filter false positives, and this week @iglocska built a new stand-alone #rust application for fast warning-list lookups, independent of MISP.

    #rust #misp #cybersecurity #cti #threatintelligence #opensource

    @misp

    🔗 Source code of misp-feedback github.com/MISP/misp-feedback
    🔗 misp-warninglists github.com/MISP/misp-warningli

  18. What really impresses me is the creativity still thriving around the MISP project. I maintain MISP warning-lists for years to help filter false positives, and this week @iglocska built a new stand-alone #rust application for fast warning-list lookups, independent of MISP.

    #rust #misp #cybersecurity #cti #threatintelligence #opensource

    @misp

    🔗 Source code of misp-feedback github.com/MISP/misp-feedback
    🔗 misp-warninglists github.com/MISP/misp-warningli

  19. We are happy to announce the release of MISP v2.5.36, which includes new geolocation and map visualisation capabilities, the continued development of the Overmind UI, a new interactive CLI shell UI, important security fixes, and installer improvements.

    #misp #cti #informationsharing #threatintel #opensource

    github.com/MISP/MISP/releases/

  20. We are happy to announce the release of MISP v2.5.36, which includes new geolocation and map visualisation capabilities, the continued development of the Overmind UI, a new interactive CLI shell UI, important security fixes, and installer improvements.

    #misp #cti #informationsharing #threatintel #opensource

    github.com/MISP/MISP/releases/

  21. I'm happy to announce the long-awaited first release of misp-modules-cli version 1.0.0.

    This initial release makes it nifty and convenient to use MISP expansion modules directly from the command line, whether you are working against a local or remote misp-modules service. The goal is simple: bring the power of misp-modules into a lightweight CLI workflow that is easy to script, automate, and integrate into daily analysis work.

    #misp #mispmodules #threatintelligence #threatintel #opensource #cli #cybersecurity #osint

    @misp

    🔗 Release note github.com/MISP/misp-modules-c
    :github: misp-modules-cli github.com/MISP/misp-modules-c
    :github: misp-modules github.com/MISP/misp-modules

  22. I'm happy to announce the long-awaited first release of misp-modules-cli version 1.0.0.

    This initial release makes it nifty and convenient to use MISP expansion modules directly from the command line, whether you are working against a local or remote misp-modules service. The goal is simple: bring the power of misp-modules into a lightweight CLI workflow that is easy to script, automate, and integrate into daily analysis work.

    #misp #mispmodules #threatintelligence #threatintel #opensource #cli #cybersecurity #osint

    @misp

    🔗 Release note github.com/MISP/misp-modules-c
    :github: misp-modules-cli github.com/MISP/misp-modules-c
    :github: misp-modules github.com/MISP/misp-modules

  23. Das Land Hessen geht mit einer MISP-Instanz des Hessen3C einen wichtigen Schritt für die kommunale Informationssicherheit.

    🔎 Strukturierter IoC-Austausch ermöglicht ein gemeinsames Lagebild statt isolierter Reaktion.
    🟢 TLP:GREEN erlaubt die direkte Nutzung im SIEM (z. B. Detektion & Anreicherung).
    🤝 Kommunen werden Teil eines gemeinsamen Sicherheitsnetzwerks.

    Mehrwert:
    • bessere Detektion
    • weniger Blindflug
    • stärkere Zusammenarbeit

    ⚙️ Herausforderung: SIEM/TI-Betrieb ist für viele Kommunen kaum leistbar → ein landesweiter SOC-Dienst wäre ein logischer nächster Schritt.

    💡 Fazit: strategischer Baustein für vernetzte Informationssicherheit.

    hessen3c.de/meldungen-neuigkei

    #ITSicherheit #Kommunen #MISP #SIEM #SOC #Hessen

  24. Das Land Hessen geht mit einer MISP-Instanz des Hessen3C einen wichtigen Schritt für die kommunale Informationssicherheit.

    🔎 Strukturierter IoC-Austausch ermöglicht ein gemeinsames Lagebild statt isolierter Reaktion.
    🟢 TLP:GREEN erlaubt die direkte Nutzung im SIEM (z. B. Detektion & Anreicherung).
    🤝 Kommunen werden Teil eines gemeinsamen Sicherheitsnetzwerks.

    Mehrwert:
    • bessere Detektion
    • weniger Blindflug
    • stärkere Zusammenarbeit

    ⚙️ Herausforderung: SIEM/TI-Betrieb ist für viele Kommunen kaum leistbar → ein landesweiter SOC-Dienst wäre ein logischer nächster Schritt.

    💡 Fazit: strategischer Baustein für vernetzte Informationssicherheit.

    hessen3c.de/meldungen-neuigkei

    #ITSicherheit #Kommunen #MISP #SIEM #SOC #Hessen

  25. 🛡️ New to #MISP? Events are the core building blocks — grouping indicators, context, and analysis into one shareable unit. Learn how to create, structure, and tag events effectively 👇 www.gomisp.com/post/events-... #ThreatIntelligence #SOC #CyberSecurity

    Events in MISP - Creating, Tag...

  26. Is there a guide how to integrate #SIEM systems and #VideoSuvailance systems vor General alarming systems for having physical and Cyber #security in one Palace (if company is not that large ...)

    Or is this just a shit idea ?

    #misp #dones #cyberPhysicalConvergence

  27. Is there a guide how to integrate #SIEM systems and #VideoSuvailance systems vor General alarming systems for having physical and Cyber #security in one Palace (if company is not that large ...)

    Or is this just a shit idea ?

    #misp #dones #cyberPhysicalConvergence

  28. Have You Ever Thought About Drones in MISP?

    To better support the documentation and analysis of drone-related incidents, several new resources have been integrated into MISP.

    #drone #drones #intelligence #misp #opensource #uavs #uav

    @misp

    🔗 misp-project.org/2026/03/10/ha

  29. Have You Ever Thought About Drones in MISP?

    To better support the documentation and analysis of drone-related incidents, several new resources have been integrated into MISP.

    #drone #drones #intelligence #misp #opensource #uavs #uav

    @misp

    🔗 misp-project.org/2026/03/10/ha

  30. Lots of exciting work happening around the MISP project, we’ll reveal more once things are ready 👀

    Meanwhile, a new MISP extension for Ghidra is under active development and steadily growing with awesome new features.

    github.com/MISP/misp-ghidra

    #ghidra #misp #cybersecurity #threatintel #reversing

    @misp
    @circl

  31. Lots of exciting work happening around the MISP project, we’ll reveal more once things are ready 👀

    Meanwhile, a new MISP extension for Ghidra is under active development and steadily growing with awesome new features.

    github.com/MISP/misp-ghidra

    #ghidra #misp #cybersecurity #threatintel #reversing

    @misp
    @circl

  32. Switzerland Operationalizes 24-Hour Critical Infrastructure Cyber Reporting

    The National Cyber Security Centre (NCSC) processed ~65,000 incident reports in 2025, including 222 under the newly mandated 24-hour reporting requirement under the ISG/CSV framework.

    Operational enhancements included:
    • Expanded Cyber Security Hub (1,600 members)
    • 4,615 incident artifacts exchanged via MISP
    • Increased bug bounty deployment across federal IT
    • Open-source vulnerability testing (TYPO3, QGIS)
    • CHF 18.4M total expenditure, including CHF 3.8M IT investment
    This represents a mature shift toward structured national cyber governance: centralized intake, intelligence enrichment, proactive vulnerability reduction, and enforceable compliance.

    From an operational standpoint, rapid disclosure requirements tighten detection cycles and strengthen cross-sector signal correlation.

    Is mandatory reporting the future baseline for critical infrastructure defense?

    Source: industrialcyber.co/reports/swi

    Follow @technadu for global cyber governance and threat intelligence analysis.

    #Infosec #NCSC #MISP #CyberGovernance #CriticalInfrastructure #BugBounty #OpenSourceSecurity #ThreatIntelligence

  33. Sweden just launched a free national threat intelligence sharing platform and your country might have one too.

    MISP SE, launched by Sweden's national CERT in December 2025, lets organizations access real-time indicators of compromise and feed them directly into security systems for automated blocking.

    Sweden isn't alone. MISP is an open-source project from Luxembourg, with national instances across the EU. Outside Europe, the US runs CISA AIS and the UK has NCSC CISP, same concept, different packaging.

    With NIS2 requiring systematic risk management across the EU, these platforms are becoming essential infrastructure.

    Does your national CSIRT offer a MISP instance? Many do, and most are free.

    #cybersecurity #NIS2 #threatintelligence #MISP

  34. Sweden just launched a free national threat intelligence sharing platform and your country might have one too.

    MISP SE, launched by Sweden's national CERT in December 2025, lets organizations access real-time indicators of compromise and feed them directly into security systems for automated blocking.

    Sweden isn't alone. MISP is an open-source project from Luxembourg, with national instances across the EU. Outside Europe, the US runs CISA AIS and the UK has NCSC CISP, same concept, different packaging.

    With NIS2 requiring systematic risk management across the EU, these platforms are becoming essential infrastructure.

    Does your national CSIRT offer a MISP instance? Many do, and most are free.

    #cybersecurity #NIS2 #threatintelligence #MISP

  35. Rulezet v1.3.0 - Structure, Collaboration, and Intelligence

    This release introduces a new way to organize and manage rule bundles, a more capable rule editor, and the first set of social features to support discussion and feedback around shared content. Rulezet.org is the publicly accessible, online version of the platform, available to everyone.

    🔗 Rulezet online rulezet.org/
    🔗 Source code github.com/ngsoti/rulezet-core

    #rulezet #opensource #cybersecurity #threatintelligence #misp #cti

  36. Rulezet v1.3.0 - Structure, Collaboration, and Intelligence

    This release introduces a new way to organize and manage rule bundles, a more capable rule editor, and the first set of social features to support discussion and feedback around shared content. Rulezet.org is the publicly accessible, online version of the platform, available to everyone.

    🔗 Rulezet online rulezet.org/
    🔗 Source code github.com/ngsoti/rulezet-core

    #rulezet #opensource #cybersecurity #threatintelligence #misp #cti

  37. Mill Springs Battlefield National Monument #misp #nationalmonument
    ⚠️ Caution ⚠️
    Issued: 2/4/2026 12:00 AM EST

    02-04-2025 Icy roads and trails

    There are still a few icy areas on some of the trails, Zollicoffer Park, and on vehicle pull offs. Please use caution in the park.

  38. Mill Springs Battlefield National Monument #misp #nationalmonument
    ⛔ Park Closure ⛔
    Issued: 2/1/2026 12:00 AM EST

    Updated 02/01/2026: Winter Storm Partial Closure

    Update 02-01-2026: The Visitor Center has resumed operations today, Sunday February 1, 2026, at 12:00pm. Continue to use caution on all walkways and the parking lot. The battlefield which includes all trails, vehicle pull offs and Zollicoffer Park remain closed due to snow and icy conditions. Park staff will continue (1/2)

  39. While listening to discussions about federated systems and protocols at #fosdem (like the one I’m currently using): I realized something.

    It recently resonated with me through some past and ongoing projects: when people are afraid of federation, they call it “balkanization” or “fragmentation.”

    Sorry for the wording @aristot73

    #federated #opensource #federation #misp #gcve