Skip to content
Back to skills

Analyzing Threat Landscape With Misp

ASecurity

Query a MISP (Malware Information Sharing Platform) instance via PyMISP

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentspythonbashtestingapisecurity

Works with

  • api

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 4 files and shows the line behind each finding

Scanned September 2, 2026

npx -y skills add nuroctane/nur-cli --skill analyzing-threat-landscape-with-misp --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Analyzing Threat Landscape With Misp?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Analyzing Threat Landscape With Misp
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nuroctane-analyzing-threat-landscape-with-misp/badge)](https://www.skillsdirectory.com/skills/nuroctane-analyzing-threat-landscape-with-misp)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: analyzing-threat-landscape-with-misp
description: Query a MISP (Malware Information Sharing Platform) instance via PyMISP
  to compute event statistics, IOC type breakdowns, threat actor galaxy clusters,
  and tag trends, and generate threat landscape reports with temporal trends. Use
  when asked to analyze threat intelligence data, summarize top threat actors or
  malware families, or produce a CTI landscape report from MISP events.
domain: cybersecurity
subdomain: threat-intelligence
tags:
- threat-intelligence
- misp
- threat-landscape
- ioc-analysis
- cti
- threat-sharing
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- File Metadata Consistency Validation
- Application Protocol Command Analysis
- Identifier Analysis
- Content Format Conversion
- Message Analysis
nist_csf:
- ID.RA-01
- ID.RA-05
- DE.CM-01
- DE.AE-02
mitre_attack:
- T1566
- T1071.001
- T1568
- T1583.001
- T1102
---


# Analyzing Threat Landscape with MISP


## When to Use

- When investigating security incidents that require analyzing threat landscape with misp
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques

## Prerequisites

- Familiarity with threat intelligence concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities

## Instructions

1. Install dependencies: `pip install pymisp`
2. Configure MISP URL and API key.
3. Run the agent to generate threat landscape analysis:
   - Pull event statistics by threat level and date range
   - Analyze attribute type distributions (IP, domain, hash, URL)
   - Identify top MITRE ATT&CK techniques from event tags
   - Track threat actor activity via galaxy clusters
   - Generate temporal trend analysis of IOC submissions

```bash
python scripts/agent.py --misp-url https://misp.local --api-key YOUR_KEY --days 90 --output landscape_report.json
```

## Examples

### Threat Landscape Summary
```
Period: Last 90 days
Events analyzed: 1,247
Top threat level: High (43%)
Top attribute type: ip-dst (31%), domain (22%), sha256 (18%)
Top MITRE technique: T1566 Phishing (89 events)
Top threat actor: APT28 (34 events)
```

Files in this skill

  • LICENSE11 KB
  • SKILL.md2.3 KB
  • references/api-reference.md1.7 KB
  • scripts/agent.py6.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…