Threat intelligence CSIRT-led

MISP

Collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The EU CSIRTs Network tooling directory identifies CIRCL as the CSIRT lead. The project also credits Belgian Defence and international contributors; Luxembourg records CIRCL stewardship, not exclusive authorship.

Reported capabilities

  • Correlates indicators and related intelligence objects.
  • Supports MISP, STIX and detection-rule export workflows.

Scope and limits

This profile covers the upstream software. Hosting providers and their terms require separate review.

Inspect the research evidence 4 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools. It documents local installation.

    Read source
  2. origin / country

    The EU CSIRTs Network tooling directory identifies CIRCL as the CSIRT lead. The project also credits Belgian Defence and international contributors; Luxembourg records CIRCL stewardship, not exclusive authorship.

    Read source
  3. license

    The upstream license file specifies AGPL-3.0.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-10-10. This is an activity signal, not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

STIX Capability

Imports and exports STIX 1.1.1, 1.2, 2.0 and 2.1 through the MISP-STIX converter used by MISP core. Conversion uses mapped object types; it is not a guarantee of lossless exchange.

Sigma Capability

Stores Sigma rules and their references in a dedicated Sigma object template. This is rule storage and exchange, not execution of Sigma detections.

YARA Capability

Stores YARA rules, rule names, supported versions and optional test-sample hashes in a dedicated YARA object template.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs