Changelog
Synapse-MISP Changelog
v5.1.0 - 2025-10-10
Features and Enhancements
Added
--publishargument tomisp.event.addcommand to publish events on the MISP server. Events to be published can be new events as they are being exported or existing events specified by event ID.
v5.0.0 - 2025-07-10
Automatic Migrations
Migrated all existing server configurations to have a proxy server value of true which will use the Cortex proxy server settings.
Features and Enhancements
Updated the Power-Up to support proxy server settings in the server configurations.
Updated the
misp.setup.server.addandmisp.setup.server.updatedcommands to support adding/updating proxy server settings.
v4.0.0 - 2025-04-25
Automatic Migrations
Migrated and removed all
inet:web:acctnodes created by Synapse-MISP as identified by<(seen)-edges frommeta:source:type=synapse.mispormeta:source:type=synapse.misp.feedsource nodes. These nodes were migrated toinet:service:accountnodes.
Features and Enhancements
Updated Power-Up to make
inet:service:accountinstead of deprecatedinet:web:accountnodes.
Bugfixes
Fixed a bug where the
misp.synccommand would not use the default tag prefix when syncing events.
v3.13.0 - 2025-03-12
Features and Enhancements
Updated
misp.searchto populate theit:exec:query:optsproperty.
Automatic Migrations
Removed
:urland:url:fqdnproperties frommedia:newsnodes that were incorrectly created by themisp.feed.synccommand.
Bugfixes
Fixed a bug where the
misp.feed.synccommand would incorrectly create:urland:url:fqdnproperties onmedia:newsnodes.Fixed a bug where MISP “filename|md5”, “filename|sha1”, or “filename|sha256” types with invalid values may raise an exception and cause a sync to fail to complete.
Fixed an issue where the
it:exec:query:synuserproperty was not being populated formisp.searchcommand.Fixed an issue where
it:exec:querynodes from themisp.searchcommand were not unique per query.
v3.12.0 - 2025-03-10
Features and Enhancements
Added support for ingesting and file parsing MISP “malware-sample” attribute types.
v3.11.1 - 2025-02-19
Bugfixes
Fixed a bug where the
misp.synccommand wouldn’t download event attachments.
v3.11.0 - 2025-02-14
Features and Enhancements
Added
misp.searchcommand for searching events on configured MISP servers.
v3.10.0 - 2025-02-05
Automatic Migrations
Removed the
meta:source:_misp:feed:updatedandmeta:source:_misp:feed:sha256extended properties and moved the data tometa:source:ingest:latestandmeta:source:ingest:cursorrespectively.
Features and Enhancements
Added support for ingesting and file parsing MISP “attachment” attribute types.
Added
--no-fileparseroption tomisp.sync,misp.sync.byid, andmisp.feed.synccommands to prevent sending attachments to Synapse-FileParser.Updated ingest logic to use the
meta:source:ingest:latestandmeta:source:ingest:cursorextended properties for tracking the last time a MISP feed was updated.Added support for applying MISP tags to nodes created when ingesting MISP events and attributes.
Added
--tagprefoption tomisp.setup.server.addcommand to support tag prefixes when adding a MISP server configuration.Added
--tagprefand--del-tagprefoptions tomisp.setup.server.updatecommand to support modifying tag prefixes on configured MISP servers.Added
--tagprefoption tomisp.feed.synccommand to support tag prefixes when ingesting data from MISP feeds.
v3.9.0 - 2025-01-17
Features and Enhancements
Removed deprecated commands
misp.setup.server.rename,misp.setup.server.setglobal, andmisp.setup.server.setperm.
v3.8.0 - 2024-09-17
Features and Enhancements
Added
misp.feed.synccommand which adds ability to sync MISP feeds published via HTTP repository in MISP standardized format.
v3.7.1 - 2024-08-05
Bugfixes
Fix an issue where Event Add warning toast messages were not displayed properly.
v3.7.0 - 2024-06-28
Features and Enhancements
Updated typemap to include support for exporting
it:sec:cwenodes.
v3.6.0 - 2024-05-30
Features and Enhancements
Added
--sharing-group-idoption tomisp.event.addfor specifying the sharing group ID when distribution value is set to value four (“Sharing group.”).Added
--threat-level-idoption tomisp.event.addfor specifying the threat level ID of an exported event.
Bugfixes
Updated
--distributionoption to include value four (“Sharing group.”).
v3.5.0 - 2024-05-22
Features and Enhancements
Updated typemap to include support for exporting
risk:vulnnodes.Added
--distributionoption tomisp.event.addto support specifying the distribution value instead of defaulting to zero (“Your organization only.”).
v3.4.1 - 2024-02-20
Features and Enhancements
Update deprecated
$lib.dict()usage to JSON style syntax.
v3.4.0 - 2024-01-23
Features and Enhancements
Added a node action workflow for
misp.event.add.Added
--nameoption tomisp.event.addto set a custom event name.Added
--set-ids-flagoption tomisp.event.addto set the IDS flag on exported attributes.Added
--typemapoption tomisp.event.addso users can specify custom MISP types and categories when exporting data to a MISP server.Added
--print-typemapoption tomisp.event.addto print the default typemap to help users create custom typemaps.Added SSL verification boolean to the server configurations.
Added
misp.setup.server.updateto change the SSL verification behavior, rename, change the global flag, and set permissions on a server configuration.Updated
misp.setup.server.addto accept a--ssl-noverifyoption which will cause the server configuration being added to not perform SSL verification.Deprecated
misp.setup.server.setglobal,misp.setup.server.setperm, andmisp.setup.server.renamecommands in favor ofmisp.setup.server.update.
v3.3.0 - 2023-11-20
Features and Enhancements
Added
misp.event.addcommand to add nodes from Synapse to an event on a configured MISP server.
v3.2.0 - 2023-08-11
Features and Enhancements
Added support to filter events by reporting organizations.
v3.1.2 - 2023-08-07
Bugfixes
Fix misp.sync.byid to use
--serverrather than--serversand require only a single server argument.Check for IPv4 cidr/slash notation in
ip-srcandip-dstfields to prevent unbounded IPv4 address addition.
v3.1.1 - 2023-08-03
Bugfixes
Fix a bug where some filenames would cause an error during parsing.
v3.1.0 - 2023-07-28
Features and Enhancements
Added support for parsing MISP file objects.
Bugfixes
Fix a bug where whois registrar names were being incorrectly parsed as
tel:phoneinstead ofinet:whois:rar.
v3.0.1 - 2023-07-06
Bugfixes
Fix an issue where the boolean value for a server configuration’s
globalvalue would display as an integer rather than a boolean.Fix an issue where renaming a server configuration would not update the displayed name.
v3.0.0 - 2023-07-05
Features and Enhancements
Add support for syncing data from multiple MISP servers.
This release contains an automatic data migration that will run when the package is first upgraded. The migration moves any existing configuration data from global and user storage to the new configuration format in jsonstor.
v2.2.0 - 2023-03-14
Features and Enhancements
Rotate the readonly API key that is used to connect to the Vertex MISP instance. The existing API key will be revoked on March 31, 2023. Users should upgrade the
synapse-mispRapid Power-Up if they sync data from the Vertex MISP instance.
v2.1.0 - 2023-01-05
Features and Enhancements
Add MISP Threat Actor UUID to the
risk:threat:org:namesproperty.Set
risk:threat:nameif unset.
v2.0.0 - 2022-09-28
Features and Enhancements
Set the
media:news:typeproperty tomisp.event.Record the MISP Event URL to the
media:news:urlproperty.Record the MISP Event UUID to the
media:news:ext:idproperty.Record the MISP Event Orgc to the
media:news:publisherproperty.Improved identification and ingestion of GalaxyCluster entries.
Removed
--disable-nodedataoption from commands in favor of--save-rawconvention. Storing raw MISP event JSON data is now disabled by default.Link
hash:sha256to themedia:newsnode for typesha256attributes.
v1.3.0 - 2022-06-02
Features and Enhancements
Additionally ingest attributes on objects associated with MISP events.
Add
ou:nameandit:prod:softnamenodes for threat-actor and tool tags on events.Add
media:newsnodes for MISP Galaxy Clusters.
v1.2.0 - 2022-05-12
Features and Enhancements
Added –disable-nodedata option to
misp.syncandmisp.sync.byidto disable storing raw event results in nodedata.
v1.1.0 - 2022-02-11
Features and Enhancements
Added
misp.sync.byidcommand to pull in individual events by id.Save the raw MISP event to node data on the
media:newsnode using themisp:eventkey.
v1.0.2 - 2021-08-30
Bugfixes
Fix plumbing for –last option to misp.sync
v1.0.1 - 2021-08-20
Bugfixes
Added description to power-up definition
v1.0.0 - 2021-08-13
Features and Enhancements
Initial release of
Synapse-MISPv1.0.0