Skip to content

Building ThreatOps-CTI and an Operational MISP Program

CTI program lead and engineer · 2025

I built the CTI process, SOPs and automation that connected collection with MISP, hunting, detection and incident response.

Context

Relevant intelligence included threats connected to the organization, region, industry, vendors and technology stack, plus applicable vulnerabilities.

Problem

Analysts were spending time reviewing many RSS feeds and reports manually, while useful intelligence reached operational teams too slowly and inconsistently.

Approach

Use GitHub workflows and Python to collect and filter sources, then normalize and enrich selected material for structured review and MISP publication.

Intelligence workflow

IOC, CVE & RSS collectionRelevance filteringAnalyst reviewMISP & GalaxyHunting & detections

SOC feedback returns to analyst review.

Implementation

  • Created relevance filters for organizational, regional, sector, vendor and technology context.
  • Normalized IOCs, vulnerabilities, TTPs, tags and galaxy relationships.
  • Sent operational indicators through MISP to SIEM so the SOC could alert and hunt.
  • Used the resulting knowledge base for campaign analysis and detection content.

Decisions

Filter before enrichment

Relevance reduces analyst noise and preserves attention for actionable intelligence.

Filtering logic needs regular review as priorities change.

Keep MISP as the operational system of record

Structured events, taxonomies and galaxies preserve context across consumers.

Good MISP hygiene remains an operational responsibility.

Outcome

Analysts no longer had to read the same feeds manually. The useful intelligence reached MISP and could be used for campaign analysis, hunting, detection and SOC alerts.

Platforms & methods

MISP · Python · GitHub Actions · n8n · RSS · SIEM · MITRE ATT&CK