MISP
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
MISP (Malware Information Sharing Platform) is a threat intelligence platform. Essential for IOC sharing and threat intelligence management.
BASIC CONCEPTS#
EVENT#
Container for related threat data Contains attributes, objects, tags
ATTRIBUTE#
Single IOC or piece of data Types: IP, domain, hash, URL, etc.
OBJECT#
Collection of related attributes Templates: file, email, domain-ip, etc.
GALAXY#
Knowledge base of threat actors, tools, etc. MITRE ATT&CK, threat actors, malware
TAG#
Label for categorization TLP, confidence, source
ATTRIBUTE TYPES#
NETWORK#
ip-src Source IP ip-dst Destination IP domain Domain name hostname Hostname url URL uri URI port Port number email-src Source email email-dst Destination email
FILE#
md5 MD5 hash sha1 SHA1 hash sha256 SHA256 hash filename File name size-in-bytes File size ssdeep Fuzzy hash imphash Import hash pehash PE hash
EMAIL#
email-subject Subject line email-body Body content email-header Header field email-attachment Attachment name
OTHER#
text Free text comment Comment malware-sample Malware file vulnerability CVE number yara YARA rule sigma Sigma rule pattern-* Pattern indicators
CATEGORIES#
Payload delivery Artifacts dropped Payload installation Persistence mechanism Network activity External analysis Targeting data Antivirus detection Attribution Support Tool Financial fraud
API USAGE#
AUTHENTICATION#
# Header
Authorization: YOUR_API_KEY
# PyMISP
from pymisp import PyMISP
misp = PyMISP('https://misp.local', 'API_KEY', ssl=False)
EVENTS#
CREATE EVENT#
POST /events/add
{
"Event": {
"info": "Phishing campaign targeting org",
"distribution": 0,
"threat_level_id": 2,
"analysis": 1
}
}
GET EVENT#
GET /events/view/{eventId}
SEARCH EVENTS#
POST /events/restSearch
{
"returnFormat": "json",
"published": true,
"eventinfo": "ransomware",
"timestamp": "7d"
}
DISTRIBUTION LEVELS#
0 = Your organization only 1 = This community only 2 = Connected communities 3 = All communities 4 = Sharing group 5 = Inherit event
THREAT LEVEL#
1 = High 2 = Medium 3 = Low 4 = Undefined
ANALYSIS STATUS#
0 = Initial 1 = Ongoing 2 = Complete
ATTRIBUTES#
ADD ATTRIBUTE#
POST /attributes/add/{eventId}
{
"type": "ip-dst",
"category": "Network activity",
"value": "192.168.1.100",
"to_ids": true,
"comment": "C2 server"
}
SEARCH ATTRIBUTES#
POST /attributes/restSearch
{
"returnFormat": "json",
"type": "ip-dst",
"value": "192.168.1.%",
"timestamp": "30d"
}
ATTRIBUTE FLAGS#
to_ids IDS signature worthy comment Description first_seen First observation time last_seen Last observation time
OBJECTS#
ADD OBJECT#
POST /objects/add/{eventId}
{
"Object": {
"name": "file",
"Attribute": [
{"object_relation": "filename", "type": "filename", "value": "malware.exe"},
{"object_relation": "md5", "type": "md5", "value": "abc123..."},
{"object_relation": "sha256", "type": "sha256", "value": "def456..."}
]
}
}
COMMON OBJECT TEMPLATES#
file File with hashes email Email message domain-ip Domain to IP mapping http-request HTTP request details network-connection Network connection url URL with context whois WHOIS data x509 Certificate
TAGS#
ADD TAG#
POST /events/addTag/{eventId}/{tagId}
POST /attributes/addTag/{attributeId}/{tagId}
COMMON TAGS#
tlp:white, tlp:green, tlp:amber, tlp:red admiralty-scale:1-6 osint malware phishing apt
GALAXIES#
ATTACH GALAXY#
POST /events/attachTagToEvent/{eventId}
{
"tag": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\""
}
COMMON GALAXIES#
mitre-attack-pattern MITRE ATT&CK techniques threat-actor Known threat actors malware Malware families tool Offensive tools sector Industry sectors country Countries
PYMISP EXAMPLES#
SEARCH IOC#
from pymisp import PyMISP
misp = PyMISP('https://misp.local', 'API_KEY')
# Search for IP
results = misp.search(value='192.168.1.100')
# Search by type
results = misp.search(type_attribute='domain')
# Search by time
results = misp.search(timestamp='7d')
CREATE EVENT#
event = MISPEvent()
event.info = "Incident description"
event.distribution = 0
event.threat_level_id = 2
event.analysis = 1
# Add attribute
event.add_attribute('ip-dst', '192.168.1.100', comment='C2')
event.add_attribute('domain', 'evil.com', to_ids=True)
# Create
misp.add_event(event)
ADD ATTRIBUTES#
# To existing event
misp.add_attribute(event_id, {'type': 'ip-dst', 'value': '1.2.3.4'})
# Bulk add
attributes = [
{'type': 'ip-dst', 'value': '1.2.3.4'},
{'type': 'domain', 'value': 'evil.com'}
]
misp.add_attribute(event_id, attributes)
EXPORT#
# CSV results = misp.search(publish_timestamp='7d', return_format='csv') # STIX results = misp.search(publish_timestamp='7d', return_format='stix2') # OpenIOC results = misp.search(publish_timestamp='7d', return_format='openioc')
FEEDS#
ADD FEED#
# Settings > Feeds > Add Feed
FEED TYPES#
MISP Feed Freetext feed CSV feed
POPULAR FEEDS#
CIRCL OSINT Botvrij.eu malwaredomainlist abuse.ch
SYNCHRONIZATION#
PUSH/PULL#
# Sync > Servers # Configure remote MISP instances # Push/pull events between instances
SYNC SETTINGS#
push Push events to remote pull Pull events from remote push_sightings Sync sightings push_galaxy_clusters Sync galaxies
SIGHTINGS#
ADD SIGHTING#
POST /sightings/add/{attributeId}
{
"source": "Firewall logs",
"type": 0
}
SIGHTING TYPES#
0 = Sighting 1 = False positive 2 = Expiration
AUTOMATION#
WARNINGLISTS#
# Lists to filter false positives # RFC1918, Microsoft IPs, Google IPs, etc.
TAXONOMIES#
# Standardized vocabularies # TLP, admiralty-scale, confidence-level
CORRELATION#
# Automatic correlation between events # Based on matching attribute values
QUICK REFERENCE#
# PyMISP
misp.search(value='192.168.1.100') # Search
misp.add_event(event) # Create event
misp.add_attribute(event_id, attr) # Add IOC
# API endpoints
GET /events/view/{id} # Get event
POST /events/add # Create event
POST /attributes/add/{eventId} # Add attribute
POST /events/restSearch # Search
POST /attributes/restSearch # Search attributes