Maltego Adds MISP Threat Intel Integration
Maltego released a tutorial on integrating MISP threat-sharing data via MITRE ATT&CK transforms for OSINT investigations.
This is a vendor blog post from Maltego describing how its graph-based investigation platform integrates with MISP (Malware Information Sharing Platform) threat intelligence instances through dedicated transforms. The piece is a product demonstration rather than a threat report, walking through a workflow where an analyst pivots from a suspicious email address to a MISP event, its attributes/objects, tags, and related MITRE ATT&CK patterns.
The demonstration uses a real example event (ID 1241) tied to a COVID-19-themed fraud/spear-phishing campaign, tracing an email indicator through MISP attributes, IP/URL/domain objects, and a VirusTotal reference, then mapping it to the Spearphishing via Service (T1194) ATT&CK technique. The article notes that threat actors FIN6, Dark Caracal, OilRig, and Magic Hound have historically used this technique per MISP galaxy data, and separately illustrates that Dark Caracal is associated with FinFisher, Bandook, CrossRAT, and Pallas malware — these are cited as illustrative examples of MISP galaxy pivoting rather than new findings.
Overall, the content is educational/informational, aimed at improving analyst workflow efficiency rather than reporting a new campaign, vulnerability, or active threat. No new IOCs, exploits, or victim organizations are disclosed beyond the single demonstration email address.
Mentioned in this report
Source reporting: https://www.misp-project.org/2024/07/16/maltego_integration_with_misp.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free