Skip to main content
Feedback

MISP MCP connector

Updated 

MISP is an open source threat intelligence platform for sharing, storing, and correlating indicators of compromise across security teams. The MISP MCP connector allows AI agents to create, update, and search attributes and events to manage threat intelligence data within a MISP instance. It also supports retrieving and deleting existing records, helping teams keep correlated threat data accurate and current across their environment.

Authentication type

  • API Key - Requires a static API key to be configured before the agent can connect to the service.

Uses

Use the MISP MCP connector to perform the following actions:

  • Track indicators of compromise across threat intelligence feeds and events
  • Correlate attributes and objects to identify related threats faster
  • Publish curated threat events to share intelligence with trusted partners
  • Automate feed synchronization to keep threat data current
  • Tag and organize events for streamlined threat categorization
  • Search historical events and attributes to investigate emerging threats
  • Map threat actor relationships using galaxy and organisation data
  • Monitor noticelists to flag sensitive or restricted indicators

Example prompts

Use the following example prompts to invoke MISP MCP connector tools from your AI assistant or Boomi Connect workflow:

  • Show me all attributes tagged as malicious in MISP from this week.
  • Create a new threat event in MISP for the phishing campaign we detected.
  • Search MISP for any events related to this IP address.
  • Publish the ransomware event in MISP so our partners can see it.
  • List all active feeds in MISP and tell me which ones are enabled.
  • Add a tag to the event about the recent malware outbreak in MISP.
  • Find all organisations in MISP that have contributed threat data this month.
  • Get details on the galaxy related to APT groups in MISP.
  • Disable the feed that keeps sending duplicate alerts in MISP.
  • Search MISP objects for anything matching this file hash.

MISP MCP connector tools

The MISP MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.

ToolDescription
getAllAttributesList all attributes
createAttributeCreate an attribute
getAttributeGet an attribute
updateAttributeUpdate an attribute
deleteAttributeDelete an attribute
searchAttributesSearch attributes
getAllEventsList all events
createEventCreate an event
getEventGet an event
updateEventUpdate an event
deleteEventDelete an event
publishEventPublish an event
unpublishEventUnpublish an event
searchEventsSearch events
addEventTagAdd tag to event
removeEventTagRemove tag from event
getAllFeedsList all feeds
createFeedCreate a feed
getFeedGet a feed
updateFeedUpdate a feed
enableFeedEnable a feed
disableFeedDisable a feed
getAllGalaxiesList all galaxies
getGalaxyGet a galaxy
deleteGalaxyDelete a galaxy
getAllNoticelistsList all noticelists
getNoticelistGet a noticelist
searchObjectsSearch objects
getAllOrganisationsList all organisations
getOrganisationGet an organisation
createOrganisationCreate an organisation
updateOrganisationUpdate an organisation
deleteOrganisationDelete an organisation
getAllTagsList all tags
createTagCreate a tag
updateTagUpdate a tag
deleteTagDelete a tag
getAllUsersList all users
createUserCreate a user
getUserGet a user
updateUserUpdate a user
deleteUserDelete a user
getAllWarninglistsList all warninglists
getWarninglistGet a warninglist
getSharingGroupsList sharing groups
On this Page