โ† All cheat sheets

MISP

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

MISP (Malware Information Sharing Platform) is a threat intelligence platform.
Essential for IOC sharing and threat intelligence management.

BASIC CONCEPTS#


    

EVENT#

Container for related threat data
Contains attributes, objects, tags

ATTRIBUTE#

Single IOC or piece of data
Types: IP, domain, hash, URL, etc.

OBJECT#

Collection of related attributes
Templates: file, email, domain-ip, etc.

GALAXY#

Knowledge base of threat actors, tools, etc.
MITRE ATT&CK, threat actors, malware

TAG#

Label for categorization
TLP, confidence, source

ATTRIBUTE TYPES#


    

NETWORK#

ip-src              Source IP
ip-dst              Destination IP
domain              Domain name
hostname            Hostname
url                 URL
uri                 URI
port                Port number
email-src           Source email
email-dst           Destination email

FILE#

md5                 MD5 hash
sha1                SHA1 hash
sha256              SHA256 hash
filename            File name
size-in-bytes       File size
ssdeep              Fuzzy hash
imphash             Import hash
pehash              PE hash

EMAIL#

email-subject       Subject line
email-body          Body content
email-header        Header field
email-attachment    Attachment name

OTHER#

text                Free text
comment             Comment
malware-sample      Malware file
vulnerability       CVE number
yara                YARA rule
sigma               Sigma rule
pattern-*           Pattern indicators

CATEGORIES#

Payload delivery
Artifacts dropped
Payload installation
Persistence mechanism
Network activity
External analysis
Targeting data
Antivirus detection
Attribution
Support Tool
Financial fraud

API USAGE#


    

AUTHENTICATION#

# Header
Authorization: YOUR_API_KEY

# PyMISP
from pymisp import PyMISP
misp = PyMISP('https://misp.local', 'API_KEY', ssl=False)

EVENTS#


    

CREATE EVENT#

POST /events/add
{
  "Event": {
    "info": "Phishing campaign targeting org",
    "distribution": 0,
    "threat_level_id": 2,
    "analysis": 1
  }
}

GET EVENT#

GET /events/view/{eventId}

SEARCH EVENTS#

POST /events/restSearch
{
  "returnFormat": "json",
  "published": true,
  "eventinfo": "ransomware",
  "timestamp": "7d"
}

DISTRIBUTION LEVELS#

0 = Your organization only
1 = This community only
2 = Connected communities
3 = All communities
4 = Sharing group
5 = Inherit event

THREAT LEVEL#

1 = High
2 = Medium
3 = Low
4 = Undefined

ANALYSIS STATUS#

0 = Initial
1 = Ongoing
2 = Complete

ATTRIBUTES#


    

ADD ATTRIBUTE#

POST /attributes/add/{eventId}
{
  "type": "ip-dst",
  "category": "Network activity",
  "value": "192.168.1.100",
  "to_ids": true,
  "comment": "C2 server"
}

SEARCH ATTRIBUTES#

POST /attributes/restSearch
{
  "returnFormat": "json",
  "type": "ip-dst",
  "value": "192.168.1.%",
  "timestamp": "30d"
}

ATTRIBUTE FLAGS#

to_ids          IDS signature worthy
comment         Description
first_seen      First observation time
last_seen       Last observation time

OBJECTS#


    

ADD OBJECT#

POST /objects/add/{eventId}
{
  "Object": {
    "name": "file",
    "Attribute": [
      {"object_relation": "filename", "type": "filename", "value": "malware.exe"},
      {"object_relation": "md5", "type": "md5", "value": "abc123..."},
      {"object_relation": "sha256", "type": "sha256", "value": "def456..."}
    ]
  }
}

COMMON OBJECT TEMPLATES#

file            File with hashes
email           Email message
domain-ip       Domain to IP mapping
http-request    HTTP request details
network-connection  Network connection
url             URL with context
whois           WHOIS data
x509            Certificate

TAGS#


    

ADD TAG#

POST /events/addTag/{eventId}/{tagId}
POST /attributes/addTag/{attributeId}/{tagId}

COMMON TAGS#

tlp:white, tlp:green, tlp:amber, tlp:red
admiralty-scale:1-6
osint
malware
phishing
apt

GALAXIES#


    

ATTACH GALAXY#

POST /events/attachTagToEvent/{eventId}
{
  "tag": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1566.001\""
}

COMMON GALAXIES#

mitre-attack-pattern    MITRE ATT&CK techniques
threat-actor            Known threat actors
malware                 Malware families
tool                    Offensive tools
sector                  Industry sectors
country                 Countries

PYMISP EXAMPLES#


    

SEARCH IOC#

from pymisp import PyMISP
misp = PyMISP('https://misp.local', 'API_KEY')

# Search for IP
results = misp.search(value='192.168.1.100')

# Search by type
results = misp.search(type_attribute='domain')

# Search by time
results = misp.search(timestamp='7d')

CREATE EVENT#

event = MISPEvent()
event.info = "Incident description"
event.distribution = 0
event.threat_level_id = 2
event.analysis = 1

# Add attribute
event.add_attribute('ip-dst', '192.168.1.100', comment='C2')
event.add_attribute('domain', 'evil.com', to_ids=True)

# Create
misp.add_event(event)

ADD ATTRIBUTES#

# To existing event
misp.add_attribute(event_id, {'type': 'ip-dst', 'value': '1.2.3.4'})

# Bulk add
attributes = [
    {'type': 'ip-dst', 'value': '1.2.3.4'},
    {'type': 'domain', 'value': 'evil.com'}
]
misp.add_attribute(event_id, attributes)

EXPORT#

# CSV
results = misp.search(publish_timestamp='7d', return_format='csv')

# STIX
results = misp.search(publish_timestamp='7d', return_format='stix2')

# OpenIOC
results = misp.search(publish_timestamp='7d', return_format='openioc')

FEEDS#


    

ADD FEED#

# Settings > Feeds > Add Feed

FEED TYPES#

MISP Feed
Freetext feed
CSV feed
CIRCL OSINT
Botvrij.eu
malwaredomainlist
abuse.ch

SYNCHRONIZATION#


    

PUSH/PULL#

# Sync > Servers
# Configure remote MISP instances
# Push/pull events between instances

SYNC SETTINGS#

push            Push events to remote
pull            Pull events from remote
push_sightings  Sync sightings
push_galaxy_clusters  Sync galaxies

SIGHTINGS#


    

ADD SIGHTING#

POST /sightings/add/{attributeId}
{
  "source": "Firewall logs",
  "type": 0
}

SIGHTING TYPES#

0 = Sighting
1 = False positive
2 = Expiration

AUTOMATION#


    

WARNINGLISTS#

# Lists to filter false positives
# RFC1918, Microsoft IPs, Google IPs, etc.

TAXONOMIES#

# Standardized vocabularies
# TLP, admiralty-scale, confidence-level

CORRELATION#

# Automatic correlation between events
# Based on matching attribute values

QUICK REFERENCE#

# PyMISP
misp.search(value='192.168.1.100')       # Search
misp.add_event(event)                     # Create event
misp.add_attribute(event_id, attr)        # Add IOC

# API endpoints
GET /events/view/{id}                     # Get event
POST /events/add                          # Create event
POST /attributes/add/{eventId}            # Add attribute
POST /events/restSearch                   # Search
POST /attributes/restSearch               # Search attributes