MISP 2.4.153 adds STIX, taxonomy updates
MISP 2.4.153 release adds new taxonomies, threat-actor galaxy entries, module updates, and a Markdown-IT security fix.
This is a routine release announcement for the MISP threat intelligence platform, version 2.4.153. The update focuses on usability and interoperability improvements rather than addressing any active threat: it adds Thai UI translation, improves STIX import/export support via the misp-stix library, enhances synchronisation debugging, and updates the bundled Markdown-IT library to version 12.3.2 to incorporate upstream security fixes.
Of note to intelligence analysts, the release expands MISP's taxonomy and galaxy content, including a new State responsibility taxonomy, an improved Workflow and runtime-packers taxonomy, and a new Unified Kill Chain taxonomy. The threat-actor galaxy was updated with new entries such as SideCopy and Aquatic Panda, and a new surveillance-vendor group entry for Cytrox was added, reflecting ongoing community tracking of these entities rather than new research findings from MISP itself. Module updates include a new VirusTotal collection export, an improved CrowdStrike Falcon expansion module, an updated Censys enrichment module for its new API, and a new MWDB push module for malware samples.
Mentioned in this report
Source reporting: https://www.misp-project.org/2022/02/04/misp.2.4.153.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free