Blogs

MISP 2.4.80 released (aka MISP objects release)

A new version of MISP 2.4.80 has been released including the most awaited MISP objects feature along with other new features, security fix CVE-2017-14337 and improvements.

Continue reading

MISP 2.4.81 released (aka new graphical visualisation and STIX 2.0 export)

A new version of MISP 2.4.81 has been released including a significant rework of the graphical visualisation, support for STIX 2.0 export, multiple bug-fixes and improvements for misp-objects.

Continue reading

MISP 2.4.79 released

A new version of MISP 2.4.79 has been released including an important security fix (persistent XSS on comment field), multiple bug fixes and new functionalities.

Continue reading

MISP 2.4.78 released

A new version of MISP 2.4.78 has been released including an important security fix (if you use sharing groups), multiple bug fixes and some new functionalities.

Continue reading

MISP 2.4.77 released

A new version of MISP 2.4.77 has been released including security fixes, bug fixes and various improvements.

This version includes multiple security fixes reported by cert.govt.nz including:

Continue reading

MISP 2.4.76 released

A new version of MISP 2.4.76 has been released including bug fixes and a set of performance improvements at the ingestion level.

Continue reading

MISP 2.4.75 released

A new version of MISP 2.4.75 has been released including bug fixes and a set of performance improvements.

In this release the most important improvement is performance tuning to improve the day-to-day life of the users. The performance improvements are most explicitly on:

Continue reading

MISP 2.4.74 released

A new version of MISP 2.4.74 has been released including new features, improvements and bug fixes.

The ZeroMQ pub-sub feature has been significantly improved in MISP to allow for a complete flexible notification scheme for a host of actions which take place within a MISP instance, such as:

Continue reading

MISP 2.4.73 released

A new version of MISP 2.4.73 has been released including new features, improvements and bug fixes.

A new module type Cortex has been introduced allowing for easy integration of MISP and Cortex. Cortex is the analysis engine part of the TheHive Project which supports expansion services from Cortex within MISP. A new setting has been added to support Cortex similarly to MISP expansion modules where you set the remote Cortex instance. MISP includes a new Cortex attribute type to allow for the raw analysis to be stored along with the event for subsequent analysis.

Continue reading

MISP 2.4.72 released

A new version of MISP 2.4.72 has been released including improvements and important bug fixes.

Improvements have been introduced to better support large MISP instances:

Continue reading

MISP 2.4.71 released

A new version of MISP 2.4.71 has been released including new features, improvements and important bug fixes.

  • Distribution can now be set in the free-text and modules import.
  • Password complexity default tightened to allow passphrase-like in addition to password.
  • Password regexp (can be considered a CTF-challenge for some users) is now available as a hint.
  • API restsearch has been significantly improved allowing to support alternate download types from the restsearch (currently OpenIOC is supported). OpenIOC export and CIDR tool refactored.
  • Organisation blacklist is now enabled by default and sample UUIDs/organisations are now blacklisted by default.
  • API The “proposal to delete flag” is now available in the API output.
  • Improved error handling when failing to add a tag.
  • API Event history is now available via the API.
  • Set comment field to an empty string in the attributes pre-validation (to avoid null comment field).
  • Correlation can now be disabled for site admin even if (s)he is not the owner.

Various bugs fixed in the sharing group synchronisation and delegation. Improvements to the UI popups when using low-resolution (aka potato displays).

Continue reading

MISP 2.4.70 released

A new version of MISP 2.4.70 has been released including new features, improvements and important bug fixes.

  • A significant improvement has been introduced to the MISP user-interface to make it more accessible especially for visually impaired users.
  • API improvements introduced to allow adding several attributes in one go.
  • API extended to support the functionality of adding and editing MISP servers.
  • A simple update feature from the user-interface was introduced to ease the update process of MISP.
  • New attribute types (hex, sigma and impfuzzy) have been introduced for new misp-objects and to improve the support of the new sigma format. Sigma is a generic signature format for SIEM Systems. This new attribute type will help the development of a sigma converter via misp-modules.
  • Test and diagnostic for the MISP server synchronisation has been significantly improved. The old legacy and mangle sync for very old MISP instances (2.3x) has been removed in an effort to make the code cleaner and improve the synchronisation process with recent MISP instances.

Many other bugs fixed and minor features added.

Continue reading

MISP 2.4.69 released

A new version of MISP 2.4.69 has been released including multiple security bug fixes and minor improvements.

Improvements added:

  • User creation now shows a warning if the encrypted notification cannot be send due to encryption issue.
  • Tagged properly added to Suricata rules.

Two security vulnerabilities (XSS) reported by Tien Phan and David Maciejak of Fortinet’s FortiGuard Labs were fixed. Thanks to them for reporting the vulnerabilities.

Continue reading

MISP 2.4.68 released

A new version of MISP 2.4.68 has been released including multiple bug fixes and improvements.

Improvements and features added:

  • Enable sync permissions for read-only accounts.
  • Upload org logo can now be performed via the org edit/view interface.
  • An option to disable cached export has been added for low disk space servers.

Blacklisting of deleted events is now enabled by default. This feature existed before but was not enabled by default. This feature allows MISP users to ensure that deleted events never propagate back to their instance. The blacklist can easily be managed from the MISP interface. As this feature is a default behaviour that a large majority of the MISP community needs, we have decided to enable this feature by default starting from version 2.4.68.

Continue reading

MISP 2.4.67 released

A new version of MISP 2.4.67 has been released, including improvements to the sighting feature, user management and activity visualisation.

Sighting activities over tags and galaxy clusters are now visualised using sparklines, giving us an interesting outlook of contextual activity:

Continue reading

Sighting the next level

Sighting is an endless topic of discussion. This is a required feature especially when information or indicators are regularly shared to gather feedback from users said shared data. Adequate sightings can be an incredible source of information in order to describe the life-time of an indicator, its evolution and especially to ensure the understanding of indicators among a group of users using the information to detect, mitigate or block malicious activities in their infrastructures. The potential is endless, potentially being a significant gain for organised communities of infosec professionals sharing information or even serve as a requirement for advanced algorithms ranging from machine learning to reinforcement learning. But to reach such a state of a feedback loop, you first require a functional model of sighting.

Continue reading

MISP 2.4.65 released

A new version of MISP 2.4.65 (and 2.4.64) has been released, including bug fixes and new features.

API access added to the MISP statistics providing additional statistics regarding information on contributions by organisation, attributes used and tags. The API can be also used by monitoring tools to monitor the state of a MISP instance.

Continue reading

MISP 2.4.63 released

A new version of MISP 2.4.63 has been released, including bug fixes and new features.

New features in the API:

  • Allowing fetching of full discussion threads via the API.
  • Add and remove tags from objects by uuid (in addition to the id).

Added a new setting to show post count on the event index including a notification if it has a post newer than 24 hours.

Continue reading

MISP 2.4.62 and PyMISP 2.4.62 released

A new version of MISP 2.4.62 has been released, including bug fixes and new features.

MISP feed has been expanded to support local feed allowing users to import feeds from local directories (if MISP format) or local files (like free-text or CSV import) in addition to the network feeds.

Continue reading

MISP 2.4.61 released

A new version of MISP 2.4.61 has been released, including a critical bug fix, new features and minor updates. We strongly recommend to update MISP to this latest version.

Continue reading