Maltego Adds MISP Threat-Intel Integration
Maltego published a how-to guide showing analysts how to pivot MISP threat-sharing data and MITRE ATT&CK entities directly inside Maltego Graph.
This is a vendor product blog from Maltego describing a new integration workflow that lets analysts query MISP instances, MITRE ATT&CK data, and MISP Galaxies directly from within the Maltego Graph interface. The piece walks through a demonstration investigation starting from a suspicious email address flagged by a spam trap, showing how an analyst can pivot from an indicator to a MISP event, its attributes/objects, associated tags, and MITRE ATT&CK techniques, ultimately surfacing threat actors and malware families associated with a given attack pattern.
The demonstration references a COVID-19-themed spear-phishing fraud campaign recorded in a MISP event, and uses the MITRE ATT&CK technique 'Spearphishing via Service' as a pivot point to show which threat actors (FIN6, Dark Caracal, OilRig, Magic Hound) have historically used that technique, and which malware/tools (FinFisher, Bandook, CrossRAT, Pallas) are associated with Dark Caracal. These are illustrative examples used to showcase the tool's enrichment and pivoting capabilities rather than new threat findings.
Overall this content is informational and instructional in nature — it does not report new malicious activity, a new campaign, or newly discovered indicators. It is intended to help CTI analysts improve investigative workflows by combining MISP threat-sharing data with Maltego's visualization and OSINT capabilities.
Mentioned in this report
Source reporting: https://www.misp-project.org/2024/07/16/maltego_integration_with_misp.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free