Hack.lu 2026

MISP Workbench: Hands-on threat intel platform workshop

A hands-on workshop introducing MISP Workbench, a modern threat intelligence platform built for MISP compatibility. Participants will explore its self-contained architecture for ingesting, correlating, and analysing threat data — no full MISP instance required.


This workshop introduces MISP Workbench, a modern, self-contained threat intelligence platform built for MISP compatibility — designed for analysts and engineers who want the power of MISP's data model without the overhead of a full MISP deployment.

Participants will get hands-on experience with the platform's core capabilities:

Feed Ingestion & Correlation — Learn how to ingest threat intelligence from MISP, CSV, JSON, and freetext feeds on a schedule or on demand. Explore how batch and incremental correlation scans surface relationships across indexed attributes automatically.

Explore & Hunt — Use Lucene queries against OpenSearch to perform fast indicator lookups, and set up Hunts — saved searches that run periodically and trigger alerts when matches are found.

Enrichment — Enrich indicators of compromise directly from the platform using misp-modules, and manage batch imports to rapidly add lists of indicators to events in a single operation.

Automation & Scripting (Tech Lab) — Write Reactor Scripts: user-defined Python scripts that react to platform events and execute in an isolated sandbox. Combine them with Analyst Notebooks — pre-loaded with the mwlab SDK — for ad-hoc exploration of events, attributes, correlations, and enrichments.

AI Integration via MCP — Query your threat intelligence conversationally through the built-in Model Context Protocol server, compatible with Claude, Cursor, and other AI assistants.

Notifications & Retention — Configure event-driven notifications processed by Celery workers, and define retention policies to automatically purge expired events.

Dashboards and API — Dive into OpenSearch dashboards, ingest pipelines, and the FastAPI-backed REST API.

Whether you're building a lightweight threat intel stack or extending an existing MISP ecosystem, this workshop gives you a practical foundation to get MISP Workbench running and tailored to your workflows.

Luciano Righetti

Software engineer driven by a genuine passion for cybersecurity. Over the past four years, I contributed as a MISP core developer at the Computer Incident Response Center of Luxembourg CIRCL) and building tools such as network scanners and other projects that help CIRCL mission on keeping Luxembourg ecosystem safe.