# MISP/MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Repository: https://github.com/MISP/MISP
Canonical: https://ross.abutalabs.com/products/misp
Homepage: https://www.misp-project.org/
Language: PHP
License: AGPL-3.0
License Family: copyleft
Topics: misp, threat-sharing, threat-hunting, threatintel, malware-analysis, stix, information-exchange, fraud-management, security, cti, cybersecurity, fraud-detection, fraud-prevention, threat-analysis, information-security, information-sharing, threat-intelligence, threat-intelligence-platform, intelligence, threat-intel
Last push: 2026-08-26T13:08:05+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 4955, "days_push": 7, "days_rel": 8, "gap_med": 9, "n_releases_24m": 60}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6490, forks 1626 (observed 2026-08-28T04:09:43.786982+00:00)

## What it is
MISP is an open source threat intelligence platform for collecting, storing, correlating, and sharing cyber security indicators, malware analysis data, and threat information. It supports structured information exchange between security teams and automated feeds to NIDS, SIEMs, and other tools via formats like STIX and OpenIOC.

## Use cases
- share threat intelligence indicators with partner organizations
- store and correlate indicators of compromise from incidents
- export IOCs to SIEM and intrusion detection systems
- analyze malware and document threat actor TTPs
- synchronize threat feeds between MISP instances
- track financial fraud and vulnerability information
- consume STIX/OpenIOC threat data in automated pipelines

## When to choose
- you need a self-hosted platform for structured threat intelligence sharing across teams or communities
- you want automated IOC correlation and exports to IDS/SIEM tooling
- you need support for open standards like STIX, MISP taxonomies, galaxies, and objects
- your organization collaborates on incident response or threat hunting with external partners

## When to avoid
- you only need a simple log aggregation or SIEM replacement rather than intelligence sharing
- you cannot operate a PHP/MySQL server-side application and prefer a lightweight client-side tool
- you need a turnkey commercial product with vendor support rather than community-driven software

## Facets
- artifact type: application
- maturity: stable
- function: security, search-engine, api-framework, web-framework, analytics, data-visualization, workflow-automation, developer-tools
- domain: security, osint
- platform: self-hosted, php
- tags: threat-intelligence-platform, ioc-sharing, stix, siem-integration, threat-hunting, incident-response, misp, threat-intelligence, information-sharing, malware-analysis, linux, web-server, docker

## Member repositories
- MISP/MISP (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:43.786982+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:44:31.662602+00:00, confidence not recorded.
  - readme: https://github.com/MISP/MISP (fetched 2026-08-28T04:09:43.786982+00:00, sha 3b109f856eca)
  - homepage: https://www.misp-project.org/ (fetched 2026-08-29T08:41:06.334186+00:00, sha da83843e70ca)
  - site_page: https://www.misp-project.org/documentation (fetched 2026-08-29T08:41:06.344105+00:00, sha f0d1df22168a)
  - site_page: https://www.misp-project.org/features (fetched 2026-08-29T08:41:06.346049+00:00, sha febaaf5a1bfa)
  - site_page: https://www.misp-project.org/documentation/openapi.html (fetched 2026-08-29T08:41:06.348080+00:00, sha ab5c18f3989d)
  - site_page: https://www.misp-project.org/who (fetched 2026-08-29T08:41:06.349576+00:00, sha 5cefcc4ea6cb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
