Add it to MISP
In MISP open Sync Actions, List Feeds, Add Feed and fill in:
| Field | Value |
|---|---|
| Name | The Hunters Ledger |
| Provider | The Hunters Ledger |
| Input source | Network |
| URL | https://the-hunters-ledger.com/feeds/misp/ |
| Source format | MISP feed |
| Enabled | yes |
Then Fetch and store all feed data once, and MISP keeps it current on its own schedule. Every event carries a stable UUID, so a re-pull updates an event in place rather than duplicating it, and an event’s timestamp only moves when its content changes. The feed also ships hashes.csv, so a MISP instance can correlate its own data against this feed without storing the events at all.
Add it to OpenCTI
Deploy the connector-misp-feed external-import connector with MISP_FEED_URL set to https://the-hunters-ledger.com/feeds/misp/. It reads the same manifest.json and event files and needs no MISP instance. If you already run MISP in front of OpenCTI, add the feed to MISP instead and let your existing MISP connector carry it across.
Anything else
The files are plain JSON: manifest.json lists every event with its UUID, title, date, tags and timestamp, and each <uuid>.json holds one event with its attributes. Poll the manifest, compare timestamps to what you hold, and fetch the events that moved. The STIX side of the site has the same arrangement at /stix/manifest.json.
What an event carries
- Indicators from the campaign’s STIX bundle, typed as
sha256,domain,urlorip-dst, each with the report’s own confidence in the comment. An indicator the report scores below 60 ships withto_idsoff: it is context, not a blocklist entry. A value the bundle carries only as an observable (a mining pool, a co-tenant domain, anything the IOC feed marks do-not-block) is not in the event at all. - Rules from the campaign’s detection page as
yara,sigmaandsnortattributes, the full rule text, with its tier, robustness, confidence, ATT&CK techniques and rule hash in the comment and ahunters-ledger:tiertag. A Detection-tier rule ships withto_idson; a Hunting-tier rule is broad by design and ships withto_idsoff, so it reaches your hunt queue rather than your alert queue. - CVEs the report names, as
vulnerabilityattributes. - Links to the report, the detection page, the STIX bundle and the IOC feed.
- Tags:
tlp:clear,misp-galaxy:mitre-attack-patternfor every technique the campaign maps,hunters-ledger:topicfor the catalog tags, andhunters-ledger:actorfor a tracked UTA designation.
Everything in an event is already published on this site; the feed adds no claim of its own. Withdrawn events are itemised on the changelog, where a UUID is never reused.
Generated from the published STIX bundles and detection pages by tools/report-tooling/generate-misp-feed.js, validated with PyMISP before every deploy. CC BY 4.0: use it, including commercially, with attribution to The Hunters Ledger.