diff --git a/content/features.md b/content/features.md index af38cad2..39fdf7dc 100644 --- a/content/features.md +++ b/content/features.md @@ -1,67 +1,7 @@ - --- title: MISP features and functionalities +layout: features aliases: - - /features.html + - /features.html +description: Explore the collaboration, analysis, automation, interoperability, and security capabilities built into MISP. --- - -## Features of MISP, the open source threat sharing platform. - -A threat intelligence platform for sharing, storing and correlating Indicators of Compromise of targeted attacks, threat intelligence, financial fraud information, vulnerability information or even counter-terrorism information. Discover how MISP is used today in multiple organisations. Not only to store, share, collaborate on cyber security indicators, malware analysis, but also to use the IoCs and information to detect and prevent attacks, frauds or threats against ICT infrastructures, organisations or people. - -![](/img/banner.jpg "{ class='img-responsive'}") - -- A **complete and robust threat intelligence sharing platform** that can be deployed on-premise, in the cloud, or as a SaaS solution, suitable for organizations of all sizes. -- **Threat intelligence, ranging from indicators, through techniques to tactics, can be easily described in MISP**, from machine-readable actionable data to detailed reports in Markdown format. -- A flexible reporting system is integrated into MISP, enabling the description of threat intelligence with cross-references to the machine-readable components, including objects and attributes. -- A **fast and efficient database for atomic data points, indicators to complex objects and selectors**, enabling the storage of both technical and non-technical information related to cybersecurity intelligence as well as broader intelligence contexts. -- Automatic **correlation** engine, revealing relationships between attributes and indicators of malware, attack campaigns, analyses or other described threats. The correlation engine handles the interlinking of matching attributes as well as more advanced correlation patterns such as fuzzy hashing overlaps (e.g. ssdeep) and CIDR block matching. Correlations can also be enabled or event disabled at different levels of granularity. -- A **flexible data model**, where complex [objects](https://www.misp-project.org/objects.html) can be expressed and **linked together to express threat intelligence, incidents or connected elements**. -- Built-in **sharing functionality** to ease information exchange, using different, customisable, models of distribution. MISP can automatically synchronize events and attributes as well as higher level threat intelligence among different MISP instances. Advanced filtering functionalities can be used to meet each organization's sharing policy including a **flexible sharing group** capability and granularity up to the atomic attribute level. -- An **intuitive user-interface** for end-users to create, update and collaborate on events and attributes/indicators, in addition to a **graphical interface** to navigate seamlessly between events and their correlations as well as an **event graph** functionality to create and view relationships between objects and attributes. Advanced filtering functionalities and [warning lists](https://github.com/MISP/misp-warninglists) to help the analysts to contribute events and attributes and limit the risk of false-positives. -- A comprehensive **workflow system** to facilitate automatic, customisable data pipelines in MISP, including data qualification, automated analysis, modification, and publication control. -- **Storing data** in a structured format, enabling automated use of the database for various purposes, with extensive support for cybersecurity indicators, fraud indicators (e.g., in the financial sector), and broader intelligence contexts. -- All intelligence and information stored in MISP is accessible via the UI but also an [extensive ReST API described as OpenAPI](https://www.misp-project.org/openapi/). -- **Export**: Generate outputs in various formats, including various native IDS formats, OpenIOC, plain text, CSV, MISP JSON, STIX (XML and JSON) versions 1 and 2, NIDS exports (Suricata, Snort, and Bro/Zeek), RPZ zones, and cache formats for forensic tools. Additional formats, such as PDF, can be easily added and are available via the [misp-modules](https://github.com/MISP/misp-modules) or customised as built in export modules. -- **Import**: Support for free-text import, URL import, bulk import, batch import, and importing from formats a long list of formats, including MISP's own standard format, STIX 1.x/2.0, CSV, or various proprietary formats. Additional formats can be easily added via the [misp-modules](https://github.com/MISP/misp-modules) system. -- Flexible **free-text import** tool to simplify the integration of unstructured reports into MISP, with automatic detection and conversion of external reports via provided URLs and text reports with an automatic conversion into MISP reports, objects, and attributes. -- A user-friendly system to **collaborate** on events and attributes allowing MISP users to propose changes or updates to attributes/indicators or provide own perspectives or counter-analyses to shared information. -- An **extensive data analyst feature** allowing analysts to add opinions, relationships, or comments to any intelligence in MISP, which can be shared using MISP's sharing mechanisms. -- **Data sharing**: Automatically exchange and synchronize information in real-time with other parties and trust groups using MISP, with support for granular sharing levels and custom sharing groups. -- **delegating of sharing**: allows for a simple, pseudo-anonymous mechanism to delegate the publication of MISP data to communities. -- Flexible **API** to integrate MISP with your own solutions. MISP is bundled with [PyMISP](https://github.com/MISP/PyMISP) which is a flexible Python Library to fetch, add or update events attributes, handle malware samples or search for attributes. An exhaustive restSearch API to easily search for indicators in MISP and exports those in all the format supported by MISP. -- Built in tooling to build, test and analyse complex queries directly in the MISP GUI using a highly context aware, templated API client. -- **Adjustable taxonomy** to classify and tag events following your own classification schemes or [existing classification](https://github.com/MISP/misp-taxonomies). The taxonomy can be local to your MISP but also shareable among MISP instances. -- **Intelligence vocabularies** called MISP galaxy and bundled with existing [threat actors, malware, RAT, ransomware or MITRE ATT&CK](https://www.misp-project.org/galaxy.html) which can be easily linked with events, reports and attributes in MISP. -- **Expansion modules in Python** to expand MISP with your own services or activate already available [misp-modules](https://github.com/MISP/misp-modules). -- **Sighting support** to get observations from organizations concerning shared indicators and attributes. Sighting [can be contributed](https://www.circl.lu/doc/misp/automation/index.html#sightings-api) via the MISP user-interface and the API as MISP data or STIX sighting documents. -- **MISP Standard Format** support is integrated into MISP and used by a long list of tools and organisations worldwide. The [MISP standard format](https://www.misp-standard.org/) is stable and backward compatible with older datasets. -- **STIX support**: Import and export data in STIX versions 1 and 2 formats, leveraging the powerful [misp-stix library](https://github.com/misp/misp-stix). -- **Integrated encryption and signing of the notifications** via GnuPG and/or S/MIME depending on the user's preferences. -- **Dashboard feature**: Integrated into MISP, allowing users and organizations to create and share custom composited dashboard configurations as well as build bespoke monitoring solutions directly in a drag and drop interface. -- **Real-time** publish-subscribe channel within MISP to automatically get all changes (e.g. new events, indicators, sightings or tagging) in ZMQ (e.g. [SkillAegis](https://github.com/MISP/SkillAegis)) or Kafka publishing. -- **Flexible logging** subsystems to help with the auditing of the system as well as the user-base's actions on the system, with various output formats supported as well as a wide range of transport mechanisms for centralised logging needs. -- **Customisable RBAC**, allowing configurations of MISP to be run both as a permissive in-house tool as well as tightly regulated community instances. -- **Information signing and validation** for more diverse and sensitive information sharing communities. -- **Batteries included**: A long list of tooling for backups, integration with identity providers and authentication systems, information leakage prevention safety nets (such as [MISP-Guard](https://github.com/MISP/misp-guard)) as well as system monitoring tools. -- **Open-source commitment**: MISP and its copyright is fully owned by an interlocked license among all contributors, ensuring that no single organisation or company can ever change the license or model of MISP. Users of MISP can rely on the tool never turning into a closed source / proprietary / semi-open multi-tier model tool. - -## Main advantages - -The main benefit of using MISP is its ability to serve as a **comprehensive and robust platform for threat intelligence sharing and collaboration**, enabling organizations of all sizes to: - -- **Centralize and manage intelligence:** Store, structure, and analyze both technical and non-technical threat intelligence efficiently. -- **Enhance collaboration:** Share information securely and flexibly with trust groups, leveraging granular sharing mechanisms and real-time synchronization. -- **Improve detection and response:** Correlate indicators, enrich intelligence, and automate workflows to enhance detection, analysis, and response capabilities. -- **Foster integration and interoperability:** Seamlessly integrate with existing tools and systems using APIs, modular extensions, and support for standard formats like STIX and MISP's own standardized format. -- **Enable actionable insights:** Provide actionable, machine-readable intelligence while also supporting detailed reporting for strategic and operational decision-making. - -MISP empowers cybersecurity teams with a scalable, flexible, and user-friendly platform to streamline their threat intelligence processes and improve their collective defense capabilities. - -### Sharing with humans -Data you store is immediately available to your **colleagues** and **partners**. Store the event id in your ticketing system or be informed by the signed and encrypted email notifications. -### Sharing with machines -By generating **Snort/Suricata/Bro/Zeek IDS rules, STIX, OpenIOC**, text or csv exports MISP allows you to **automatically** import data in your detection systems resulting in **better and faster detection** of intrusions. Importing data can also be done in various ways: **free-text import, OpenIOC, batch import**, sandbox result import or using the preconfigured or **custom templates**. If you run MISP internally, data can also be uploaded and downloaded automagically **from and to externally hosted MISP instances**. Thanks to this automation and the effort of others you are now in possession of valuable indicators of compromise with no additional work. - -### Collaborative sharing of analysis and correlation -How often has your team analyzed to realise at the end that a **colleague had already worked on another, similar, threat**? Or that an external report has already been made? When new data is added MISP will immediately show **relations with other observables and indicators**. This results in more efficient analysis, but also allows you to have a better picture of the TTPs, related campaigns and attribution. The **discussion** feature will also enable conversations between multiple analysts resulting in **win-win** for everyone. ![](/img/blog/automation-icon.png "{class='img-responsive'}") diff --git a/data/feature_catalog.yaml b/data/feature_catalog.yaml new file mode 100644 index 00000000..3a6ca39d --- /dev/null +++ b/data/feature_catalog.yaml @@ -0,0 +1,97 @@ +- id: intelligence + title: Structure & analyse + icon: fas fa-project-diagram + summary: Turn atomic observations and rich reports into connected, actionable intelligence. + features: + - title: Flexible intelligence model + description: Describe everything from atomic indicators and selectors to linked objects, tactics, techniques, and detailed Markdown reports. + - title: High-performance correlation + description: Reveal relationships through exact matches and advanced patterns, including fuzzy hashes and CIDR overlaps, with granular controls. + - title: Analyst collaboration + description: Add opinions, relationships, comments, sightings, proposals, and counter-analysis directly to shared intelligence. + - title: Context and vocabularies + description: Apply shareable taxonomies, warning lists, and MISP galaxies for threat actors, malware, ransomware, tools, and MITRE ATT&CK. + - title: Visual exploration + description: Navigate correlations and build event graphs that connect events, objects, and attributes into a coherent picture. + +- id: sharing + title: Share & collaborate + icon: fas fa-people-arrows + summary: Exchange intelligence with the right communities while retaining precise control over distribution. + features: + - title: Granular sharing controls + description: Use distribution levels and custom sharing groups, down to individual attributes, to match each organisation's sharing policy. + - title: Real-time synchronisation + description: Automatically exchange events, attributes, and higher-level intelligence among MISP instances and trusted communities. + - title: Delegated publishing + description: Delegate publication to a trusted community through a simple, pseudo-anonymous sharing mechanism. + - title: Secure notifications + description: Sign and encrypt notifications with GnuPG or S/MIME according to each user's preferences. + - title: Information integrity + description: Sign and validate shared information for diverse and sensitive information-sharing communities. + +- id: automation + title: Automate & integrate + icon: fas fa-cogs + summary: Connect MISP to your security stack and turn intelligence into repeatable, automated action. + features: + - title: Extensive REST API + description: Access all intelligence through an OpenAPI-described API, exhaustive restSearch capabilities, and the bundled PyMISP library. + link: /openapi/ + - title: Custom workflows + description: Build automatic data pipelines for qualification, analysis, modification, and publication control. + - title: Enrichment modules + description: Extend MISP with Python expansion, import, and export modules or connect your own services. + link: https://github.com/MISP/misp-modules + - title: Real-time streaming + description: Publish new events, indicators, sightings, and tagging changes through ZMQ or Kafka channels. + - title: Built-in API tooling + description: Build, test, and analyse complex queries in the interface with a context-aware, templated API client. + +- id: interoperability + title: Import & export + icon: fas fa-exchange-alt + summary: Move intelligence freely with open standards, common security formats, and adaptable modules. + features: + - title: Broad export support + description: Generate MISP JSON, STIX 1 and 2, OpenIOC, CSV, text, Suricata, Snort, Zeek, RPZ, forensic cache formats, and more. + - title: Flexible ingestion + description: Import MISP, STIX, CSV, proprietary formats, URLs, batches, sandbox results, and bulk data through the UI or API. + - title: Free-text conversion + description: Extract structured reports, objects, and attributes from unstructured text and externally hosted reports. + - title: MISP Standard Format + description: Rely on a stable, backward-compatible format adopted by tools and organisations around the world. + link: https://www.misp-standard.org/ + - title: STIX interoperability + description: Import and export STIX 1 and 2 content through the actively maintained misp-stix library. + link: https://github.com/MISP/misp-stix + +- id: operations + title: Operate at scale + icon: fas fa-tachometer-alt + summary: Deploy a robust platform with the controls and observability required by organisations of any size. + features: + - title: Deployment flexibility + description: Run MISP on-premise, in the cloud, or as a SaaS solution for teams and communities of any size. + - title: Custom dashboards + description: Create and share composable dashboards or build bespoke monitoring views in a drag-and-drop interface. + - title: Auditable logging + description: Track system and user activity with flexible logging formats and transports for centralised monitoring. + - title: Customisable RBAC + description: Configure permissive internal deployments or tightly regulated community instances with role-based access controls. + - title: Batteries included + description: Use tooling for backups, identity and authentication integration, leakage prevention, and system monitoring. + +- id: open + title: Open by design + icon: fas fa-lock-open + summary: Build on a transparent, community-owned foundation without proprietary lock-in. + features: + - title: Open-source commitment + description: MISP's contributor-owned licensing ensures the platform cannot be converted into a closed or proprietary product. + - title: Open data model and API + description: Integrate without lock-in using documented formats, open standards, and a comprehensive API. + - title: Extensible ecosystem + description: Adapt export modules, enrichment services, taxonomies, galaxies, object templates, and workflows to your needs. + - title: Community-powered + description: Benefit from an international community that develops software, open standards, knowledge bases, and integrations together. diff --git a/layouts/page/features.html b/layouts/page/features.html new file mode 100644 index 00000000..a1961dae --- /dev/null +++ b/layouts/page/features.html @@ -0,0 +1,76 @@ + + + + {{ partial "headers.html" . }} + {{ partial "custom_headers.html" . }} + + +
+ {{ partial "top.html" . }} + {{ partial "nav.html" . }} + +
+
+
+
+ Open source threat intelligence +

Intelligence becomes more powerful when it is connected.

+

MISP gives teams one flexible platform to collect, enrich, correlate, automate, and securely share threat intelligence—from a single indicator to a community-wide knowledge base.

+ +
+ +
+
+ + + +
+ A complete intelligence lifecycle +

Built for analysts, communities, and machines

+

Use structured, machine-readable intelligence without losing the human context behind it. MISP combines day-to-day analyst tools with scalable sharing and automation.

+
+ +
+ {{ range $index, $group := .Site.Data.feature_catalog }} +
+
+
+
0{{ add $index 1 }}

{{ $group.title }}

{{ $group.summary }}

+
+
+ {{ range $group.features }} +
+ +

{{ .title }}

{{ .description }}

{{ with .link }}Learn more {{ end }}
+
+ {{ end }} +
+
+ {{ end }} +
+ +
+
+
Start sharing smarter

Put collective intelligence to work.

Deploy MISP, connect your tools, and join a global ecosystem built around open collaboration.

+ +
+
+
+ + {{ partial "footer.html" . }} +
+ {{ partial "scripts.html" . }} + + diff --git a/static/css/custom.css b/static/css/custom.css index 790d6cf9..942b0d8a 100644 --- a/static/css/custom.css +++ b/static/css/custom.css @@ -1010,3 +1010,133 @@ ul ul { transition-duration: 0.01ms !important; } } + +/* Feature catalogue */ +.features-page { + padding: 0 !important; + overflow: hidden; +} + +.features-hero { + background: linear-gradient(125deg, #071d29 0%, #0b4353 58%, #087f98 100%); + color: #fff; + padding: 92px 0 82px; + position: relative; +} + +.features-hero::before { + background: radial-gradient(circle at 75% 40%, rgba(83, 215, 231, 0.2), transparent 34%); + content: ""; + inset: 0; + position: absolute; +} + +.features-hero .container { + align-items: center; + display: flex; + gap: 80px; + position: relative; +} + +.features-hero__content { max-width: 680px; } +.features-eyebrow { + color: #47cee0; + display: block; + font-size: 13px; + font-weight: 750; + letter-spacing: .14em; + margin-bottom: 15px; + text-transform: uppercase; +} + +.features-hero h1 { + color: #fff; + font-size: clamp(42px, 5vw, 66px); + letter-spacing: -.05em; + line-height: 1.02; + margin: 0 0 25px; +} + +.features-hero p { + color: #d7edf1; + font-size: 19px; + line-height: 1.65; + margin-bottom: 30px; + max-width: 640px; +} + +.features-hero__actions { align-items: center; display: flex; flex-wrap: wrap; gap: 25px; } +.features-hero .btn-template-main, +.features-cta .btn-template-main { background: #fff; border-color: #fff; color: #006f86; } +.features-hero .btn-template-main:hover, +.features-cta .btn-template-main:hover { background: #dff5f8; border-color: #dff5f8; } +.features-text-link { color: #fff; font-weight: 700; } +.features-text-link:hover, .features-text-link:focus { color: #9ce6ef; text-decoration: none; } +.features-text-link i { margin-left: 7px; } + +.features-hero__visual { flex: 0 0 340px; height: 340px; position: relative; } +.features-hero__visual::before, +.features-hero__visual::after { border: 1px solid rgba(133, 226, 238, .28); border-radius: 50%; content: ""; inset: 28px; position: absolute; } +.features-hero__visual::after { inset: 76px; } +.signal { align-items: center; background: rgba(255,255,255,.13); border: 1px solid rgba(255,255,255,.3); border-radius: 15px; box-shadow: 0 14px 35px rgba(0,0,0,.18); display: flex; height: 60px; justify-content: center; position: absolute; width: 60px; z-index: 1; } +.signal i { color: #8ce4ef; font-size: 22px; } +.signal--one { left: 12px; top: 78px; } +.signal--two { right: 8px; top: 64px; } +.signal--three { bottom: 26px; right: 50px; } +.signal--core { background: #fff; border: 0; border-radius: 50%; color: #006f86; flex-direction: column; height: 142px; left: 99px; top: 99px; width: 142px; } +.signal--core span { font-size: 34px; font-weight: 800; letter-spacing: -.04em; } +.signal--core small { color: #54717b; font-size: 9px; font-weight: 700; letter-spacing: .08em; text-transform: uppercase; } + +.features-jump { background: #fff; border-bottom: 1px solid var(--line); box-shadow: var(--shadow-sm); position: relative; } +.features-jump .container { display: flex; overflow-x: auto; scrollbar-width: thin; } +.features-jump a { align-items: center; color: #405560; display: flex; flex: 1 0 auto; font-size: 13px; font-weight: 700; gap: 8px; justify-content: center; padding: 19px 12px; text-decoration: none; } +.features-jump a:hover, .features-jump a:focus { background: var(--primary-accent-light); color: var(--primary-accent-dark); } + +.features-intro { padding-bottom: 70px; padding-top: 92px; text-align: center; } +.features-intro h2 { font-size: 40px; margin: 0 0 18px; } +.features-intro p { color: var(--ink-muted); font-size: 18px; margin: auto; max-width: 760px; } +.features-catalog { padding-bottom: 60px; } +.feature-group { border-top: 1px solid var(--line); display: grid; gap: 55px; grid-template-columns: 320px 1fr; padding: 72px 0; scroll-margin-top: 90px; } +.feature-group__header { display: flex; gap: 18px; } +.feature-group__icon { align-items: center; background: var(--primary-accent-light); border-radius: 14px; color: var(--primary-accent-dark); display: flex; flex: 0 0 52px; height: 52px; justify-content: center; } +.feature-group__icon i { font-size: 20px; } +.feature-group__number { color: #8aa0a9; font-size: 12px; font-weight: 800; letter-spacing: .12em; } +.feature-group h2 { font-size: 28px; margin: 3px 0 12px; } +.feature-group__header p { color: var(--ink-muted); line-height: 1.6; } +.feature-grid { display: grid; gap: 16px; grid-template-columns: repeat(2, minmax(0, 1fr)); } +.feature-card { background: var(--surface-soft); border: 1px solid transparent; border-radius: var(--radius-md); display: flex; gap: 14px; padding: 24px; transition: border-color 160ms ease, box-shadow 160ms ease, transform 160ms ease; } +.feature-card:hover { background: #fff; border-color: #cfe2e7; box-shadow: var(--shadow-sm); transform: translateY(-2px); } +.feature-card > i { align-items: center; background: #d9f2eb; border-radius: 50%; color: #197a60; display: flex; flex: 0 0 25px; height: 25px; justify-content: center; margin-top: 1px; } +.feature-card h3 { font-size: 18px; margin: 0 0 8px; } +.feature-card p { color: var(--ink-muted); font-size: 14px; line-height: 1.65; margin: 0; } +.feature-card a { display: inline-block; font-size: 13px; font-weight: 700; margin-top: 12px; } + +.features-cta { background: #0a3543; color: #fff; padding: 72px 0; } +.features-cta .container { align-items: center; display: flex; justify-content: space-between; } +.features-cta h2 { color: #fff; font-size: 38px; margin: 0 0 10px; } +.features-cta p { color: #c9e3e8; margin: 0; } +.features-cta__actions { display: flex; flex: 0 0 auto; gap: 12px; margin-left: 40px; } +.btn-ghost { background: transparent; border: 1px solid rgba(255,255,255,.5); color: #fff; } +.btn-ghost:hover, .btn-ghost:focus { background: rgba(255,255,255,.1); color: #fff; } + +@media (max-width: 991px) { + .features-hero { padding: 70px 0; } + .features-hero__visual { display: none; } + .feature-group { gap: 35px; grid-template-columns: 1fr; } + .features-cta .container { align-items: flex-start; flex-direction: column; } + .features-cta__actions { margin: 28px 0 0; } +} + +@media (max-width: 767px) { + .features-hero { padding: 56px 0; } + .features-hero h1 { font-size: 40px; } + .features-hero p { font-size: 17px; } + .features-jump a { justify-content: flex-start; } + .features-intro { padding-bottom: 48px; padding-top: 62px; } + .features-intro h2 { font-size: 32px; } + .feature-group { padding: 52px 0; } + .feature-grid { grid-template-columns: 1fr; } + .features-cta { padding: 54px 0; } + .features-cta h2 { font-size: 31px; } + .features-cta__actions { align-items: stretch; flex-direction: column; width: 100%; } +}