# MISP details JTAN threat-sharing framework

Published: 2024-07-01 · Severity: low · Sectors: government-national
Canonical: https://vorant.io/reports/03122cfa-c045-5e74-95d0-67672686972e/misp-details-jtan-threat-sharing-framework

> The EU-funded JTAN project outlines MISP-based tooling and techniques for CSIRTs to share threat intelligence more efficiently across Europe.

This article is an informational writeup from the MISP Project describing outcomes of the JTAN (Joint Threat Analysis Network) initiative, co-funded by the European Union's CEF program. It is not a threat report but a technical/process overview of data-sharing mechanisms tested for CSIRT and SOC networks, including MISP synchronization, MISP caching, MISP's REST API, real-time streaming via CocktailParty and N6, and privacy-preserving techniques using PSS (peer-to-peer search) and Bloom Filters.

The goal of JTAN is to improve interoperability and situational awareness among European national CSIRTs by strengthening and interconnecting existing CTI tooling, rather than introducing new detection capabilities or responding to a specific threat. The document serves as a reference for organizations seeking to build or improve threat intelligence sharing infrastructure using open-source tools compatible with the MISP standard.

There is no indication of active exploitation, malware, threat actors, or vulnerabilities in this piece — it is purely a project/process report on tooling and collaboration frameworks for the CSIRT community.

## Mentioned in this report

- Campaigns: JTAN (Joint Threat Analysis Network)

Source reporting: https://www.misp-project.org/2024/07/01/jtan-project-experience.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/03122cfa-c045-5e74-95d0-67672686972e/misp-details-jtan-threat-sharing-framework.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
