THREAT-INTEL-PLATFORMS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Setup, configuration, and usage guide for major threat intelligence platforms, feeds, and standards.
MISP (MALWARE INFORMATION SHARING PLATFORM)#
Overview:
- Open-source threat intelligence platform
- Event-based IOC sharing and correlation
- STIX/TAXII support
- Galaxy clusters for threat actor and malware tracking
- Active community with shared feeds
Installation:
# Docker (recommended for quick setup)
git clone https://github.com/MISP/misp-docker.git
cd misp-docker
cp template.env .env
# Edit .env: set MISP_BASEURL, admin email, passwords
docker compose up -d
# Manual install (Ubuntu)
# Follow: https://misp.github.io/MISP/INSTALL.ubuntu2204/
Default credentials: admin@admin.test / admin
Initial configuration:
1. Change default admin password immediately
2. Server Settings > MISP settings:
- MISP.baseurl: https://your-misp-instance
- MISP.org: your organization name
- MISP.email: admin email
3. Create organizations: Admin > Organizations > Add
4. Create users: Admin > Users > Add
5. Configure authentication (LDAP/OIDC if needed)
Adding feeds:
Sync Actions > Feeds > Add Feed
Built-in feed sources:
- CIRCL OSINT Feed
- Botvrij.eu
- abuse.ch feeds (URLhaus, MalwareBazaar, ThreatFox)
- PhishTank
- OpenPhish
Enable feeds:
Sync Actions > Feeds > Fetch and store all feed data
Set up cron: /var/www/MISP/app/Console/cake Server fetchFeeds
Schedule: every hour or as appropriate
Custom feed:
URL: https://example.com/feed.json
Source format: MISP, CSV, Freetext
Headers: if authentication needed
Correlation:
- MISP auto-correlates attributes across events
- Correlation engine matches: IPs, domains, hashes, emails
- View correlations on event page (related events)
- Disable for high-volume attributes to reduce noise
Key concepts:
Event: Container for related IOCs (an incident or report)
Attribute: Individual IOC (IP, hash, domain, etc.)
Object: Structured group of attributes (file object, network connection)
Tag: Labels for categorization (TLP, confidence, threat type)
Galaxy: Knowledge base entries (threat actors, malware, tools)
Taxonomy: Controlled vocabulary for tagging
Sighting: Confirmation that an IOC was observed
PyMISP (Python API):
pip install pymisp
from pymisp import PyMISP
misp = PyMISP('https://misp.example.com', 'API_KEY', ssl=False)
# Search events
result = misp.search(controller='events', value='malware.com')
# Add event
event = misp.new_event(
distribution=0, # your org only
info='Phishing campaign targeting finance dept',
analysis=1, # ongoing
threat_level_id=2 # medium
)
# Add attribute
misp.add_attribute(event, {
'type': 'ip-dst',
'value': '192.168.1.100',
'category': 'Network activity',
'to_ids': True
})
# Search attributes
result = misp.search(controller='attributes', type_attribute='ip-dst',
value='192.168.1.%')
OPENCTI (OPEN CYBER THREAT INTELLIGENCE)#
Overview:
- Open-source threat intelligence platform
- STIX2 native data model
- Knowledge graph visualization
- Connector ecosystem for automated enrichment
- Dashboard and reporting capabilities
Architecture:
Components:
- OpenCTI Platform (GraphQL API + React frontend)
- ElasticSearch / OpenSearch (search and analytics)
- Redis (caching and message broker)
- RabbitMQ (connector message queue)
- MinIO (file storage)
- Connectors (data import/export/enrichment)
Installation (Docker):
git clone https://github.com/OpenCTI-Platform/docker.git
cd docker
cp .env.sample .env
# Edit .env: set OPENCTI_ADMIN_EMAIL, TOKEN, passwords
# Generate UUIDs for connector IDs
docker compose up -d
# Access at http://localhost:8080
Connectors:
Import connectors (data sources):
- MITRE ATT&CK
- AlienVault OTX
- Abuse.ch (URLhaus, MalwareBazaar)
- MISP Feed
- CVE (NIST NVD)
- VirusTotal
- TheHive
- OpenCTI Datasets (malware, threat actors)
Enrichment connectors:
- VirusTotal (hash/domain/IP enrichment)
- AbuseIPDB
- Shodan
- DomainTools
- Hybrid Analysis
- URLhaus
Export connectors:
- MISP
- Splunk
- Elastic
- TheHive
Enable connector:
docker compose -f docker-compose.yml \
-f docker-compose.connectors.yml up -d connector-mitre
Data model (STIX2 entities):
SDO (STIX Domain Objects):
- Threat Actor, Intrusion Set, Campaign
- Malware, Tool, Attack Pattern
- Vulnerability, Identity, Location
- Report, Note, Opinion
- Indicator, Observed Data
SRO (STIX Relationship Objects):
- uses, targets, attributed-to
- indicates, mitigates, located-at
- based-on, delivers, exploits
THEHIVE AND CORTEX INTEGRATION#
TheHive:
- Open-source Security Incident Response Platform (SIRP)
- Case management and collaboration
- Alert triage and escalation
- Observable management
- Integrates with MISP and Cortex
Installation:
# Docker
docker pull strangebee/thehive:5
# Follow: https://docs.strangebee.com/thehive/installation/docker/
Key features:
Cases: Incident containers with tasks, observables, logs
Alerts: Incoming notifications (from SIEM, email, MISP)
Tasks: Assignable work items within a case
Observables: IOCs attached to cases (IPs, hashes, domains)
Dashboards: Customizable views of case metrics
Cortex:
- Analysis and response engine
- Analyzers: automated IOC analysis (100+ analyzers)
- Responders: automated response actions
Analyzers include:
- VirusTotal lookup
- AbuseIPDB check
- Shodan host info
- MISP search
- OTX lookup
- URLhaus check
- DomainTools whois
- Censys lookup
- PassiveTotal
Usage:
1. Add observable to TheHive case
2. Click "Analyze" -> select analyzers
3. Review results in observable details
4. Automated enrichment with all configured analyzers
Integration flow:
SIEM Alert -> TheHive Alert -> Triage -> Case
Case Observable -> Cortex Analyzer -> Enriched Data
Case Observable -> MISP Event -> Sharing with partners
STIX AND TAXII#
STIX (Structured Threat Information eXpression):
- Standard language for cyber threat intelligence
- Current version: STIX 2.1
- JSON-based format
STIX2 Object Types:
Attack Pattern: TTP description (mapped to ATT&CK)
Campaign: Set of related intrusion activity
Identity: Individuals, organizations, groups
Indicator: Pattern for detecting threats
Intrusion Set: Grouped adversary behavior
Malware: Malicious software description
Observed Data: Raw cyber observables
Report: Threat intelligence report
Threat Actor: Individuals/groups with intent
Tool: Legitimate software used by threat actors
Vulnerability: CVE or weakness
STIX2 Indicator example:
{
"type": "indicator",
"id": "indicator--a1b2c3d4-...",
"created": "2026-03-19T12:00:00Z",
"name": "Malicious IP",
"pattern": "[ipv4-addr:value = '203.0.113.100']",
"pattern_type": "stix",
"valid_from": "2026-03-19T12:00:00Z",
"labels": ["malicious-activity"]
}
Python STIX2 library:
pip install stix2
from stix2 import Indicator, Malware, Relationship, Bundle
indicator = Indicator(
name="Malicious Domain",
pattern="[domain-name:value = 'evil.example.com']",
pattern_type="stix",
valid_from="2026-03-19T00:00:00Z"
)
malware = Malware(name="EvilBot", is_family=True)
relationship = Relationship(
source_ref=indicator.id,
target_ref=malware.id,
relationship_type="indicates"
)
bundle = Bundle(objects=[indicator, malware, relationship])
TAXII (Trusted Automated eXchange of Intelligence Information):
- Transport protocol for sharing STIX data
- Current version: TAXII 2.1
- RESTful API over HTTPS
Key concepts:
API Root: Base URL for TAXII services
Collection: Set of STIX objects (like a feed)
Channel: Pub/sub mechanism (TAXII 2.1)
Python TAXII client:
pip install taxii2-client
from taxii2client.v20 import Server, Collection
server = Server('https://taxii.example.com/taxii/',
user='user', password='pass')
api_root = server.api_roots[0]
for collection in api_root.collections:
print(collection.title, collection.id)
collection = Collection(
'https://taxii.example.com/api/collections/<ID>/',
user='user', password='pass')
content = collection.get_objects()
THREAT FEED SOURCES#
Free feeds:
AlienVault OTX:
- https://otx.alienvault.com/
- Pulses with IOCs from community
- API: https://otx.alienvault.com/api/
- STIX/TAXII support
Abuse.ch:
URLhaus: https://urlhaus.abuse.ch/
MalwareBazaar: https://bazaar.abuse.ch/
ThreatFox: https://threatfox.abuse.ch/
Feodo Tracker: https://feodotracker.abuse.ch/
SSL Blacklist: https://sslbl.abuse.ch/
YARAify: https://yaraify.abuse.ch/
VirusTotal:
- https://www.virustotal.com/
- Free API: 4 lookups/minute
- Premium: higher limits, hunting, retro-hunting
PhishTank:
- https://phishtank.org/
- Community-submitted phishing URLs
- API access available
CIRCL (Computer Incident Response Center Luxembourg):
- https://www.circl.lu/
- MISP feeds, passive DNS, passive SSL
Emerging Threats (Proofpoint):
- https://rules.emergingthreats.net/
- Snort/Suricata rules
- IP reputation lists
Blocklist.de:
- https://www.blocklist.de/
- IP blocklists by attack type
Spamhaus:
- https://www.spamhaus.org/
- SBL, XBL, PBL, DBL, DROP lists
Commercial feeds:
- Recorded Future
- CrowdStrike Falcon Intelligence
- Mandiant Threat Intelligence
- IBM X-Force Exchange
- Palo Alto Unit 42
- Cisco Talos Intelligence
IOC MANAGEMENT#
IOC types and priorities:
HIGH CONFIDENCE:
- File hashes (SHA256 preferred, then SHA1, then MD5)
- X.509 certificate fingerprints
- YARA rules
- Snort/Suricata signatures
MEDIUM CONFIDENCE:
- IP addresses (consider CDN/shared hosting)
- Domain names (check for sinkholing)
- URLs (specific paths)
- Email addresses
- Mutex names
LOW CONFIDENCE (high false positive risk):
- File names (easily changed)
- Registry keys (common paths)
- User-Agent strings
- Generic file paths
IOC lifecycle:
1. Collection: gather from feeds, incidents, reports
2. Normalization: standard format (STIX, CSV)
3. Enrichment: add context (whois, geolocation, reputation)
4. Analysis: determine confidence and relevance
5. Distribution: share with detection tools (SIEM, IDS, EDR)
6. Operationalization: create detection rules
7. Review: age-out stale IOCs, update confidence
8. Feedback: track detection rates, false positives
IOC aging and retention:
- IP addresses: 30-90 days (IPs change frequently)
- Domains: 90-180 days (may be re-registered)
- File hashes: 1-2 years (more persistent)
- YARA rules: until superseded
- Review and cull regularly to reduce noise
TIP COMPARISON TABLE#
Feature | MISP | OpenCTI | TheHive
-----------------|-------------|--------------|-------------
License | AGPL | Apache 2.0 | AGPL
Primary focus | IOC sharing | Knowledge | Incident
| | management | response
Data model | MISP events | STIX2 native | Cases/alerts
Visualization | Basic | Knowledge | Dashboard
| | graph |
API | REST | GraphQL | REST
Correlation | Built-in | Built-in | Via Cortex
Sharing | MISP sync | STIX/TAXII | MISP export
Feeds | Many built- | Connectors | Via MISP
| in feeds | |
Scalability | Medium | High | Medium
Learning curve | Medium | High | Low
Best for | IOC sharing | CTI analysis | IR/SOC ops
| community | team |
Integration architecture (recommended):
Feeds -> MISP (collection & sharing)
-> OpenCTI (analysis & knowledge base)
-> TheHive/Cortex (incident response & enrichment)
-> SIEM/EDR (detection & alerting)
BUILDING A THREAT INTEL PROGRAM#
1. Define requirements: - What threats matter to your organization? - What decisions will threat intel support? - Who are the consumers (SOC, IR, exec, vuln mgmt)? 2. Collection: - Subscribe to relevant feeds - Join ISACs/ISAOs for your industry - Configure automated feed ingestion - Establish manual reporting process 3. Processing: - Normalize data formats (STIX2) - De-duplicate across sources - Enrich with context - Assign confidence scores 4. Analysis: - Map to MITRE ATT&CK - Assess relevance to your environment - Create threat profiles and reports - Track campaigns and threat actors 5. Dissemination: - Automated IOC distribution to security tools - Regular threat briefings for stakeholders - Actionable advisories for IT/security teams - Executive-level threat summaries 6. Feedback: - Track IOC detection rates - Measure false positive rates - Refine collection based on value - Continuous improvement cycle
REFERENCES#
- MISP Project: https://www.misp-project.org/ - OpenCTI: https://www.opencti.io/ - TheHive: https://thehive-project.org/ - STIX/TAXII: https://oasis-open.github.io/cti-documentation/ - MITRE ATT&CK: https://attack.mitre.org/ - FIRST TLP: https://www.first.org/tlp/