BigHugger
sk Skill · mukul975

building-threat-feed-aggregation-with-misp

Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization and STIX/TAXII-based integration with Splunk, Elasticsearch, and SOAR platforms. Use when standing up centralized IOC management or wiring multi-source threat feeds into a SIEM.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
yamlpythonPythonthreat-intelligencesiem-integrationcorrelationsharingindicatoraggregationthreat-feedmisp
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python