// resources / threat intelligence

MISP — CYBORA's threat-intelligence sharing platform

CYBORA operates a MISP instance — the open-source Malware Information Sharing Platform used by CERTs and security teams worldwide — to trade indicators of compromise, malware findings and campaign intelligence with our clients, national and partner CERTs, and the wider trusted-sharing community.

// what is misp

What MISP is, in practice

MISP stores, correlates and shares Indicators of Compromise (IOCs) — file hashes, malicious domains, IP addresses, phishing URLs — alongside the context that makes them useful: which campaign they belong to, which threat actor is behind them, and how confident the reporting organisation is. Where a spreadsheet of hashes goes stale the moment it's exported, a MISP event stays linked to everything it's connected to, and updates propagate to everyone subscribed to it.

// how our instance works

From raw signal to correlated intelligence

Indicators reach CYBORA's MISP instance from several directions at once: our own HybridSOC detections, Braze's dark-web and malware-sandbox findings, direct submissions from clients who spot something in their own environment, and feeds from partner CERTs. MISP's correlation engine links a new indicator against everything already known — the same hash seen in three unrelated client environments becomes one campaign, not three isolated alerts.

HybridSOC telemetryBraze OSINTClient submissionsPartner CIRT feedsCYBORAMISPIDS / NIDS rulesHybridSOC alertsAgentic GRC evidenceShared back to community
  • Automatic correlation across attributes — a shared hash, C2 domain or mutex links otherwise unrelated reports into one event.
  • Structured export straight to IDS/NIDS rules (Suricata, Snort) for anything with enough fidelity to block on.
  • Findings feed HybridSOC detection logic directly, and evidence flows into Agentic GRC where a framework requires threat-intel monitoring.
  • What we learn, we give back — sanitised, correctly classified events flow back out to the communities that shared with us.
// the open-source project behind it

MISP itself: built and maintained by CIRCL

CYBORA doesn't run a fork or a lookalike — we operate a real MISP instance, on the actual open-source platform originally built by CIRCL (Computer Incident Response Center Luxembourg) with the wider community. The two diagrams below are CIRCL's own explanation of how the software and its global federation work; we're showing them as-is, credited, because they explain the underlying project better than a redrawn version would.

MISP architecture: UI users and API users both flow through correlation and a shared database, exporting to formats such as STIX, Suricata, Snort and CSV.
How a MISP instance works internally: analyst (UI) and machine (API) input both flow through the same correlation engine and database, then export to the formats detection tooling expects.Source: CIRCL — circl.lu
MISP federation diagram: CIRCL operates an API clearing house connecting a Private Sector MISP instance, a CERT Community instance, and (via MISP Synchronisation) a NATO/NCIRC instance.
The wider federation CIRCL coordinates: separate MISP instances for the private sector, the CERT community and NATO/NCIRC member countries, bridged by CIRCL as an API clearing house and kept in sync via MISP Synchronisation. CYBORA's own instance sits inside this same ecosystem.Source: CIRCL — circl.lu
// who we share with

NKSC LT, partner CIRTs, and our own clients

CYBORA's MISP instance is federated with the National Cyber Security Centre of Lithuania (NKSC LT) and a number of partner CIRTs/CSIRTs across the region, alongside dedicated sharing communities for our own clients. Every event carries a Traffic Light Protocol (TLP) marking — the same standard the whole MISP ecosystem uses — so it's always explicit how far a piece of intelligence is allowed to travel, from strictly internal to fully public.

CYBORAMISP instanceNKSC LT (national CERT)TLP:AMBERPartner CIRTs / CSIRTsTLP:AMBERCYBORA clientsTLP:GREENGlobal MISP communityTLP:CLEAR
// what you get

What access includes

Web interface

Browse, search and contribute events through MISP's own analyst UI — no separate tooling to learn.

PyMISP / REST API

Pull indicators programmatically into your own SIEM, EDR or ticketing system.

Tiered sharing levels

From organisation-only to the full federated community, matching MISP's TLP model exactly.

Free of charge

Access carries no fee — we ask only for a legitimate organisational need and basic verification.

// frequently asked

Before you request access

What are the rules once I have access?

Respect the TLP marking on every event you see, and match it on anything you contribute: TLP:RED never leaves the room it was shared in, TLP:AMBER stays inside the recipient organisations named, TLP:GREEN can move around the wider community, and TLP:CLEAR is fine to share openly. Misclassifying or leaking TLP:RED/AMBER intelligence is grounds for losing access.

Do I need to install anything?

No. You get a web login to CYBORA's instance and, if you want programmatic access, an API key for PyMISP or the REST API — there's no MISP server for you to stand up or maintain on your side.

I lost my password or API key — what now?

Email info@cybora.tech from the address your organisation registered with (or have your organisation's MISP administrator reset it for you) and we'll reissue your credentials after a quick identity check.

I found a bug or a bad correlation — how do I report it?

Send details to info@cybora.tech. If it's a bug in MISP itself rather than something specific to our instance, we'll also raise it with the upstream project on their public GitHub tracker.

Is there a user guide or training?

MISP's own user guide (available online, and as PDF/EPUB) covers the interface in full — we point every new member to it during onboarding. For teams that want a live walkthrough, ask about a short onboarding session when you request access.

// join the community

Request access to CYBORA's MISP instance

Open to CYBORA clients, national and partner CERTs/CSIRTs, and vetted security teams with a genuine intelligence-sharing need. Tell us a little about your organisation below.

By submitting you agree to our Privacy Policy. Access is free of charge, subject to organisation verification.