STIX Capability
Imports and exports STIX 1.1.1, 1.2, 2.0 and 2.1 through the MISP-STIX converter used by MISP core. Conversion uses mapped object types; it is not a guarantee of lossless exchange.
An independent tool index
for incident response teams
Threat intelligence CSIRT-led
Collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools.
By CIRCL and project contributors · Luxembourg
Primary sources connect this project to an EU CSIRT as developer or lead.
The EU CSIRTs Network tooling directory identifies CIRCL as the CSIRT lead. The project also credits Belgian Defence and international contributors; Luxembourg records CIRCL stewardship, not exclusive authorship.
This profile covers the upstream software. Hosting providers and their terms require separate review.
identity / capabilities / deployment
Upstream documentation describes collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools. It documents local installation.
Read sourceorigin / country
The EU CSIRTs Network tooling directory identifies CIRCL as the CSIRT lead. The project also credits Belgian Defence and international contributors; Luxembourg records CIRCL stewardship, not exclusive authorship.
Read sourcelicense
The upstream license file specifies AGPL-3.0.
Read sourcemaintenance
Repository is not archived; its last recorded push was 2026-10-10. This is an activity signal, not a support guarantee.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Imports and exports STIX 1.1.1, 1.2, 2.0 and 2.1 through the MISP-STIX converter used by MISP core. Conversion uses mapped object types; it is not a guarantee of lossless exchange.
Exports indicators in Suricata rule format. This describes rule export, not a bundled Suricata sensor.
Stores Sigma rules and their references in a dedicated Sigma object template. This is rule storage and exchange, not execution of Sigma detections.
Stores YARA rules, rule names, supported versions and optional test-sample hashes in a dedicated YARA object template.
Reference: 2016-LU-IA-0098
The 2017–2019 action supported development of MISP for information sharing. This is a completed funding action, not a statement about current financing.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs