Misp Integration
Ingest and share threat intelligence via your MISP instance.
What this integration does
MISP meets agentic SOC
MISP (Malware Information Sharing Platform) is the open-source threat intelligence platform used by CERTs, ISACs, and security teams worldwide. ManySignal integrates with MISP to consume threat indicators for IOC enrichment, push new indicators discovered during investigations, and synchronise threat actor and campaign context.
MISP event and attribute ingestion for IOC enrichment
Automatic attribute type mapping (IP, domain, hash, email)
Tag and galaxy cluster context in alert enrichment
Data collected
- MISP attributes (IOCs) across all attribute types
- MISP event metadata and tags
- Galaxy cluster threat actor and malware context
Actions supported
- Create MISP event from ManySignal investigation
- Add attribute to existing MISP event
- Tag MISP event with campaign or threat actor
- Publish MISP event to sharing group
Getting started
Set up in minutes
- 1
Generate a MISP API key
- 2
Configure the connector
- 3
Configure feed synchronisation
Misp Integration: frequently asked questions
Can ManySignal push indicators back to MISP automatically?
Yes. Configure ManySignal to auto-publish high-confidence malicious IOCs discovered during investigations as MISP attributes to a designated event. Manual approval workflows are also supported for sensitive intelligence.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.