MISP
An open-source threat intelligence platform for sharing, storing and correlating indicators of compromise.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About MISP
MISP is a self-hosted platform for sharing, storing, correlating and analysing threat intelligence, used for targeted attacks, financial fraud and counter-terrorism work. Its dashboards and visualizations help analysts explore the data, and an OpenAPI interface and the PyMISP library support automation.
The project also maintains open taxonomies and the MISP Galaxy, covering ATT&CK, TLP, GDPR and more, which other software can use too. New releases appeared in September 2026, and commercial support is available.
Strengths
- Correlates indicators across shared events
- Large set of open taxonomies and galaxies
- API and PyMISP for automation
- Frequent releases
Limitations
- Needs a server and administration effort
- Built for security teams and sharing communities rather than individuals
Details
- Pricing
- FreeFree and open source; commercial support is offered separately.
- License
- Open source, license not stated
- Developer
- The MISP contributors
- Platforms
- Web, Self-hosted
- How it runs
- Self-hosted
- Best suited for
- Security teams and communities that exchange threat intelligence
- Categories
- Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to MISP
Compare allSoftware that can replace MISP for an important use case, and what changes if you switch.
OpenCTI
A self-hosted open-source platform for storing, organizing and visualizing cyber threat intelligence.
OpenCTI is a self-hosted open-source platform for storing and visualizing threat intelligence, built around a knowledge base rather than event correlation and sharing.
Similar software
Related functionality, not necessarily a direct replacement.
Shuffle
An open-source security orchestration, automation and response (SOAR) platform for building workflows across security tools.
DefectDojo
An open source, self-hosted vulnerability management platform that collects and tracks findings from security scanners.
Canarytokens
A free web tool that creates tripwire tokens which alert you when an attacker triggers them.
dnstwist
A domain permutation engine that finds lookalike domains used for typosquatting, phishing and impersonation.
VirusTotal
Online service that checks a URL or file against many antivirus engines and URL scanners.
Shodan
A search engine that indexes internet-connected devices and the services they expose.