Skip to main content

MISP Threat Actors

Download With Dependencies

This pack downloads and parses the MISP threat actor galaxy into XSOAR TIM.

MISP Threat Actors Feed

This pack provides a feed integration for ingesting threat actor data from the MISP Threat Actors Galaxy.

About This Pack

The MISP Threat Actors Feed pack allows you to ingest threat actor data from the MISP Threat Actors Galaxy, providing valuable threat intelligence to enhance your security operations. This feed includes detailed information about known threat actors, their aliases, associated countries, and descriptions.

What does this pack do?

  • Fetches threat actor data from the MISP Threat Actors Galaxy.
  • Creates indicators for each threat actor with rich metadata.
  • Establishes relationships between threat actors and their targets or attributed locations.
  • Supports custom tagging and TLP color assignment.
  • Provides command for manual retrieval of threat actor information.

Pack Contents

Integrations

FeedMISPThreatActors: The main integration for fetching and processing threat actor data.

Use Cases

  • Enhance threat intelligence by incorporating known threat actor information.
  • Identify potential threats based on actor profiles and their historical activities.
  • Correlate internal incidents with known threat actor behaviors.

Pack Contributors:


  • Timothy Roberts

Contributions are welcome and appreciated. For more info, visit our Contribution Guide.

MISP Threat Actors Feed

This pack provides a feed integration for ingesting threat actor data from the MISP Threat Actors Galaxy.

About This Pack

The MISP Threat Actors Feed pack allows you to ingest threat actor data from the MISP Threat Actors Galaxy, providing valuable threat intelligence to enhance your security operations. This feed includes detailed information about known threat actors, their aliases, associated countries, and descriptions.

What does this pack do?

  • Fetches threat actor data from the MISP Threat Actors Galaxy.
  • Creates indicators for each threat actor with rich metadata.
  • Establishes relationships between threat actors and their targets or attributed locations.
  • Supports custom tagging and TLP color assignment.
  • Provides command for manual retrieval of threat actor information.

Pack Contents

Integrations

FeedMISPThreatActors: The main integration for fetching and processing threat actor data.

Use Cases

  • Enhance threat intelligence by incorporating known threat actor information.
  • Identify potential threats based on actor profiles and their historical activities.
  • Correlate internal incidents with known threat actor behaviors.

Pack Contributors:


  • Timothy Roberts

Contributions are welcome and appreciated. For more info, visit our Contribution Guide.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedJanuary 23, 2025
Last ReleaseMarch 22, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
By downloading or using Marketplace content, you agree to the applicable Terms of Use and End User License Agreement. Third-party content is provided by its publisher, and Palo Alto Networks does not warrant, endorse, support, or assume responsibility for content not expressly identified as owned by Palo Alto Networks.