MISP is an open source threat intelligence platform for collecting, storing, correlating and sharing indicators of compromise and other information about cyber threats. Analysts can explore relationships between data through correlation views and graphs, tag information with taxonomies and galaxies such as MITRE ATT&CK, and automate exports to IDS and SIEM tools in formats like STIX and OpenIOC. A REST API, the PyMISP library and extension modules support integration, and instances can synchronise with each other so that organisations share threat data within trusted communities. Organisations download the software and run it themselves.
MISP is developed by CIRCL, the Computer Incident Response Center Luxembourg, together with an international open source community, and the code is published under the GNU Affero General Public License version 3. Because the software is self-hosted, each organisation decides where its instance runs and with whom it shares data. The project distributes the software for download, which suits European CERTs, public bodies and companies that want to keep control of their threat intelligence.