MISP, an open source threat intelligence and sharing platform for collecting, correlating and sharing indicators of compromise, threat events, feeds and taxonomies across a trust community.
This product is available in the build below. Open it for the operating system, cloud and version detail, or read its deployment guide.
| Product | Cloud | Operating system | Version | |
|---|---|---|---|---|
| MISP Threat Intelligence Platform on Ubuntu 24.04 LTS | Azure | Ubuntu 24.04 | Standard | View · Guide |
MISP is an open source threat intelligence platform used by security teams, CERTs and SOCs to store, correlate and share threat data. Analysts record events, attach attributes and objects, tag them with taxonomies and galaxies, and let MISP automatically correlate indicators across events. Curated open source feeds can be pulled in, and findings shared selectively with partner organisations through sharing groups and server to server synchronisation. It gives a community a common, structured place to turn scattered indicators of compromise into shared, actionable intelligence.
cloudimg ships the full official MISP stack, the web application, enrichment modules, a bundled database and a cache and worker backend, hardened and fully patched on one instance. Because MISP holds sensitive threat intelligence, security is enforced from first boot: every instance generates its own administrator password, REST API key, per instance signing key, database and cache passwords, salt and encryption key, so the well known default administrator is rejected and no secret is ever shared between customers. The database, cache and enrichment modules stay on a private network, never exposed on a public port. Every image is paired with a step by step deployment guide and backed by 24/7 support.