MISP威胁情报采集

原名:collecting-threat-intelligence-with-misp

部署MISP并配置威胁情报源(社区、Freetext、TAXII、CSV),通过PyMISP API实现IOCs的自动化采集、添加与检索,构建聚合多源情报的自动化管道。适用于IOC收集、存储、关联分析及MISP数据接入脚本开发。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
3.6 / 5

内容概览

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat intelligence, financial fraud information, vulnerability information, or counter-terrorism information. This skill covers deploying MISP, configuring threat feeds, using the PyMISP API for programmatic access, and building automated collection pipelines that aggregate IOCs from multiple community and commercial sources. - When managing security operations that require collecting threat intelligence with misp - When improving security program maturity and operational processes - When establishing standardized procedures for security team workflows - When integrating threat intelligence or vulnerability data into operations - Python 3.9+ with pymisp library installed - Docker and Docker Compos…

查看 SKILL 详情