Skip to main content

Overview

The MISP connector searches attributes, retrieves events, creates events, adds attributes, and records sightings from CaseBender.

Configure

1

Create an automation key

Create a dedicated MISP automation user with permissions limited to the organizations, sharing groups, and distribution levels you require.
2

Store the credential

In Settings → Integrations, select Add integration, choose MISP, enter the instance URL and API key, and add the MISP hostname to the allowed-host list.
3

Create and test a connection

Bind the credential to the MISP URL and verify the server version can be retrieved.

Available actions

  • Search attributes and retrieve events
  • Create events and attributes
  • Add sightings
Align MISP distribution and TLP values with your organization’s sharing policy before publishing indicators.