Knowledge (XXG)

MISP Threat Sharing

Source 📝

453: 146: 399: 38: 201:) where the feedback was rather positive. After giving access to CyDefSIG running on his personal server the Belgian Defence started to use CyDefSIG officially starting mid August 2011. Christophe was then allowed to spend some time on CyDefSIG during his work-hours, while still working on it at home. 228:
As the MISP project expanded, MISP is not only covering the malware indicators but also fraud or vulnerability information. The name is now MISP Threat Sharing, which includes the core MISP software and a myriad of tools (PyMISP) and format (core format, MISP taxonomies, warning-lists) to support
212:
One thing led to another and some months later NATO hired a full-time developer to improve the code and add more features. A collaborative development started from that date. As with many personal projects the license was not explicitly written yet, it was collaboratively decided that the project
208:
heard about this project. In January 2012 a first presentation was done to introduce them in more depth to the project. They looked at other products that the market offered, but it seemed they deemed the openness of CyDefSIG to be of a great advantage. Andrzej Dereszowski was the first part-time
189:
This project started around June 2011 when Christophe Vandeplas had a frustration that way too many Indicators of Compromise (IOCs) were shared by email, or in pdf documents and were not parsable by automatic machines. So at home he started to play around with
257:
Indicators of compromise which are managed by MISP may originate from a variety of sources; including internal incident investigation teams, intelligence sharing partners or commercial intelligence sources. Commercial sources with integration to MISP include
219:
In January 2013 Andras Iklody became the main full-time developer of MISP, during the day initially hired by NATO and during the evening and week-end contributor to an open source project.
213:
would be released publicly under the Affero GPL license. This to share the code with as many people as possible and to protect it from any harm.
488: 178: 222:
Meanwhile other organisations started to adopt the software and promoted it around the CERT world (CERT-EU, CIRCL, and many others).
125: 416: 493: 468: 263: 170: 98: 216:
The project was then renamed to MISP: Malware Information Sharing Project, a name invented by Alex Vandurme from NATO.
72: 242: 174: 483: 464:
Building and designing MISP: A practical information-sharing tool for cybersecurity and fraud indicators
463: 262:, Kaspersky threat feeds and McAfee Active Response. MISP integrations with open-source and commercial 173:. The project develops utilities and documentation for more effective threat intelligence, by sharing 458: 198: 145: 17: 313: 120: 194:
and made a proof of concept of his idea. He called it CyDefSIG: Cyber Defence Signatures.
452: 238: 225:
Nowadays, Andras Iklody is the lead developer of the MISP project and works for CIRCL.
477: 291: 403: 167: 61: 55: 45: 339: 398: 267: 191: 271: 37: 381: 229:
MISP. MISP is now a community project led by a team of volunteers.
402:
Material was copied from this source, which is available under a
205: 103: 113: 446: 259: 136: 197:
Mid July 2011 he presented his personal project at work (
246: 260:
Symantec's DeepSight Intelligence (now called Broadcom)
404:
Creative Commons Attribution-ShareAlike 3.0 Unported
131: 119: 109: 97: 71: 54: 44: 177:. There are several organizations who run MISP 376: 374: 372: 370: 368: 366: 364: 362: 360: 8: 247:Computer Incident Response Center Luxembourg 30: 459:IETF draft-dulaunoy-misp-taxonomy-format-06 451: 144: 36: 29: 283: 469:Privacy Aware Sharing of IOCs in MISP 7: 164:Malware Information Sharing Platform 60:Andras Iklody (lead developer), and 18:Malware Information Sharing Platform 25: 382:"Who is behind the MISP project?" 181:, who are listed on the website. 397: 417:"Digital Single Market - MISP" 314:"MISP threat sharing platform" 1: 264:threat intelligence platforms 237:The project is funded by the 171:threat intelligence platform 104:https://github.com/MISP/MISP 27:Threat intelligence platform 268:the ThreatQuotient Platform 78:2.4.196 / 21 August 2024 510: 489:Computer security software 243:Connecting Europe Facility 209:developer from NATO side. 93: 67: 35: 253:Intelligence Integration 175:indicators of compromise 494:Free security software 80:; 22 days ago 344:www.misp-project.org 50:Christophe Vandeplas 272:EclecticIQ Platform 156:MISP Threat Sharing 32: 31:MISP Threat Sharing 340:"MISP Communities" 62:other contributors 46:Original author(s) 292:"Release 2.4.196" 153: 152: 16:(Redirected from 501: 455: 450: 449: 447:Official website 432: 431: 429: 427: 413: 407: 401: 396: 394: 392: 386:MISP-Project.org 378: 355: 354: 352: 350: 336: 330: 329: 327: 325: 310: 304: 303: 301: 299: 294:. 21 August 2024 288: 149: 148: 141: 138: 88: 86: 81: 40: 33: 21: 509: 508: 504: 503: 502: 500: 499: 498: 474: 473: 445: 444: 441: 436: 435: 425: 423: 415: 414: 410: 390: 388: 380: 379: 358: 348: 346: 338: 337: 333: 323: 321: 320:. 7 August 2017 312: 311: 307: 297: 295: 290: 289: 285: 280: 255: 235: 199:Belgian Defence 187: 143: 135: 89: 84: 82: 79: 28: 23: 22: 15: 12: 11: 5: 507: 505: 497: 496: 491: 486: 476: 475: 472: 471: 466: 461: 456: 440: 439:External links 437: 434: 433: 408: 356: 331: 305: 282: 281: 279: 276: 254: 251: 239:European Union 234: 231: 204:At some point 186: 183: 151: 150: 133: 129: 128: 123: 117: 116: 111: 107: 106: 101: 95: 94: 91: 90: 85:21 August 2024 77: 75: 73:Stable release 69: 68: 65: 64: 58: 52: 51: 48: 42: 41: 26: 24: 14: 13: 10: 9: 6: 4: 3: 2: 506: 495: 492: 490: 487: 485: 484:Data security 482: 481: 479: 470: 467: 465: 462: 460: 457: 454: 448: 443: 442: 438: 422: 418: 412: 409: 405: 400: 387: 383: 377: 375: 373: 371: 369: 367: 365: 363: 361: 357: 345: 341: 335: 332: 319: 315: 309: 306: 293: 287: 284: 277: 275: 273: 269: 265: 261: 252: 250: 248: 244: 241:(through the 240: 232: 230: 226: 223: 220: 217: 214: 210: 207: 202: 200: 195: 193: 184: 182: 180: 176: 172: 169: 165: 161: 157: 147: 140: 134: 130: 127: 124: 122: 118: 115: 112: 108: 105: 102: 100: 96: 92: 76: 74: 70: 66: 63: 59: 57: 53: 49: 47: 43: 39: 34: 19: 424:. Retrieved 421:ec.europe.eu 420: 411: 389:. Retrieved 385: 347:. Retrieved 343: 334: 322:. Retrieved 318:media.ccc.de 317: 308: 296:. Retrieved 286: 256: 236: 227: 224: 221: 218: 215: 211: 203: 196: 188: 163: 159: 155: 154: 137:misp-project 56:Developer(s) 426:19 February 391:24 February 349:19 February 324:19 February 168:open source 478:Categories 278:References 245:) and the 110:Written in 99:Repository 298:22 August 179:instances 406:license. 266:include 233:Funding 192:CakePHP 185:History 132:Website 121:License 83: ( 166:is an 142:  126:AGPLv3 428:2019 393:2019 351:2019 326:2019 300:2024 270:and 206:NATO 160:MISP 139:.org 162:), 114:PHP 480:: 419:. 384:. 359:^ 342:. 316:. 274:. 249:. 430:. 395:. 353:. 328:. 302:. 158:( 87:) 20:)

Index

Malware Information Sharing Platform

Original author(s)
Developer(s)
other contributors
Stable release
Repository
https://github.com/MISP/MISP
PHP
License
AGPLv3
misp-project.org
Edit this on Wikidata
open source
threat intelligence platform
indicators of compromise
instances
CakePHP
Belgian Defence
NATO
European Union
Connecting Europe Facility
Computer Incident Response Center Luxembourg
Symantec's DeepSight Intelligence (now called Broadcom)
threat intelligence platforms
the ThreatQuotient Platform
EclecticIQ Platform
"Release 2.4.196"
"MISP threat sharing platform"
"MISP Communities"

Text is available under the Creative Commons Attribution-ShareAlike License. Additional terms may apply.