MISP — CYBORA's threat-intelligence sharing platform
CYBORA operates a MISP instance — the open-source Malware Information Sharing Platform used by CERTs and security teams worldwide — to trade indicators of compromise, malware findings and campaign intelligence with our clients, national and partner CERTs, and the wider trusted-sharing community.
What MISP is, in practice
MISP stores, correlates and shares Indicators of Compromise (IOCs) — file hashes, malicious domains, IP addresses, phishing URLs — alongside the context that makes them useful: which campaign they belong to, which threat actor is behind them, and how confident the reporting organisation is. Where a spreadsheet of hashes goes stale the moment it's exported, a MISP event stays linked to everything it's connected to, and updates propagate to everyone subscribed to it.
From raw signal to correlated intelligence
Indicators reach CYBORA's MISP instance from several directions at once: our own HybridSOC detections, Braze's dark-web and malware-sandbox findings, direct submissions from clients who spot something in their own environment, and feeds from partner CERTs. MISP's correlation engine links a new indicator against everything already known — the same hash seen in three unrelated client environments becomes one campaign, not three isolated alerts.
- Automatic correlation across attributes — a shared hash, C2 domain or mutex links otherwise unrelated reports into one event.
- Structured export straight to IDS/NIDS rules (Suricata, Snort) for anything with enough fidelity to block on.
- Findings feed HybridSOC detection logic directly, and evidence flows into Agentic GRC where a framework requires threat-intel monitoring.
- What we learn, we give back — sanitised, correctly classified events flow back out to the communities that shared with us.
MISP itself: built and maintained by CIRCL
CYBORA doesn't run a fork or a lookalike — we operate a real MISP instance, on the actual open-source platform originally built by CIRCL (Computer Incident Response Center Luxembourg) with the wider community. The two diagrams below are CIRCL's own explanation of how the software and its global federation work; we're showing them as-is, credited, because they explain the underlying project better than a redrawn version would.


What access includes
Web interface
Browse, search and contribute events through MISP's own analyst UI — no separate tooling to learn.
PyMISP / REST API
Pull indicators programmatically into your own SIEM, EDR or ticketing system.
Tiered sharing levels
From organisation-only to the full federated community, matching MISP's TLP model exactly.
Free of charge
Access carries no fee — we ask only for a legitimate organisational need and basic verification.
Before you request access
What are the rules once I have access?
Respect the TLP marking on every event you see, and match it on anything you contribute: TLP:RED never leaves the room it was shared in, TLP:AMBER stays inside the recipient organisations named, TLP:GREEN can move around the wider community, and TLP:CLEAR is fine to share openly. Misclassifying or leaking TLP:RED/AMBER intelligence is grounds for losing access.
Do I need to install anything?
No. You get a web login to CYBORA's instance and, if you want programmatic access, an API key for PyMISP or the REST API — there's no MISP server for you to stand up or maintain on your side.
I lost my password or API key — what now?
Email info@cybora.tech from the address your organisation registered with (or have your organisation's MISP administrator reset it for you) and we'll reissue your credentials after a quick identity check.
I found a bug or a bad correlation — how do I report it?
Send details to info@cybora.tech. If it's a bug in MISP itself rather than something specific to our instance, we'll also raise it with the upstream project on their public GitHub tracker.
Is there a user guide or training?
MISP's own user guide (available online, and as PDF/EPUB) covers the interface in full — we point every new member to it during onboarding. For teams that want a live walkthrough, ask about a short onboarding session when you request access.
Request access to CYBORA's MISP instance
Open to CYBORA clients, national and partner CERTs/CSIRTs, and vetted security teams with a genuine intelligence-sharing need. Tell us a little about your organisation below.