Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

MISP

Open-source threat intelligence and sharing platform, with an official test VM

specializedbased on UbuntuBlue Team

MISP has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗Download ↗Source repo ↗

Last verified September 5, 2026

MISP is a platform for collecting, correlating, and sharing threat intelligence between organizations and communities, rather than a tool bundle for running attacks. It’s included here because its official downloadable test VM gives it the same “boot it and try it” on-ramp as the pentest/forensics distros in this catalog, even though its actual use case is defensive intelligence sharing.

Use it only in environments you own or are explicitly authorized to operate in — see the disclaimer.

Getting started

MISP publishes a VirtualBox/VMware VM image, rebuilt automatically from every commit to its core repository, as the fastest way to try it — the project's own documentation is explicit that this image is for evaluation only, not production use. For a real deployment, MISP documents dedicated installers for Ubuntu, plus Docker-based options. Either way you land on the same web UI for creating, correlating, and sharing structured threat-intelligence events (IOCs, TTPs, galaxies) with other MISP instances or feeds.