Skip to main content
Glama

misp_add_sighting

Report sightings of threat indicators in MISP to confirm observations, mark false positives, or set expiration dates for threat intelligence accuracy.

Instructions

Report a sighting of an IOC (confirms it was observed in the wild, marks as false positive, or sets expiration)

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
attributeIdNoAttribute ID to sight (use this or value)
valueNoAttribute value to sight (use this or attributeId)
typeYes0=Sighting (seen in the wild), 1=False positive, 2=Expiration
sourceNoSource of the sighting (e.g., organization name, sensor ID)
timestampNoTimestamp of the sighting (Unix timestamp)

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/solomonneas/misp-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server