A small Model Context Protocol (MCP) server for searching the MISP galaxy knowledge base.
#misp #cti #threatintelligence #opensource #reallyopen #mcp #ai
🔗 https://github.com/MISP/misp-galaxy-mcp
----------------
🛠️ Tool
===================
zsazsa CTI is a cyber threat intelligence program management and production platform built around MISP. It links collection, triage, analyst workflows, requirement management, publishing, and stakeholder delivery in a single integrated workflow.
The platform targets teams that treat threat intelligence as an operational capability rather than a collection of loose documents and disconnected scripts. Analysts move from source events to validated intelligence products, align output to PIR and GIR priorities, distribute to stakeholders, and feed response back into program maturity signals.
Key functional areas:
Dashboard provides a live snapshot: active PIRs and GIRs, stakeholder counts, analyser freshness, the last 24 hours of processing, and scraper events awaiting triage.
Stakeholders records who receives output, with role, organisation, TLP clearance, product subscriptions, and notification channels. Includes a power and interest matrix for engagement planning.
Requirements (PIR and GIR) hold the intelligence questions driving collection, with scope, ownership, and distribution. Adding scope to a requirement highlights matching events in the data collection view.
RFIs handle one-off requests from intake to closure, with SLA, owner, linked PIR or GIR, response confidence, attachments, notes, and feedback.
Data collection is the cached view of everything arriving from the scraper MISP, other MISP servers, and manual or newsletter sources. Analysts browse and triage events, enrich them with scope from MISP galaxies, generate AI summaries, and start a product straight from a source event.
Products form a searchable catalogue: Flash Intel Alerts, Vulnerability Advisories, Daily Threat Briefings, Threat Landscape Reports, Indicator Feeds, and Threat Actor Profiles.
Statistics cover pipeline and program metrics, RFI and feedback figures, and a scope coverage view. A CTI-CMM maturity panel maps the program against levels CTI0 to CTI3.
MISP integration
All operational data resides in MISP using events, object templates, attributes, and event reports. This preserves auditability and allows teams to inspect raw records directly in MISP. The MISP event history serves as an audit trail for every change to a product, stakeholder, or requirement. Product content and supporting context sit together, so analysts move from collection evidence to published output without losing traceability.
The built-in reference panel helps teams apply common intelligence concepts consistently, including the Admiralty Scale, TLP, and CTI evaluation criteria.
Considerations
The platform assumes you are already running or willing to adopt MISP as the backbone of your CTI stack. Teams without an existing MISP instance face additional deployment overhead. The AI summary feature in data collection is mentioned but the underlying model or service is not specified. Not independently verified.
For CTI teams struggling with fragmented workflows, zsazsa provides a structured path from collection to delivery with built-in maturity measurement. The MISP-native design eliminates data silos between stages.
🔹 CTI #MISP #threat_intelligence #tool #zsazsa
🔗 Source: https://github.com/zsazsa-project/zsazsa
You've seen all posts