When Threat Intelligence Outgrows the Spreadsheet: Moving to MISP
For a lot of teams, tracking indicators and notes in a spreadsheet, then feeding them manually into detection and prevention systems, works well for months or even years. As your program grows, you'll eventually want to do things that get harder in a flat table. None of that is impossible in a spreadsheet. It just gets slower and more fragile as volume and complexity grow. For most teams reaching that point, we recommend MISP as the next step. It gives you more structure, correlation, automation and sharing capability without requiring you to build an overly complex CTI environment from day one.
MISP Beta UI/UX Mode (v2.5.32): A Walkthrough from Contributor Chris Horsley
We’ve been doing some work at Cosive to modernise the MISP user interface and bring more responsive web design into the experience. The result is a new beta UI that you can enable today if you’re running a recent version of MISP (v2.5.32 or later).This update is driven by a simple goal: make MISP easier to use, especially for analysts working on smaller screens or remotely.
MISP 2025 Retrospective: Monthly Highlights & Workflow Improvements
The incredibly active MISP developer community put out a dozen-plus releases in 2025 – and the results speak for themselves in new features and quality-of-life improvements for threat intel teams. In this article we recap some of the highlights from 2025, and extend a big thank you to the MISP core team and community for their hard work keeping this critical open-source tool moving forward.
Creating CTI Like a Journalist
I'm going to argue that as CTI analysts, we often get lost in the middle of these technical woods and forget about the ultimate purpose of threat intel: our outputs. These are commonly called threat intelligence products; the reports, alerts, or briefings we send to help others make decisions and take action. So how do we stay focused on the real purpose of CTI: producing useful, actionable outputs? Consider the lessons from an occupation we’ve had lifelong exposure to: journalism.
Using the CTI-CMM Model to Evaluate Threat Intel Program Maturity
It’s okay to admit that you don’t know exactly what CTI means. Of course, you know it stands for Cyber Threat Intelligence, and you might have a general sense it has something to do with staying on top of threats. How, though, do you actually build a successful CTI program in an organisation? What activities should it perform? What should it produce? For who?
Using MISP Bookmarks with Workflows for Team Coordination
Have you tried the Bookmarks feature in MISP yet? It’s much more powerful than you might think. Bookmarks are incredibly useful because within a team, we need to know what to take action on from all the new MISP events that come in over the last 24 hours. MISP bookmarks give us a way to save searches that help us isolate the signal from the noise. Paired with the Workflow features, they give us some powerful options to get our team on the same page.
Getting More Out of MISP and Microsoft Sentinel
Typically, SecOps analysts will have many daily routines, one of which will be to check their favourite Threat Intelligence Platforms, read the latest threats and note down any that are worthy of attention. Next, they’ll add those threats to the their central log analysis and alerting platform (e.g. Microsoft Sentinel) as something to look for. Depending on how many feeds analysts are watching and how active the bad actors are, this can be a very time consuming process. Granted, an important one, but still time consuming. Wouldn't it be nice if we could save the planet one tree at a time by doing away with all the post-it notes with one-off IP addresses and domain names? Could we get MISP and Microsoft Sentinel to talk directly without wasting analyst time?
The Opportunity Cost of Self-hosting MISP
A term with origins in macroeconomics, opportunity cost is the hidden cost of choosing one course of action over another, when both cannot be chosen at the same time. Opportunity costs are not always financial. For example, the opportunity cost of playing video games instead of going for a hike are the benefits you’d have likely gained from hiking, such as improved fitness and mental health. Security teams also incur opportunity costs whenever they pick one way to spend their time and resources over another. The opportunity cost of self-hosting and maintaining MISP is the additional time and brainpower teams could have otherwise spent gathering and leveraging usable threat intelligence and enhancing their organisation’s security posture.


