MISP (Malware Information Sharing Platform & Threat Sharing) is an open source software solution for collecting, storing, distributing and sharing cyber security indicators and threats and analyzing cyber security incidents.
MISP is designed by and for event analysts, security professionals and ICT or reverse engineers to support their day-to-day operations for efficient structured information exchange.
The goal of MISP is to promote the exchange of structured information within the security community. The MISP provides functions to support the exchange of information, but also the consumption of information from Network intrusion Detection System (NIDS), LIDS but also log analysis tools, SIEMs.
Information sharing leads to faster detection targeted attacks and improves detection ratio while reducing false threats. We also avoid reverse engineering similar malware, as we know very quickly that other teams or organizations have already analyzed a particular malware.
Specifications
- efficient IOC and indicators
- correlation
- flexible data model
- sharing functionality
- intuitive user-interface
- storing data
- export
- import
- free text import
- Collaborate
- data-sharing
- delegating of sharing
- API
- Adjustable taxonomy
- Intelligence vocabularies
- Expansion modules in Python
- Sighting support
- STIX support
- Integrated encryption and signing of the notifications
Application snapshots
You can download it program from here.
Instructions on installation of the program you will find here.
Instructions for using the program can be found here.