MISP 威胁情报聚合
原名:building-threat-feed-aggregation-with-misp
通过 Docker 部署 MISP,配置来自 abuse.ch、AlienVault OTX、CIRCL 等来源的威胁情报 Feed,实现 IOC 的聚合、关联与分发,支持 STIX/TAXII 与 Splunk、Elasticsearch、SOAR 平台集成,适用于构建集中式威胁情报中心或多源 Feed 接入 SIEM。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-24
- TRACE 评分
- 3.2 / 5
内容概览
MISP is the leading open-source threat intelligence platform for collecting, storing, distributing, and sharing cybersecurity indicators and threat intelligence. It aggregates feeds from OSINT sources, commercial providers, and sharing communities into a unified platform with automatic correlation, STIX/TAXII export, and direct integration with SIEMs and security tools. This skill covers deploying MISP via Docker, configuring feeds from sources like abuse.ch, AlienVault OTX, and CIRCL, setting up automated feed synchronization, and integrating with Splunk, Elasticsearch, and SOAR platforms. - When deploying or configuring building threat feed aggregation with misp capabilities in your environment - When establishing security controls aligned to compliance requirements - When building or improving security architecture for this domain - When conducting security assessments that require th…