The Malpedia to MISP ingestor gathers data from various sources to catalog malware and store the data in a MISP instance you provide. The project:
- Downloads:
- The Malpedia malware corpus
- The Malpedia Client
- The Malpedia threat actor and malware family metadata
- MITRE CTI Attack Matrix
- MISP Galaxies
- Builds an incident tree in MISP:
- Threat Actor => Malware Family => Version => Specimen
- Creates tags that identify various aspects of each of the tiers of the tree including but not limited to:
- Country
- Types of Incidents
- Synonyms
- Associates all known MITRE ATT&CK Matrix codes