MISP/MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform observed · 2026-08-28
Health v2 · maintenance only
99/100
- Activity 99
- Release rhythm 99
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 9
- age_days: 4955
- days_rel: 8
- days_push: 7
- n_releases_24m: 60
Adoption not part of the score
6490 stars · 1626 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
MISP is an open source threat intelligence platform for collecting, storing, correlating, and sharing cyber security indicators, malware analysis data, and threat information. It supports structured information exchange between security teams and automated feeds to NIDS, SIEMs, and other tools via formats like STIX and OpenIOC.
Use cases
- share threat intelligence indicators with partner organizations
- store and correlate indicators of compromise from incidents
- export IOCs to SIEM and intrusion detection systems
- analyze malware and document threat actor TTPs
- synchronize threat feeds between MISP instances
- track financial fraud and vulnerability information
- consume STIX/OpenIOC threat data in automated pipelines
When to choose
- you need a self-hosted platform for structured threat intelligence sharing across teams or communities
- you want automated IOC correlation and exports to IDS/SIEM tooling
- you need support for open standards like STIX, MISP taxonomies, galaxies, and objects
- your organization collaborates on incident response or threat hunting with external partners
When to avoid
- you only need a simple log aggregation or SIEM replacement rather than intelligence sharing
- you cannot operate a PHP/MySQL server-side application and prefer a lightweight client-side tool
- you need a turnkey commercial product with vendor support rather than community-driven software
Facets
application · maturity stable
security search-engine api-framework web-framework analytics data-visualization workflow-automation developer-tools security osint self-hosted php threat-intelligence-platform ioc-sharing stix siem-integration threat-hunting incident-response misp threat-intelligence information-sharing malware-analysis linux web-server docker
6 sources
- readme: https://github.com/MISP/MISP · fetched 2026-08-28 · 3b109f856eca
- homepage: https://www.misp-project.org/ · fetched 2026-08-29 · da83843e70ca
- site_page: https://www.misp-project.org/documentation · fetched 2026-08-29 · f0d1df22168a
- site_page: https://www.misp-project.org/features · fetched 2026-08-29 · febaaf5a1bfa
- site_page: https://www.misp-project.org/documentation/openapi.html · fetched 2026-08-29 · ab5c18f3989d
- site_page: https://www.misp-project.org/who · fetched 2026-08-29 · 5cefcc4ea6cb
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| MISP/MISP | main | 99 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem