Building ThreatOps-CTI and an Operational MISP Program
CTI program lead and engineer · 2025
I built the CTI process, SOPs and automation that connected collection with MISP, hunting, detection and incident response.
Context
Relevant intelligence included threats connected to the organization, region, industry, vendors and technology stack, plus applicable vulnerabilities.
Problem
Analysts were spending time reviewing many RSS feeds and reports manually, while useful intelligence reached operational teams too slowly and inconsistently.
Approach
Use GitHub workflows and Python to collect and filter sources, then normalize and enrich selected material for structured review and MISP publication.
Intelligence workflow
SOC feedback returns to analyst review.
Implementation
- Created relevance filters for organizational, regional, sector, vendor and technology context.
- Normalized IOCs, vulnerabilities, TTPs, tags and galaxy relationships.
- Sent operational indicators through MISP to SIEM so the SOC could alert and hunt.
- Used the resulting knowledge base for campaign analysis and detection content.
Decisions
Filter before enrichment
Relevance reduces analyst noise and preserves attention for actionable intelligence.
Filtering logic needs regular review as priorities change.
Keep MISP as the operational system of record
Structured events, taxonomies and galaxies preserve context across consumers.
Good MISP hygiene remains an operational responsibility.
Outcome
Analysts no longer had to read the same feeds manually. The useful intelligence reached MISP and could be used for campaign analysis, hunting, detection and SOC alerts.
Platforms & methods
MISP · Python · GitHub Actions · n8n · RSS · SIEM · MITRE ATT&CK