This document explains to set up and use the MISP intel feed with TruSTAR Station.
MISP is a threat intelligence platform for gathering, sharing, storing and correlating IOCs from targeted attacks, threat intelligence, financial fraud information, vulnerability information or even counter-terrorism information.
- Time to Install: 10 minutes
- Type of Feed: Automatic updates
- Update Frequency: 15 minutes
- Source Type: Open Feed
- Your MISP Server URL
- MISP Authentication Key
After you have retrieved your MISP URL and Auth Keys follow these steps:
- Sign into TruSTAR.
- Click the Marketplace tab.
- Choose Closed Sources.
- Click Subscribe on the MISP box.
- Enter your MISP API key and click Save Credentials & Request Subscription.
TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.
How It Works
The TruSTAR integration retrieves data from MISP every 15 minutes. The initial pull will query events for the last 24 hours and checkpoint the timestamp to use as a basis to ingest the latest events every 15 minutes.
Please see our API documentation for more information about data elements for TruSTAR Reports.
Report External Id
Entire Event Content
If an event with the same UUID is observed, the existing report is updated by replacing it with the updated content.
Q: What data does TruSTAR pull from MISP?
The TruSTAR integration currently only pulls newly created events in MISP. The whole event body is pulled down and submitted as the body of the report in TruSTAR.
Q: What about Historical Data?
TruSTAR can use the MISP sync feature to download all historical data from the MISP server and upload that data into the user's enclave in TruSTAR.
No reported issues.