
Clusters and elements to attach to MISP events or attributes (like threat actors)

MISP galaxy is a simple method to express a large object called cluster that can be attached to MISP events or attributes. A cluster can be composed of one or more elements. Elements are expressed as key-values. There are default knowledge base (such as Threat Actors, Tools, Ransomware, ATT&CK matrixes) available in MISP galaxy but those can be overwritten, replaced, updated, forked and shared as you wish.
Existing clusters and vocabularies can be used as-is or as a common knowledge base. MISP distribution can be applied to each cluster to permit a limited or broader distribution scheme.
Galaxies can be also used to expressed existing matrix-like standards such as MITRE ATT&CK(tm) or custom ones.
The objective is to have a comment set of clusters for organizations starting analysis but that can be expanded to localized information (which is not shared) or additional information (that can be shared).
360.net Threat Actors - Known or estimated adversary groups as identified by 360.net.
Category: actor - source: https://apt.360.net/aptlist - total: 42 elements
Agent Threat Rules - Open detection rules for AI agent threats — prompt injection, tool poisoning, MCP server attacks, skill compromise. Each cluster value is one ATR rule with category, severity, and CVE/OWASP/MITRE ATLAS references where mapped.
Category: agent-threat-rules - source: https://github.com/Agent-Threat-Rule/agent-threat-rules - total: 713 elements
Ammunitions - Common ammunitions galaxy
Category: firearm - source: https://ammo.com/ - total: 409 elements
Android - Android malware galaxy based on multiple open sources.
Category: tool - source: Open Sources - total: 450 elements
Azure Threat Research Matrix - The purpose of the Azure Threat Research Matrix (ATRM) is to educate readers on the potential of Azure-based tactics, techniques, and procedures (TTPs). It is not to teach how to weaponize or specifically abuse them. For this reason, some specific commands will be obfuscated or parts will be omitted to prevent abuse.
Category: atrm - source: https://github.com/microsoft/Azure-Threat-Research-Matrix - total: 90 elements
attck4fraud - attck4fraud - Principles of MITRE ATT&CK in the fraud domain
Category: guidelines - source: Open Sources - total: 71 elements
Backdoor - A list of backdoor malware.
Category: tool - source: Open Sources - total: 29 elements
Banker - A list of banker malware.
Category: tool - source: Open Sources - total: 53 elements
Bhadra Framework - Bhadra Threat Modeling Framework
Category: mobile - source: https://arxiv.org/pdf/2005.05110.pdf - total: 47 elements
Busy is the New Stupid framework - Busy is the New Stupid framework - A tactical framework, examining how busyness compromises cognitive function, strategic thinking, and effectiveness. Created by Ross Young.
Category: user-tie - source: https://www.cisotradecraft.com/bitns - total: 40 elements
Botnet - Botnet galaxy.
Category: tool - source: MISP Project - total: 148 elements
Branded Vulnerability - List of known vulnerabilities and attacks with a branding
Category: vulnerability - source: Open Sources - total: 14 elements
Cert EU GovSector - Cert EU GovSector
Category: sector - source: CERT-EU - total: 6 elements
China Defence Universities Tracker - The China Defence Universities Tracker is a database of Chinese institutions engaged in military or security-related science and technology research. It was created by ASPI’s International Cyber Policy Centre.
Category: academic-institution - source: ASPI International Cyber Policy Centre - total: 159 elements
Concealment Layers for Online Anonymity and Knowledge (CLOAK) - Concealment Layers for Online Anonymity and Knowledge (CLOAK) is a knowledge base of cybercriminal concealment measures inspired by MITRE ATT&CK. This matrix-like galaxy organises concealment practices across technical, behavioural, and physical layers to support investigation, common referencing, gap analysis, and defensive planning. The source project describes CLOAK as derived from qualitative research over more than 200 OpSec guides and its initial public version as containing 13 tactics, 109 techniques, 679 sub-techniques, and 586 procedures.
Category: concealment - source: https://github.com/Mickinthemiddle/CLOAK - total: 13 elements