misp_add_sighting
Report sightings of threat indicators in MISP to confirm observations, mark false positives, or set expiration dates for threat intelligence accuracy.
Instructions
Report a sighting of an IOC (confirms it was observed in the wild, marks as false positive, or sets expiration)
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| attributeId | No | Attribute ID to sight (use this or value) | |
| value | No | Attribute value to sight (use this or attributeId) | |
| type | Yes | 0=Sighting (seen in the wild), 1=False positive, 2=Expiration | |
| source | No | Source of the sighting (e.g., organization name, sensor ID) | |
| timestamp | No | Timestamp of the sighting (Unix timestamp) |