VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.153 adds STIX, taxonomy updates

low threat

MISP 2.4.153 release adds new taxonomies, threat-actor galaxy entries, module updates, and a Markdown-IT security fix.

This is a routine release announcement for the MISP threat intelligence platform, version 2.4.153. The update focuses on usability and interoperability improvements rather than addressing any active threat: it adds Thai UI translation, improves STIX import/export support via the misp-stix library, enhances synchronisation debugging, and updates the bundled Markdown-IT library to version 12.3.2 to incorporate upstream security fixes.

Of note to intelligence analysts, the release expands MISP's taxonomy and galaxy content, including a new State responsibility taxonomy, an improved Workflow and runtime-packers taxonomy, and a new Unified Kill Chain taxonomy. The threat-actor galaxy was updated with new entries such as SideCopy and Aquatic Panda, and a new surveillance-vendor group entry for Cytrox was added, reflecting ongoing community tracking of these entities rather than new research findings from MISP itself. Module updates include a new VirusTotal collection export, an improved CrowdStrike Falcon expansion module, an updated Censys enrichment module for its new API, and a new MWDB push module for malware samples.

Mentioned in this report

Threat actors Aquatic PandaSideCopy

Source reporting: https://www.misp-project.org/2022/02/04/misp.2.4.153.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free