MISP
MISP is an open-source threat intelligence platform for collecting, storing and sharing cyber security indicators between analysts and security teams.
- GitHub stars
- 6.6k
- Last commit
- today
- Latest release
- v2.5.48
- Licence
- AGPL-3.0
- Self-hosted
- Yes
- Hosted version
- Available

MISP is open-source software for gathering, storing, distributing and sharing cyber security indicators and details from incident and malware analysis. It is aimed at incident analysts, security and ICT staff and malware reverse engineers, who use it to exchange structured information efficiently.
Beyond sharing, MISP supports the consumption of that information by network intrusion detection systems, log analysis tools and SIEMs. Threat intelligence from indicators through techniques to tactics can be described in a machine-readable form or as detailed reports in Markdown, and the integrated reporting system cross-references the structured data. Repository topics point to STIX, threat hunting and fraud detection use cases.
The core software is written in PHP and licensed under AGPL-3.0. The README says it can be deployed on premises, in the cloud or as a SaaS solution, so organizations of different sizes can run their own instance and choose which partners to share data with. Installation guides, documentation and a support site are linked from the repository.
Key features
- Collect and store threat indicators
- Share structured intelligence with communities
- Machine-readable and Markdown reports
- Export to IDS, log analysis tools and SIEMs
- STIX-related threat intelligence formats
- On-premise, cloud or SaaS deployment
Pricing: Free and open source under the AGPL-3.0 licence.