MISP Integration
MISP bots collect events, look up matching source IPs, create MISP feeds and create events through the MISP API.
An independent tool index
for incident response teams
Feed automation CSIRT-led
Collects and processes security feeds through message-queued bots to automate incident handling, notifications and exchange with other systems.
By CERT.at / IntelMQ community · Austria
Primary sources connect this project to an EU CSIRT as developer or lead.
EU CSIRTs Network Tooling WG names CERT.at as lead; upstream credits a wider European CERT community.
Multi-CSIRT project; Austria identifies the directory-listed lead, not every contributor or all engineering.
identity / capabilities / deployment
README describes message-queued security-feed processing and automated incident workflows for CERTs and CSIRTs.
Read sourcelicense
Actual license text is GNU Affero General Public License version 3.
Read sourceorigin / country
The CSIRTs Network Tooling WG lists IntelMQ with CERT.at as lead.
Read sourcemaintenance
Upstream NEWS records version 3.5.0 released 1 November 2025 and documents a 3.5.1 patch under development.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
MISP bots collect events, look up matching source IPs, create MISP feeds and create events through the MISP API.
Documents event delivery to Elasticsearch through a Redis output bot and Logstash. The walkthrough targets ELK 6.8.0, so current-version setup needs adaptation.
Documents sending events with its TCP output bot to a configured Splunk TCP input.
Reference: 2018-AT-IA-0111
CERT.at reports funded IntelMQ development, including the 2.1 and 2.2 releases, under this 2019–2021 action. The action has closed.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Plan a security feed pipeline with parsing, validation, deduplication, delivery and failure checks. Source-linked guidance for IntelMQ and n6 evaluation.
Automate security feeds without losing context