# MISP-mcp: Interact with MISP through natural language

**URL:** <https://discourse.ossbase.org/t/misp-mcp-interact-with-misp-through-natural-language/85>\
**Category:** hackathon.lu\
**Tags:** hackathon-2025\
**Created:** [April 9, 2025, 4:02pm UTC](https://discourse.ossbase.org/t/misp-mcp-interact-with-misp-through-natural-language/85 "2025-04-09T16:02:44Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![D4idalos](https://discourse.ossbase.org/user_avatar/discourse.ossbase.org/d4idalos/32/76_2.png) [@D4idalos](https://discourse.ossbase.org/u/D4idalos)\
**Post date:** [April 9, 2025, 4:02pm UTC](https://discourse.ossbase.org/t/misp-mcp-interact-with-misp-through-natural-language/85/1 "2025-04-09T16:02:44Z")

</div>

# MISP-mcp

## What is MCP?

The **Model Context Protocol (MCP)** is an open protocol designed to standardize how applications provide contextual information to large language models (LLMs). Much like how **USB-C** serves as a universal interface for connecting hardware devices, **MCP acts as a universal connector** between AI models and various data sources or tools. This standardization simplifies integration and enhances the adaptability and functionality of AI-powered applications.

### Why MCP?

MCP helps you build agents and complex workflows on top of LLMs. LLMs frequently need to integrate with data and tools, and MCP provides:

- A growing list of pre-built integrations that your LLM can directly plug into
- The flexibility to switch between LLM providers and vendors
- Best practices for securing your data within your infrastructure

### General architecture

At its core, MCP follows a client-server architecture where a host application can connect to multiple servers:

![image-20250409162936741](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409162936741.png?lastModify=1744213926)

- **MCP Hosts** : Programs like Claude Desktop, IDEs, or AI tools that want to access data through MCP
- **MCP Clients** : Protocol clients that maintain 1:1 connections with servers
- **MCP Servers** : Lightweight programs that each expose specific capabilities through the standardized Model Context Protocol
- **Local Data Sources** : Your computer’s files, databases, and services that MCP servers can securely access
- **Remote Services** : External systems available over the internet (e.g., through APIs) that MCP servers can connect to

## Get started

1. Clone the repository

git clone [GitHub - Eacus/misp-mcp: A Model Context Protocol server allows to interact with MISP](https://github.com/Eacus/misp-mcp.git)

1. Install [Claude Desktop](https://claude.ai/download)
2. Follow the guide [Connect to local MCP servers - Model Context Protocol](https://modelcontextprotocol.io/quickstart/user)
3. Add the following MCP configuration

{  
“mcpServers”: {  
“MISP-mcp”:{  
“command”: “uv”,  
“args”: [  
“–directory”,  
“\<path\_to\_repo\>/server/”,  
“run”,  
“server.py”  
]  
}  
}  
}

1. Restart Claude desktop

## Basic Usage

### Search Event by ID

#### Prompting with `misp-mcp`

> Can you give to me the MISP event with id 119?

![image-20250409160824466](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409160824466.png?lastModify=1744211291)

#### GUI

![image-20250409150858330](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409150858330.png?lastModify=1744211291)

#### PyMISP

​  
misp\_url = ‘[https://127.0.0.1:8443](https://127.0.0.1:8443)’  
misp\_key = ‘\<misp\_key\>’

# Should PyMISP verify the MISP certificate

misp\_verifycert = False  
r = misp.search(eventid=[119], metadata=True, pythonify=True)

### Create an event

#### Prompting with `misp-mcp`

> Create a new MISP event with the following parameters:
> 
> - Info: `This is my new MISP event`
> - Distribution: `0` (Your organization only)
> - Threat Level ID: `2` (Medium)
> - Analysis Level: `1` (Ongoing)

![image-20250409163209884](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409163209884.png?lastModify=1744209128)

#### GUI

![image-20250409150904842](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409150904842.png?lastModify=1744209128)

#### PyMISP

from pymisp import MISPEvent  
​  
event = MISPEvent()  
​  
event.info = ‘This is my new MISP event’ # Required  
event.distribution = 0 # Optional, defaults to MISP.default\_event\_distribution in MISP config  
event.threat\_level\_id = 2 # Optional, defaults to MISP.default\_event\_threat\_level in MISP config  
event.analysis = 1 # Optional, defaults to 0 (initial analysis)  
​  
print(event.to\_json())

## Administrative task

### Create an user

![image-20250409170428039](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409170428039.png?lastModify=1744211066)

![image-20250409170506173](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409170506173.png?lastModify=1744211104)

#### Prompting with `misp-mcp`

> Add a new user to the MISP instance using the following required fields:
> 
> - `email@email.com`: the email address associated with the account
> - `test_id`: the ID of the organization the user belongs to
> - `role_id`: the ID of the role assigned to the user

#### GUI

![image-20250409150913949](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409150913949.png?lastModify=1744211066)

#### PyMisp

from pymisp import ExpandedPyMISP, MISPUser  
from keys import misp\_url, misp\_key, misp\_verifycert  
import argparse  
​  
​  
misp = ExpandedPyMISP(misp\_url, misp\_key, misp\_verifycert, ‘json’)  
​  
user = MISPUser()  
user.email =   
user.org\_id = \<org\_id\>  
user.role\_id = \<role\_id\>  
​  
misp.add\_user(user, pythonify=True)

## Add AI Capabilities!

> Summarise all information about the MISP events that happened yesterday?

![image-20250409174228425](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409174228425.png?lastModify=1744213347)

> Generate a report written in Markdown based on the MISP event with id 114

![image-20250409172033250](file:///Users/luciano/Library/CloudStorage/OneDrive-Personal/Dottorato/projects/26-Hackaton.lu/PoC/imagemd/image-20250409172033250.png?lastModify=1744213293)

# MISP Event Report: Configuration and Security Posture Issues

​

## Event Details

​

- **Event ID:** 114
- **UUID:** 9d8c6821-0db5-4745-bb58-aac4f04eab78
- **Date:** 2025-03-25
- **Status:** Not Published
- **Threat Level:** 4
- **Distribution:** 1 (Organization)
- **Analysis Status:** 0 (Initial)  
​

## Organization Information

​

- **Organization:** ORG\_Main
- **Organization UUID:** 3094f85b-a22f-475b-a68f-ae77c233bb72
- **Event Creator:** user88@org-admin.main.test  
​

## Description

​  
This event focuses on “Configuration and Security Posture Issues.” It appears to be in an initial stage of analysis and has not yet been published within the MISP instance.  
​

## Attributes

​  
No attributes have been added to this event yet.  
​

## Objects

​  
No objects have been associated with this event.  
​

## Related Events

​  
No related events have been linked to this event.  
​

## Galaxies

​  
No galaxies have been associated with this event.  
​

## Summary

​  
This MISP event (ID: 114) is currently in development and focuses on configuration and security posture issues. The event has been created but does not yet contain any attributes, objects, or relationships with other events. The event is set to be shared only within the organization (ORG\_Main).  
​

## Recommendations

​

1. Add relevant attributes to provide context about the specific configuration and security posture issues being addressed
2. Consider adding objects to structure the information more effectively
3. Link to related events if applicable
4. Determine appropriate galaxies to categorize the threat information
5. Review the threat level assignment to ensure it accurately reflects the severity
6. Consider publishing the event when it contains sufficient information  
​

* * *

​  
_Report generated on April 9, 2025_
