M ManySignal
MS
MI
Integration

Misp Integration

Ingest and share threat intelligence via your MISP instance.

What this integration does

MISP meets agentic SOC

MISP (Malware Information Sharing Platform) is the open-source threat intelligence platform used by CERTs, ISACs, and security teams worldwide. ManySignal integrates with MISP to consume threat indicators for IOC enrichment, push new indicators discovered during investigations, and synchronise threat actor and campaign context.

MISP event and attribute ingestion for IOC enrichment

Automatic attribute type mapping (IP, domain, hash, email)

Tag and galaxy cluster context in alert enrichment

Data collected

  • MISP attributes (IOCs) across all attribute types
  • MISP event metadata and tags
  • Galaxy cluster threat actor and malware context

Actions supported

  • Create MISP event from ManySignal investigation
  • Add attribute to existing MISP event
  • Tag MISP event with campaign or threat actor
  • Publish MISP event to sharing group

Getting started

Set up in minutes

  1. 1

    Generate a MISP API key

  2. 2

    Configure the connector

  3. 3

    Configure feed synchronisation

Misp Integration: frequently asked questions

Can ManySignal push indicators back to MISP automatically?

Yes. Configure ManySignal to auto-publish high-confidence malicious IOCs discovered during investigations as MISP attributes to a designated event. Manual approval workflows are also supported for sensitive intelligence.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.