Skip to content
THE HUNTER’S LEDGER
MISP Feed
Subscribe as a MISP feed
Every published campaign as one MISP event: the indicators from its STIX bundle, the Suricata, YARA and Sigma rules from its detection page, the CVEs it names, ATT&CK galaxy tags, and links back to the report. Static files in the MISP feed format, so MISP pulls it on its own schedule and OpenCTI reads it through its MISP feed connector, with no MISP instance in between. Free under CC BY 4.0.
Feed URL https://the-hunters-ledger.com/feeds/misp/

Add it to MISP

In MISP open Sync Actions, List Feeds, Add Feed and fill in:

Field Value
Name The Hunters Ledger
Provider The Hunters Ledger
Input source Network
URL https://the-hunters-ledger.com/feeds/misp/
Source format MISP feed
Enabled yes

Then Fetch and store all feed data once, and MISP keeps it current on its own schedule. Every event carries a stable UUID, so a re-pull updates an event in place rather than duplicating it, and an event’s timestamp only moves when its content changes. The feed also ships hashes.csv, so a MISP instance can correlate its own data against this feed without storing the events at all.

Add it to OpenCTI

Deploy the connector-misp-feed external-import connector with MISP_FEED_URL set to https://the-hunters-ledger.com/feeds/misp/. It reads the same manifest.json and event files and needs no MISP instance. If you already run MISP in front of OpenCTI, add the feed to MISP instead and let your existing MISP connector carry it across.

Anything else

The files are plain JSON: manifest.json lists every event with its UUID, title, date, tags and timestamp, and each <uuid>.json holds one event with its attributes. Poll the manifest, compare timestamps to what you hold, and fetch the events that moved. The STIX side of the site has the same arrangement at /stix/manifest.json.

What an event carries

Everything in an event is already published on this site; the feed adds no claim of its own. Withdrawn events are itemised on the changelog, where a UUID is never reused.

Generated from the published STIX bundles and detection pages by tools/report-tooling/generate-misp-feed.js, validated with PyMISP before every deploy. CC BY 4.0: use it, including commercially, with attribution to The Hunters Ledger.