implementing-threat-intelligence-platform

Installation
SKILL.md

Instructions

  1. Install dependencies: pip install pymisp requests stix2
  2. Deploy MISP instance and generate an API key from Administration > Auth Keys.
  3. Use PyMISP to connect and create threat intelligence events:
    • Create events with threat level, distribution, and analysis status
    • Add attributes (ip-dst, domain, sha256, url) with to_ids flags
    • Tag events with MITRE ATT&CK technique identifiers
    • Correlate events across organizations
  4. Ingest from external feeds: URLhaus, Feodo Tracker, MalwareBazaar.
  5. Enrich IOCs via VirusTotal and AbuseIPDB APIs.
  6. Export correlated events as STIX 2.1 bundles.
python scripts/agent.py --misp-url https://misp.local --misp-key <api_key> --ingest-feeds --output misp_report.json

Examples

Related skills
Installs
1
GitHub Stars
6.2K
First Seen
Mar 15, 2026