Get CrowdSec IOCs feed into MISP

This page summarizes the projects mentioned and recommended in the original post on /r/CrowdSec

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • MISP

    MISP (core software) - Open Source Threat Intelligence and Sharing Platform

  • Is it possible to feed MISP with CrowdSec’s IOC lists?

  • misp-modules

    Modules for expansion services, import and export in MISP

  • Do you mean like this? https://github.com/crowdsecurity/misp-modules

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • PyMISP

    Python library using the MISP Rest API

  • You might consider misp feed https://github.com/MISP/PyMISP/tree/main/examples/feed-generator, basically it’s the best way to collect IOCs and import them into a MISP instance. These feeds help to correlate IOCs without manually launching the MISP module every time for each IOC, this also reduce the workload on your API servers as the list is cached locally on the MISP and updated every day.

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts