MISP threat feeds from Q-Feeds
MISP already correlates your events. Add Q-Feeds and it correlates them against curated malicious IPs, domains and URLs instead of free lists of unknown quality.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds and MISP integration?
MISP is built to correlate and share, but it only sees what you feed it. Q-Feeds adds one curated stream drawn from more than 2,500 commercial, OSINT and governmental sources and filtered for false positives, so your analysts spend their time on real overlaps instead of on noise.
Q-Feeds arrives through the feed system MISP already ships with. Point MISP at the complete malicious IP, domain and URL lists, set how often it should fetch them, and every event your team creates from then on is checked against curated intelligence without anyone going looking.
The feed route works on every licence, including the free Community edition, so you can measure how often Q-Feeds overlaps with your own events before you commit. The malicious URL list needs Premium. There is no module to install and no converter to write, only a feed definition and a schedule.
Keep the full lists current
Add Q-Feeds as a feed and MISP pulls the complete malicious IP, domain and URL lists on the schedule you set. Every event your team creates from then on is checked against them.
- Every new event correlated automatically
- Works on any licence, including Community
Or correlate without importing
If you would rather keep your instance lean, MISP can cache Q-Feeds and correlate against it without storing the indicators as events. You still see every overlap, your database stays the size it was.
- Overlap visible without growing your database
- Switch to a full import whenever you want
What we offer
Always ahead
Intelligence that updates every 20 minutes, so you are always ahead of the attackers.
Automatic response
Trust automated response actions and reduce the manual work needed to stop the latest threats.
Categories
Focus on what matters most, phishing, botnets, dark web and more crafted categories.
Knowledge
Knowledge is power when fighting threats. We take the knowledge part off your hands.
Easy implementation
You never did an implementation this easy. Follow our concise implementation guide and you are good to go.
Fewer false positives
We filter out false positives, so you never waste valuable resources chasing noise.
Add Q-Feeds to MISP in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and choose the lists that match your risk. Your feed details are waiting for you there.
Choose your lists
Take the malicious IP, domain and URL lists that match your risk. Each one is its own feed, so you can start with a single list and add the others later.
Add it to MISP
The feed uses functions MISP already ships with, so your administrator has Q-Feeds running in minutes without writing a converter.
Let correlation do the work
New indicators are matched against your events on their own, so overlaps between your incidents and live threat activity surface without anyone going looking.
Explore other TI platform integrations
Frequently asked questions about the MISP integration
What does Q-Feeds add to MISP?
Intelligence worth correlating against. Q-Feeds combines more than 2,500 commercial, OSINT and governmental sources into one prioritised stream, filtered for false positives and refreshed every 20 minutes.
Do we have to import everything into MISP?
No. You can let MISP import the indicators as attributes, or cache the feed and only correlate against it, which keeps your instance small. Both use the same feed definition, so you can change your mind later.
Which indicators do we get?
Malicious IP addresses, domains and URLs, each filtered for false positives before it reaches you and refreshed every 20 minutes.
Which licence do we need?
Any of them. The feed route is not gated behind Enterprise, so you can start on the free Community edition and measure the overlap with your own events before you commit. Community and Plus cover the IP and domain lists, and the malicious URL list is part of Premium.
Does this replace MISP?
No. MISP stays your platform for correlating and sharing; Q-Feeds is the intelligence you put into it. The MISP setup guide in our knowledge base covers the setup field by field.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access