misp-modules/documentation/mkdocs/index.md

23 KiB

Home

Build statusCoverage Status codecov

MISP modules are autonomous modules that can be used to extend MISP for new services such as expansion, import, export and workflow action.

MISP modules can be also installed and used without MISP as a standalone tool accessible via a convenient web interface.

The modules are written in Python 3 following a simple API interface. The objective is to ease the extensions of MISP functionalities without modifying core components. The API is available via a simple REST API which is independent from MISP installation or configuration and can be used with other tools.

For more information: Extending MISP with Python modules slides from MISP training.

Existing MISP modules

Expansion modules

  • apiosintDS - a hover and expansion module to query the OSINT.digitalside.it API. Documentation.
  • API Void - an expansion and hover module to query API Void with a domain attribute.
  • AssemblyLine submit - an expansion module to submit samples and urls to AssemblyLine.
  • AssemblyLine query - an expansion module to query AssemblyLine and parse the full submission report.
  • Backscatter.io - a hover and expansion module to expand an IP address with mass-scanning observations.
  • BGP Ranking - a hover and expansion module to expand an AS number with the ASN description, its history, and position in BGP Ranking.
  • RansomcoinDB check - An expansion hover module to query the ransomcoinDB: it contains mapping between BTC addresses and malware hashes. Enrich MISP by querying for BTC -> hash or hash -> BTC addresses.
  • BTC scam check - An expansion hover module to instantly check if a BTC address has been abused.
  • BTC transactions - An expansion hover module to get a blockchain balance and the transactions from a BTC address in MISP.
  • Censys-enrich - An expansion and module to retrieve information from censys.io about a particular IP or certificate.
  • CIRCL Passive DNS - a hover and expansion module to expand hostname and IP addresses with passive DNS information.
  • CIRCL Passive SSL - a hover and expansion module to expand IP addresses with the X.509 certificates seen.
  • countrycode - a hover module to tell you what country a URL belongs to.
  • CrowdSec - a hover module to expand using CrowdSec's CTI API.
  • CrowdStrike Falcon - an expansion module to expand using CrowdStrike Falcon Intel Indicator API.
  • CPE - An expansion module to query the CVE Search API with a cpe code, to get its related vulnerabilities.
  • CVE - a hover module to give more information about a vulnerability (CVE).
  • CVE advanced - An expansion module to query the CIRCL CVE search API for more information about a vulnerability (CVE).
  • Cuckoo submit - A hover module to submit malware sample, url, attachment, domain to Cuckoo Sandbox.
  • Cytomic Orion - An expansion module to enrich attributes in MISP and share indicators of compromise with Cytomic Orion.
  • DBL Spamhaus - a hover module to check Spamhaus DBL for a domain name.
  • DNS - a simple module to resolve MISP attributes like hostname and domain to expand IP addresses attributes.
  • docx-enrich - an enrichment module to get text out of Word document into MISP (using free-text parser).
  • DomainTools - a hover and expansion module to get information from DomainTools whois.
  • EQL - an expansion module to generate event query language (EQL) from an attribute. Event Query Language
  • EUPI - a hover and expansion module to get information about an URL from the Phishing Initiative project.
  • Farsight DNSDB Passive DNS - a hover and expansion module to expand hostname and IP addresses with passive DNS information.
  • GeoIP - a hover and expansion module to get GeoIP information from geolite/maxmind.
  • GeoIP_City - a hover and expansion module to get GeoIP City information from geolite/maxmind.
  • GeoIP_ASN - a hover and expansion module to get GeoIP ASN information from geolite/maxmind.
  • [Google Threat Intelligence] (https://github.com/MISP/misp-modules/tree/main/misp_modules/modules/expansion/google_threat_intelligence.py) - An expansion module to have the observable's threat score assessed by Google Threat Intelligence.
  • GreyNoise - a hover and expansion module to get IP and CVE information from GreyNoise.
  • hashdd - a hover module to check file hashes against hashdd.com including NSLR dataset.
  • Hashlookup - An expansion module to enrich a file hash with hashlookup.circl.lu services (NSRL and other sources)
  • hibp - a hover module to lookup against Have I Been Pwned?
  • html_to_markdown - Simple HTML to markdown converter
  • HYAS Insight - a hover and expansion module to get information from HYAS Insight.
  • intel471 - an expansion module to get info from Intel471.
  • IP2Location.io - an expansion module to get additional information on an IP address using the IP2Location.io API
  • IPASN - a hover and expansion to get the BGP ASN of an IP address.
  • ipinfo.io - an expansion module to get additional information on an IP address using the ipinfo.io API
  • iprep - an expansion module to get IP reputation from packetmail.net.
  • Joe Sandbox submit - Submit files and URLs to Joe Sandbox.
  • Joe Sandbox query - Query Joe Sandbox with the link of an analysis and get the parsed data.
  • Lastline submit - Submit files and URLs to Lastline.
  • Lastline query - Query Lastline with the link to an analysis and parse the report.
  • macaddress.io - a hover module to retrieve vendor details and other information regarding a given MAC address or an OUI from MAC address Vendor Lookup. See integration tutorial here.
  • macvendors - a hover module to retrieve mac vendor information.
  • MALWAREbazaar - an expansion module to query MALWAREbazaar with some payload.
  • McAfee MVISION Insights - an expansion module enrich IOCs with McAfee MVISION Insights.
  • Mmdb server lookup - an expansion module to enrich an ip with geolocation information from an mmdb server such as ip.circl.lu.
  • ocr-enrich - an enrichment module to get OCRized data from images into MISP.
  • ods-enrich - an enrichment module to get text out of OpenOffice spreadsheet document into MISP (using free-text parser).
  • odt-enrich - an enrichment module to get text out of OpenOffice document into MISP (using free-text parser).
  • onyphe - a modules to process queries on Onyphe.
  • onyphe_full - a modules to process full queries on Onyphe.
  • OTX - an expansion module for OTX.
  • passivetotal - a passivetotal module that queries a number of different PassiveTotal datasets.
  • pdf-enrich - an enrichment module to extract text from PDF into MISP (using free-text parser).
  • pptx-enrich - an enrichment module to get text out of PowerPoint document into MISP (using free-text parser).
  • qrcode - a module decode QR code, barcode and similar codes from an image and enrich with the decoded values.
  • rbl - a module to get RBL (Real-Time Blackhost List) values from an attribute.
  • recordedfuture - a hover and expansion module for enriching MISP attributes with threat intelligence from Recorded Future.
  • reversedns - Simple Reverse DNS expansion service to resolve reverse DNS from MISP attributes.
  • securitytrails - an expansion module for securitytrails.
  • shodan - a minimal shodan expansion module.
  • Sigma queries - Experimental expansion module querying a sigma rule to convert it into all the available SIEM signatures.
  • Sigma syntax validator - Sigma syntax validator.
  • Socialscan - a hover module to check if an email address or a username is used on different online platforms, using the socialscan python library
  • SophosLabs Intelix - SophosLabs Intelix is an API for Threat Intelligence and Analysis (free tier available). SophosLabs
  • sourcecache - a module to cache a specific link from a MISP instance.
  • stairwell - an expansion module to enrich hash observables with the Stairwell API
  • STIX2 pattern syntax validator - a module to check a STIX2 pattern syntax.
  • ThreatCrowd - an expansion module for ThreatCrowd.
  • threatminer - an expansion module to expand from ThreatMiner.
  • TruSTAR Enrich - an expansion module to enrich MISP data with TruSTAR.
  • urlhaus - Query urlhaus to get additional data about a domain, hash, hostname, ip or url.
  • urlscan - an expansion module to query urlscan.io.
  • variotdbs - an expansion module to query the VARIoT db API to get more information about a Vulnerability
  • virustotal - an expansion module to query the VirusTotal API with a high request rate limit required. (More details about the API: here)
  • virustotal_public - an expansion module to query the VirusTotal API with a public key and a low request rate limit. (More details about the API: here)
  • VMray - a module to submit a sample to VMray.
  • VMware NSX - a module to enrich a file or URL with VMware NSX Defender.
  • VulnDB - a module to query VulnDB.
  • Vulners - an expansion module to expand information about CVEs using Vulners API.
  • Vysion - an expansion module to add dark web intelligence using Vysion API.
  • whois - a module to query a local instance of uwhois.
  • whoisfreaks - An expansion module for whoisfreaks that will provide an enriched analysis of the provided domain, including WHOIS and DNS information.
  • wikidata - a wikidata expansion module.
  • xforce - an IBM X-Force Exchange expansion module.
  • xlsx-enrich - an enrichment module to get text out of an Excel document into MISP (using free-text parser).
  • YARA query - a module to create YARA rules from single hash attributes.
  • YARA syntax validator - YARA syntax validator.

Export modules

Import modules

  • CSV import - Customizable CSV import module.
  • Cuckoo JSON - Cuckoo JSON import.
  • Email Import - Email import module for MISP to import basic metadata.
  • GoAML import - Module to import GoAML XML format.
  • Joe Sandbox import - Parse data from a Joe Sandbox json report.
  • Lastline import - Module to import Lastline analysis reports.
  • OCR - Optical Character Recognition (OCR) module for MISP to import attributes from images, scan or faxes.
  • OpenIOC - OpenIOC import based on PyMISP library.
  • ThreatAnalyzer - An import module to process ThreatAnalyzer archive.zip/analysis.json sandbox exports.
  • VMRay - An import module to process VMRay export.

How to contribute your own module?

Fork the project, add your module, test it and make a pull-request. Modules can be also private as you can add a module in your own MISP installation. For further information please see Contribute.

Licenses

For further Information see also the license file.