โ† All cheat sheets

THREAT-INTEL-PLATFORMS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Setup, configuration, and usage guide for major threat intelligence
platforms, feeds, and standards.

MISP (MALWARE INFORMATION SHARING PLATFORM)#

Overview:
  - Open-source threat intelligence platform
  - Event-based IOC sharing and correlation
  - STIX/TAXII support
  - Galaxy clusters for threat actor and malware tracking
  - Active community with shared feeds

Installation:
  # Docker (recommended for quick setup)
  git clone https://github.com/MISP/misp-docker.git
  cd misp-docker
  cp template.env .env
  # Edit .env: set MISP_BASEURL, admin email, passwords
  docker compose up -d

  # Manual install (Ubuntu)
  # Follow: https://misp.github.io/MISP/INSTALL.ubuntu2204/

  Default credentials: admin@admin.test / admin

Initial configuration:
  1. Change default admin password immediately
  2. Server Settings > MISP settings:
     - MISP.baseurl: https://your-misp-instance
     - MISP.org: your organization name
     - MISP.email: admin email
  3. Create organizations: Admin > Organizations > Add
  4. Create users: Admin > Users > Add
  5. Configure authentication (LDAP/OIDC if needed)

Adding feeds:
  Sync Actions > Feeds > Add Feed
  Built-in feed sources:
    - CIRCL OSINT Feed
    - Botvrij.eu
    - abuse.ch feeds (URLhaus, MalwareBazaar, ThreatFox)
    - PhishTank
    - OpenPhish

  Enable feeds:
    Sync Actions > Feeds > Fetch and store all feed data
    Set up cron: /var/www/MISP/app/Console/cake Server fetchFeeds
    Schedule: every hour or as appropriate

  Custom feed:
    URL: https://example.com/feed.json
    Source format: MISP, CSV, Freetext
    Headers: if authentication needed

Correlation:
  - MISP auto-correlates attributes across events
  - Correlation engine matches: IPs, domains, hashes, emails
  - View correlations on event page (related events)
  - Disable for high-volume attributes to reduce noise

Key concepts:
  Event:         Container for related IOCs (an incident or report)
  Attribute:     Individual IOC (IP, hash, domain, etc.)
  Object:        Structured group of attributes (file object, network connection)
  Tag:           Labels for categorization (TLP, confidence, threat type)
  Galaxy:        Knowledge base entries (threat actors, malware, tools)
  Taxonomy:      Controlled vocabulary for tagging
  Sighting:      Confirmation that an IOC was observed

PyMISP (Python API):
  pip install pymisp

  from pymisp import PyMISP
  misp = PyMISP('https://misp.example.com', 'API_KEY', ssl=False)

  # Search events
  result = misp.search(controller='events', value='malware.com')

  # Add event
  event = misp.new_event(
      distribution=0,   # your org only
      info='Phishing campaign targeting finance dept',
      analysis=1,       # ongoing
      threat_level_id=2 # medium
  )

  # Add attribute
  misp.add_attribute(event, {
      'type': 'ip-dst',
      'value': '192.168.1.100',
      'category': 'Network activity',
      'to_ids': True
  })

  # Search attributes
  result = misp.search(controller='attributes', type_attribute='ip-dst',
                       value='192.168.1.%')

OPENCTI (OPEN CYBER THREAT INTELLIGENCE)#

Overview:
  - Open-source threat intelligence platform
  - STIX2 native data model
  - Knowledge graph visualization
  - Connector ecosystem for automated enrichment
  - Dashboard and reporting capabilities

Architecture:
  Components:
    - OpenCTI Platform (GraphQL API + React frontend)
    - ElasticSearch / OpenSearch (search and analytics)
    - Redis (caching and message broker)
    - RabbitMQ (connector message queue)
    - MinIO (file storage)
    - Connectors (data import/export/enrichment)

Installation (Docker):
  git clone https://github.com/OpenCTI-Platform/docker.git
  cd docker
  cp .env.sample .env
  # Edit .env: set OPENCTI_ADMIN_EMAIL, TOKEN, passwords
  # Generate UUIDs for connector IDs
  docker compose up -d

  # Access at http://localhost:8080

Connectors:
  Import connectors (data sources):
    - MITRE ATT&CK
    - AlienVault OTX
    - Abuse.ch (URLhaus, MalwareBazaar)
    - MISP Feed
    - CVE (NIST NVD)
    - VirusTotal
    - TheHive
    - OpenCTI Datasets (malware, threat actors)

  Enrichment connectors:
    - VirusTotal (hash/domain/IP enrichment)
    - AbuseIPDB
    - Shodan
    - DomainTools
    - Hybrid Analysis
    - URLhaus

  Export connectors:
    - MISP
    - Splunk
    - Elastic
    - TheHive

  Enable connector:
    docker compose -f docker-compose.yml \
      -f docker-compose.connectors.yml up -d connector-mitre

Data model (STIX2 entities):
  SDO (STIX Domain Objects):
    - Threat Actor, Intrusion Set, Campaign
    - Malware, Tool, Attack Pattern
    - Vulnerability, Identity, Location
    - Report, Note, Opinion
    - Indicator, Observed Data

  SRO (STIX Relationship Objects):
    - uses, targets, attributed-to
    - indicates, mitigates, located-at
    - based-on, delivers, exploits

THEHIVE AND CORTEX INTEGRATION#

TheHive:
  - Open-source Security Incident Response Platform (SIRP)
  - Case management and collaboration
  - Alert triage and escalation
  - Observable management
  - Integrates with MISP and Cortex

Installation:
  # Docker
  docker pull strangebee/thehive:5
  # Follow: https://docs.strangebee.com/thehive/installation/docker/

Key features:
  Cases:        Incident containers with tasks, observables, logs
  Alerts:       Incoming notifications (from SIEM, email, MISP)
  Tasks:        Assignable work items within a case
  Observables:  IOCs attached to cases (IPs, hashes, domains)
  Dashboards:   Customizable views of case metrics

Cortex:
  - Analysis and response engine
  - Analyzers: automated IOC analysis (100+ analyzers)
  - Responders: automated response actions

  Analyzers include:
    - VirusTotal lookup
    - AbuseIPDB check
    - Shodan host info
    - MISP search
    - OTX lookup
    - URLhaus check
    - DomainTools whois
    - Censys lookup
    - PassiveTotal

  Usage:
    1. Add observable to TheHive case
    2. Click "Analyze" -> select analyzers
    3. Review results in observable details
    4. Automated enrichment with all configured analyzers

Integration flow:
  SIEM Alert -> TheHive Alert -> Triage -> Case
  Case Observable -> Cortex Analyzer -> Enriched Data
  Case Observable -> MISP Event -> Sharing with partners

STIX AND TAXII#

STIX (Structured Threat Information eXpression):
  - Standard language for cyber threat intelligence
  - Current version: STIX 2.1
  - JSON-based format

  STIX2 Object Types:
    Attack Pattern:    TTP description (mapped to ATT&CK)
    Campaign:          Set of related intrusion activity
    Identity:          Individuals, organizations, groups
    Indicator:         Pattern for detecting threats
    Intrusion Set:     Grouped adversary behavior
    Malware:           Malicious software description
    Observed Data:     Raw cyber observables
    Report:            Threat intelligence report
    Threat Actor:      Individuals/groups with intent
    Tool:              Legitimate software used by threat actors
    Vulnerability:     CVE or weakness

  STIX2 Indicator example:
    {
      "type": "indicator",
      "id": "indicator--a1b2c3d4-...",
      "created": "2026-03-19T12:00:00Z",
      "name": "Malicious IP",
      "pattern": "[ipv4-addr:value = '203.0.113.100']",
      "pattern_type": "stix",
      "valid_from": "2026-03-19T12:00:00Z",
      "labels": ["malicious-activity"]
    }

  Python STIX2 library:
    pip install stix2

    from stix2 import Indicator, Malware, Relationship, Bundle

    indicator = Indicator(
        name="Malicious Domain",
        pattern="[domain-name:value = 'evil.example.com']",
        pattern_type="stix",
        valid_from="2026-03-19T00:00:00Z"
    )
    malware = Malware(name="EvilBot", is_family=True)
    relationship = Relationship(
        source_ref=indicator.id,
        target_ref=malware.id,
        relationship_type="indicates"
    )
    bundle = Bundle(objects=[indicator, malware, relationship])

TAXII (Trusted Automated eXchange of Intelligence Information):
  - Transport protocol for sharing STIX data
  - Current version: TAXII 2.1
  - RESTful API over HTTPS

  Key concepts:
    API Root:     Base URL for TAXII services
    Collection:   Set of STIX objects (like a feed)
    Channel:      Pub/sub mechanism (TAXII 2.1)

  Python TAXII client:
    pip install taxii2-client

    from taxii2client.v20 import Server, Collection

    server = Server('https://taxii.example.com/taxii/',
                    user='user', password='pass')
    api_root = server.api_roots[0]
    for collection in api_root.collections:
        print(collection.title, collection.id)

    collection = Collection(
        'https://taxii.example.com/api/collections/<ID>/',
        user='user', password='pass')
    content = collection.get_objects()

THREAT FEED SOURCES#

Free feeds:
  AlienVault OTX:
    - https://otx.alienvault.com/
    - Pulses with IOCs from community
    - API: https://otx.alienvault.com/api/
    - STIX/TAXII support

  Abuse.ch:
    URLhaus:         https://urlhaus.abuse.ch/
    MalwareBazaar:   https://bazaar.abuse.ch/
    ThreatFox:       https://threatfox.abuse.ch/
    Feodo Tracker:   https://feodotracker.abuse.ch/
    SSL Blacklist:   https://sslbl.abuse.ch/
    YARAify:         https://yaraify.abuse.ch/

  VirusTotal:
    - https://www.virustotal.com/
    - Free API: 4 lookups/minute
    - Premium: higher limits, hunting, retro-hunting

  PhishTank:
    - https://phishtank.org/
    - Community-submitted phishing URLs
    - API access available

  CIRCL (Computer Incident Response Center Luxembourg):
    - https://www.circl.lu/
    - MISP feeds, passive DNS, passive SSL

  Emerging Threats (Proofpoint):
    - https://rules.emergingthreats.net/
    - Snort/Suricata rules
    - IP reputation lists

  Blocklist.de:
    - https://www.blocklist.de/
    - IP blocklists by attack type

  Spamhaus:
    - https://www.spamhaus.org/
    - SBL, XBL, PBL, DBL, DROP lists

Commercial feeds:
  - Recorded Future
  - CrowdStrike Falcon Intelligence
  - Mandiant Threat Intelligence
  - IBM X-Force Exchange
  - Palo Alto Unit 42
  - Cisco Talos Intelligence

IOC MANAGEMENT#

IOC types and priorities:
  HIGH CONFIDENCE:
    - File hashes (SHA256 preferred, then SHA1, then MD5)
    - X.509 certificate fingerprints
    - YARA rules
    - Snort/Suricata signatures

  MEDIUM CONFIDENCE:
    - IP addresses (consider CDN/shared hosting)
    - Domain names (check for sinkholing)
    - URLs (specific paths)
    - Email addresses
    - Mutex names

  LOW CONFIDENCE (high false positive risk):
    - File names (easily changed)
    - Registry keys (common paths)
    - User-Agent strings
    - Generic file paths

IOC lifecycle:
  1. Collection: gather from feeds, incidents, reports
  2. Normalization: standard format (STIX, CSV)
  3. Enrichment: add context (whois, geolocation, reputation)
  4. Analysis: determine confidence and relevance
  5. Distribution: share with detection tools (SIEM, IDS, EDR)
  6. Operationalization: create detection rules
  7. Review: age-out stale IOCs, update confidence
  8. Feedback: track detection rates, false positives

IOC aging and retention:
  - IP addresses: 30-90 days (IPs change frequently)
  - Domains: 90-180 days (may be re-registered)
  - File hashes: 1-2 years (more persistent)
  - YARA rules: until superseded
  - Review and cull regularly to reduce noise

TIP COMPARISON TABLE#

Feature          | MISP        | OpenCTI      | TheHive
-----------------|-------------|--------------|-------------
License          | AGPL        | Apache 2.0   | AGPL
Primary focus    | IOC sharing | Knowledge    | Incident
                 |             | management   | response
Data model       | MISP events | STIX2 native | Cases/alerts
Visualization    | Basic       | Knowledge    | Dashboard
                 |             | graph        |
API              | REST        | GraphQL      | REST
Correlation      | Built-in    | Built-in     | Via Cortex
Sharing          | MISP sync   | STIX/TAXII   | MISP export
Feeds            | Many built- | Connectors   | Via MISP
                 | in feeds    |              |
Scalability      | Medium      | High         | Medium
Learning curve   | Medium      | High         | Low
Best for         | IOC sharing | CTI analysis | IR/SOC ops
                 | community   | team         |

Integration architecture (recommended):
  Feeds -> MISP (collection & sharing)
       -> OpenCTI (analysis & knowledge base)
       -> TheHive/Cortex (incident response & enrichment)
       -> SIEM/EDR (detection & alerting)

BUILDING A THREAT INTEL PROGRAM#

1. Define requirements:
   - What threats matter to your organization?
   - What decisions will threat intel support?
   - Who are the consumers (SOC, IR, exec, vuln mgmt)?

2. Collection:
   - Subscribe to relevant feeds
   - Join ISACs/ISAOs for your industry
   - Configure automated feed ingestion
   - Establish manual reporting process

3. Processing:
   - Normalize data formats (STIX2)
   - De-duplicate across sources
   - Enrich with context
   - Assign confidence scores

4. Analysis:
   - Map to MITRE ATT&CK
   - Assess relevance to your environment
   - Create threat profiles and reports
   - Track campaigns and threat actors

5. Dissemination:
   - Automated IOC distribution to security tools
   - Regular threat briefings for stakeholders
   - Actionable advisories for IT/security teams
   - Executive-level threat summaries

6. Feedback:
   - Track IOC detection rates
   - Measure false positive rates
   - Refine collection based on value
   - Continuous improvement cycle

REFERENCES#

- MISP Project: https://www.misp-project.org/
- OpenCTI: https://www.opencti.io/
- TheHive: https://thehive-project.org/
- STIX/TAXII: https://oasis-open.github.io/cti-documentation/
- MITRE ATT&CK: https://attack.mitre.org/
- FIRST TLP: https://www.first.org/tlp/