MISP MCP connector
MISP is an open source threat intelligence platform for sharing, storing, and correlating indicators of compromise across security teams. The MISP MCP connector allows AI agents to create, update, and search attributes and events to manage threat intelligence data within a MISP instance. It also supports retrieving and deleting existing records, helping teams keep correlated threat data accurate and current across their environment.
Authentication type
- API Key - Requires a static API key to be configured before the agent can connect to the service.
Uses
Use the MISP MCP connector to perform the following actions:
- Track indicators of compromise across threat intelligence feeds and events
- Correlate attributes and objects to identify related threats faster
- Publish curated threat events to share intelligence with trusted partners
- Automate feed synchronization to keep threat data current
- Tag and organize events for streamlined threat categorization
- Search historical events and attributes to investigate emerging threats
- Map threat actor relationships using galaxy and organisation data
- Monitor noticelists to flag sensitive or restricted indicators
Example prompts
Use the following example prompts to invoke MISP MCP connector tools from your AI assistant or Boomi Connect workflow:
Show me all attributes tagged as malicious in MISP from this week.Create a new threat event in MISP for the phishing campaign we detected.Search MISP for any events related to this IP address.Publish the ransomware event in MISP so our partners can see it.List all active feeds in MISP and tell me which ones are enabled.Add a tag to the event about the recent malware outbreak in MISP.Find all organisations in MISP that have contributed threat data this month.Get details on the galaxy related to APT groups in MISP.Disable the feed that keeps sending duplicate alerts in MISP.Search MISP objects for anything matching this file hash.
MISP MCP connector tools
The MISP MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.
| Tool | Description |
|---|---|
| getAllAttributes | List all attributes |
| createAttribute | Create an attribute |
| getAttribute | Get an attribute |
| updateAttribute | Update an attribute |
| deleteAttribute | Delete an attribute |
| searchAttributes | Search attributes |
| getAllEvents | List all events |
| createEvent | Create an event |
| getEvent | Get an event |
| updateEvent | Update an event |
| deleteEvent | Delete an event |
| publishEvent | Publish an event |
| unpublishEvent | Unpublish an event |
| searchEvents | Search events |
| addEventTag | Add tag to event |
| removeEventTag | Remove tag from event |
| getAllFeeds | List all feeds |
| createFeed | Create a feed |
| getFeed | Get a feed |
| updateFeed | Update a feed |
| enableFeed | Enable a feed |
| disableFeed | Disable a feed |
| getAllGalaxies | List all galaxies |
| getGalaxy | Get a galaxy |
| deleteGalaxy | Delete a galaxy |
| getAllNoticelists | List all noticelists |
| getNoticelist | Get a noticelist |
| searchObjects | Search objects |
| getAllOrganisations | List all organisations |
| getOrganisation | Get an organisation |
| createOrganisation | Create an organisation |
| updateOrganisation | Update an organisation |
| deleteOrganisation | Delete an organisation |
| getAllTags | List all tags |
| createTag | Create a tag |
| updateTag | Update a tag |
| deleteTag | Delete a tag |
| getAllUsers | List all users |
| createUser | Create a user |
| getUser | Get a user |
| updateUser | Update a user |
| deleteUser | Delete a user |
| getAllWarninglists | List all warninglists |
| getWarninglist | Get a warninglist |
| getSharingGroups | List sharing groups |