Skip to main content

Case Study on MISP

Published on: 25/09/2026 Document

This case study has been drafted based on comprehensive desk research—including official MISP documentation, technical portals, and academic articles—as well as on an interview conducted by the OSOR Team with Alexandre Dulaunoy, Head of the Computer Incident Response Center Luxembourg (CIRCL). 

Introduction

The latest Report on the State of Cybersecurity in the Union by the European Union Agency for Cybersecurity (ENISA) highlighted a significant increase in cyberattacks across the EU in recent years, with more than 10,000 incidents observed. This rise is driven by long-term trends such as rapid digitalisation and growing societal and economic interconnectivity, as well as by contextual factors including the COVID-19 pandemic, geopolitical tensions, and major national and European events that contributed to increased hacktivist activity. In parallel, artificial intelligence (AI) is further amplifying cyber threats, enabling threat actors to scale attacks such as phishing, social engineering, impersonation and malware development, while also creating a new attack surface through vulnerabilities in AI-based systems [1].

To address the growing volume and sophistication of cyber threats, public and private organisations must adopt multi-layered defence strategies, with cybersecurity intelligence and information sharing at their core. As threat actors operate beyond borders and exploit common digital vulnerabilities, timely sharing of indicators of compromise (IOCs), threat intelligence and vulnerability data enables a more proactive and coordinated defence. This need is reflected in ENISA’s NIS360 assessment, which identifies collaboration and information sharing as key enablers of cybersecurity maturity across public and private sectors. 

The relevance of threat intelligence and information sharing is reinforced by several EU policy and legal frameworks, including:

  • The NIS 2 Directive, establishing a legal framework for entities to voluntarily share essential threat data, IOCs, and vulnerabilities.

  • The EU Cybersecurity Act, granting a permanent mandate to ENISA to directly support operational cooperation and structured threat information exchange between Member States. 

  • The EU Cyber Solidarity Act, introducing a European Cyber Shield comprised of interconnected Security Operations Centres (SOCs) to actively detect, analyse, and share real-time threat intelligence across the Union.

  • The European Cybercrime Centre (EC3) at Europol, facilitating the continuous exchange of criminal cyber intelligence to disrupt international threat networks. 

Years before many of these policies and legal frameworks emerged, some cybersecurity practitioners had already recognised the value of intelligence sharing in strengthening cyber defence. One of them was Christophe Vandeplas, who created MISP in 2011 based on the principle that effective information sharing is essential for combating cyber threats, and can be significantly enhanced through open source tools, open standards and shared practices. 

MISP

MISP (Malware Information Sharing Platform) is a free and open source cyber threat intelligence platform used to collect, store, correlate, and share data about security incidents, malware and IOCs. It functions as a centralised repository and collaboration hub where security teams, government agencies, and global communities can securely store, organise, and correlate technical and non-technical information regarding cyberattacks. By standardising IOCs—such as malicious IP addresses, file hashes, and phishing domains—alongside strategic information like threat actor behaviours and vulnerability tracking, MISP automatically surfaces hidden relations between seemingly isolated incidents. 

MISP’s collaborative ecosystem allows organisations to move away from isolated defence strategies, enabling them to automate the distribution of real-time threat data directly into security tools like SIEMs (Security Information and Event Management), firewalls, and intrusion detection systems to proactively block emerging threats. 

misp_logo

The MISP project originated in May 2011 as an initiative by Christophe Vandeplas, then Cyber Defence Expert at the Belgian Ministry of Defence. Vandeplas identified limitations in the way IOCs were exchanged at the time, with information often distributed through emails or PDF documents. To automate these exchanges, he developed an initial proof of concept using CakePHP, an open source, rapid development web framework, which he named CyDefSIG (Cyber Defence Signatures). After presenting the project within the Belgian Ministry of Defence in July 2011 and receiving positive feedback, CyDefSIG was adopted for official use in August of the same year. Vandeplas subsequently continued developing the project alongside his professional responsibilities. 

CyDefSIG later attracted NATO’s attention, which evaluated the project and other available solutions and identified its open nature as a significant advantage. In 2012, NATO began contributing to its development, initially through part-time involvement and later through a dedicated full-time developer. The project was subsequently released under the Affero General Public Licence (AGPL) and renamed MISP. By January 2013, MISP started to be adopted by CERT-EU (the Cybersecurity Service for the Union Institutions, Bodies, Offices and Agencies), and CIRCL (Luxembourg’s Computer Security Incident Response Team), which also began promoting the platform. Over time, responsibility for MISP’s development and maintenance transitioned fully to CIRCL, which became the primary steward of the platform. 

How MISP works

At the technical level, MISP can be understood as a structured platform for collecting, contextualising, correlating and distributing threat information. Rather than treating threat intelligence as a collection of isolated indicators, MISP organises information into events, which act as containers for contextually related data. An event might describe an incident, a malware investigation, a campaign or another analytical finding. Within an event, attributes represent individual data points, such as IP addresses, domain names, URLs, file hashes or other types of indicators and supporting information. Attributes are typed and categorised, allowing MISP to distinguish, for example, between a hash, a domain name and a network address. More complex information can be represented through MISP objects, which combine several related attributes according to a template and allow relationships to be established between them. This object-based approach makes it possible to represent more than individual indicators without requiring the MISP core to have prior knowledge of every possible data structure. 

misp_core_concepts

The distinction between the data layer and the context layer is particularly important for understanding how MISP is used operationally. The data layer contains the observations themselves, while the context layer provides information that helps analysts assess, classify and prioritise them. Tags and taxonomies provide a common vocabulary for describing information, e.g., its confidence, source, classification or sharing conditions. MISP taxonomies use machine-readable tags so that the same classification can be understood and processed across different organisations and systems. This is significant because an indicator without context has limited analytical value: knowing that an IP address has been observed is different from knowing that it is associated with a particular campaign, has a certain confidence level, or should only be distributed to a defined group of organisations. The MISP project therefore provides a library of reusable taxonomies, while allowing organisations to create or adapt their own. 

One of the main mechanisms for adding context is MISP Galaxy. A Galaxy is a structured knowledge repository that enriches threat intelligence by linking cyber incidents to broader contextual information (clusters), such as threat actors, malware families, ransomware groups, or attack techniques. MISP describes Galaxy information as a more flexible, human-oriented layer than strongly typed indicators, which makes it suitable for representing concepts where different sources may use different names or descriptions. The graph below depicts how Galaxies, clusters and elements interrelate and work:

misp_galaxy

MISP Galaxy representation. Source: Creating a MISP Galaxy, 101

MISP also provides several mechanisms to manage the quality, reliability and lifecycle of shared threat intelligence, including:

  • Sightings: observations indicating whether an indicator has been seen in the wild, including positive, negative or expiration-related feedback, creating a continuous loop between intelligence sharing and Sightings: observations indicating whether an indicator has been seen in the wild, including positive, negative or expiration-related feedback, creating a continuous loop between intelligence sharing and operational detection.

  • Warning lists: curated lists of values known to generate false positives or otherwise be unsuitable for detection, helping analysts avoid unreliable indicators.

  • Decaying models: mechanisms that assess the decreasing relevance of indicators over time, enabling users to prioritise more actionable intelligence without modifying the underlying data. 

The platform’s technical architecture is designed around sharing intelligence data between MISP instances as well as within an individual instance. Organisations can choose different distribution levels, ranging from keeping information within their own organisation to sharing it with a specific community or with connected communities. MISP instances can synchronise with one another using push and pull mechanisms, while feeds provide another way of importing information from external sources. The platform can therefore support both relatively open information-sharing environments and restricted or partially connected communities, including deployments where systems are isolated or air-gapped. 

The distribution model is closely connected to the concept of MISP communities. A community is a group that shares information according to a common purpose, set of interests or level of trust. Communities involve financial institutions, military and international organisations, Computer Emergency Response Teams (CERTs) and Computer Security Incident Response Teams (CSIRTs), security vendors, and communities established around specific topics. These communities can operate independently, connect to other communities, or use more restricted arrangements depending on their requirements. This is an important aspect of MISP because information sharing is ultimately a governance and trust problem as much as a technical one. A more detailed description of MISP's information sharing process can be found in the dedicated page. 

As with any other community-driven model, MISP relies heavily on interoperability, given that different organisations and sectors may operate with their own taxonomies, custom objects and data structures. MISP addresses this by balancing a highly stable, well-documented core format with adaptable extension layers. While the core MISP Standard guarantees consistent baseline data exchanges, its flexible taxonomies and objects allow member organisations to map threat intelligence directly to their internal frameworks without breaking compatibility. As a result, MISP is an ecosystem in which the technical standards, the software and the communities using it are closely interconnected. 

Finally, regarding MISP’s own distribution, its core platform is released under the GNU Affero General Public Licence (AGPL), leveraging its copyleft provisions to guarantee that code contributors retain ownership and continuous access. Conversely, associated elements like taxonomies and galaxies utilise other licences such as CC0-1.0 and BSD 2-Clause to maximise interoperability, enabling smooth adoption and integration across diverse tools and systems. An exhaustive list of each MISP repository and its licence can be found here.

The governance and financing of MISP

MISP was initially developed and maintained through the involvement of NATO and the Belgian Ministry of Defence, but responsibility for the project gradually and organically transitioned to CIRCL. Thus, the Luxembourgish CSIRT became the de facto main driver of MISP’s governance, which operates as a “do-ocracy” whereby decision-making is shaped by those actively contributing to the project. Today, CIRCL acts as MISP’s primary developer and maintainer, leading a team of around 30 internal and external experts. Additionally, CIRCL manages approximately 60 MISP-related GitHub repositories and cultivates a vibrant open source community that generates between 600 and 700 contributions each year. 

Despite the centrality of CIRCL, given its open source and community-driven nature, MISP also relies on different actors and sources to achieve its goals and perform its different activities, including gathering feature requests, feedback, and reporting bugs. The graph below maps the different actors and sources that MISP depends on: 

misp_collaborators

MISP mapping of collaborators. Source: MISP Model of Governance

Regarding its financing, MISP relies on a multi-stream funding model that combines public, European, and private sector resources to ensure its long-term sustainability and continuous development:

  • National budget of the Grand Duchy of Luxembourg: funding allocated to CIRCL in its capacity as national CSIRT, with a portion of the funds dedicated to supporting MISP.

  • European Union grants: project-based funding across various EU initiatives, including the Connecting Europe Facility (supporting compliance with NIS2 and DORA), DG HOME’s Internal Security Fund (for MISP’s use by law enforcement agencies), and the AIPITCH project for AI-driven extensions (co-funded 50% by the EU and 50% by CIRCL). 

  • Private sector contributions: commercial funding from private organisations seeking formal, legally binding contracts or requesting prioritised feature development to perform specific functions.

  • Defence-related agreements: strategic funding derived from partnerships with the Luxembourgish Army and Directorate of Defence, supporting MISP’s deployment across military and defence sectors. 

Use cases

MISP is used by a broad range of organisations involved in cybersecurity, public safety, research and critical infrastructure. Its users include national and sectoral CERTs and CSIRTs, government and military cyber defence units, law enforcement and intelligence organisations, financial institutions, critical infrastructure operators, security vendors, managed security providers, universities and research laboratories, as well as industry information-sharing communities. For an exhaustive list of the types of organisations and communities using MISP, the MISP project provides a dedicated overview here.

A particularly relevant example from the EU-level public sector is MISP’s use by Europol. During the international operation targeting the criminal abuse of Cobalt Strike [2], Europol reported that MISP was used to facilitate the exchange of real-time threat intelligence between private sector organisations and law enforcement agencies. Over the course of the investigation, law enforcement used MISP to share more than 730 pieces of threat intelligence, containing almost 1.2 million IOCs [3].

NATO provides another instance of MISP being used to support information sharing across a multinational community. The platform was introduced in the context of a Belgian-led NATO Smart Defence project launched in 2013, with the objective of enabling participating nations to share the technical characteristics of malware within a trusted community without necessarily disclosing details of the underlying incidents. The NATO Communications and Information Agency has described several MISP-based services supporting information exchange between NATO, national governments and industry, including the sharing of IOCs, threat actors, infrastructure, tactics, techniques, procedures and vulnerabilities [4]. MISP has also been used in NATO-EU cyber-defence cooperation: the 2017 EU-NATO Seventh Progress Report noted that MISP was being leveraged in the technical arrangement between NATO’s Computer Incident Response Capability and CERT-EU. 

Today, there are an estimated 60,000 MISP installations worldwide, though the precise number of active instances remains unknown as many operate offline or within classified networks. Driven by this widespread adoption and the evolving functional needs of its users, MISP has developed into a multi-domain intelligence-sharing tool capable of handling data and indicators beyond cybersecurity, including those related to financial fraud, money laundering, disinformation, and signals or radio-frequency intelligence for defence purposes. The core team at CIRCL encourages these community-driven expansions, supporting their broader adoption within the platform to the best of their capacity. 

Benefits and challenges

One of MISP’s most significant benefits is its ability to automate threat intelligence sharing while remaining configurable, i.e., giving organisations full control over what data they push or pull, and with whom they share it. Another relevant benefit of MISP is its automatic correlation of IOCs across diverse datasets, which allows security teams within and between organisations to surface hidden threat patterns, simplify detection, and turn raw data into actionable intelligence leads. Additionally, MISP has been designed to be user-friendly and easy to set up.

However, MISP also faces challenges rooted in organisational culture and trust, namely that there is generally no shared agreement on what data should be shared, and even when there is, trust and credibility issues may prevent full disclosure of information. This creates a series of challenges, including poor contextualisation, where organisations share raw indicators without adequate detail regarding their source, reliability, or confidence level. To directly address these trust and quality issues, the MISP community provides clear guidance, best practices, and dedicated support. 

Future outlook

Looking ahead, MISP does not rely on a rigid long-term roadmap, and rather favours a flexible, community-driven model shaped by the emerging threat landscape and observable use cases. Key technical priorities include scaling the platform for very large datasets without burdening smaller deployments, and integrating Pivotick, CIRCL’s newly developed graph library designed to replace legacy components and improve performance across the toolset. Moving forward, MISP is also expected to integrate more closely with CIRCL’s broader ecosystem, including its case management and monitoring tools.

Central to the next developments is also AI, which is envisaged to serve both as a development tool and a core platform capability. The MISP team is piloting AI for codebase review and hygiene, with AI-assisted audits recently helping identify and patch around 35 vulnerabilities under strict human review, while planned features will provide optional AI assistance for processing, analysing, and summarising large volumes of threat intelligence. 

Policy context

For information regarding the policy context of open source software in the Luxembourgish public sector, please consult the respective Country Intelligence Report and its corresponding factsheet in the OSOR Knowledge Centre. These resources include a detailed overview of the political actors, strategic players, political and legislative frameworks and public sector open source software initiatives in Luxembourg. 

Footnotes

Click number to go back to text

[1] European Union Agency for Cybersecurity (ENISA). (2025, October 1). ENISA threat landscape 2025. ENISA. https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025 

[2] Cobalt Strike is a commercial security tool developed by Fortra for legitimate red-teaming and attack simulation; however, cracked, unlicensed versions are widely exploited by cybercriminals to gain unauthorised network access and deploy malware. Operation Morpheus (2021-2024) was a multinational law enforcement operation led by the UK National Crime Agency and coordinated through Europol (supported by private partners using MISP) that targeted this illicit abuse. 

[3] Europol. (2024, July 3). Europol coordinates global action against criminal abuse of Cobalt Strike. https://www.europol.europa.eu/media-press/newsroom/news/europol-coordinates-global-action-against-criminal-abuse-of-cobalt-strike 

[4]For instance, see this article on the 2018 NATO-Industry cyber partnership signed at NITEC18: NCIA | New NATO-Industry cyber partnerships signed at NITEC18

Categorisation

Type of document
Open source case study
Licence
GNU Affero General Public License v3.0

Attachment

Login or create an account to comment.