$npx skillfedfor your agent

pymisp

Python API for MISP.

Worth itPyPI InternetReleased Aug 2026829.5K downloads / moBSD-2-ClausePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pymisp-2.5.34.2-py3-none-any.whl
v2.5.34.2 · released 2026-08-14 · Python <4.0,>=3.10 · 3 runtime deps: deprecated, python-dateutil, requests

Yes. PyMISP is actively maintained, has low install friction, carries no known vulnerabilities, and is the standard Python client for MISP platforms. Install it if you need to automate threat intelligence workflows or integrate MISP into a larger security system. The permissive BSD-2-Clause license poses no restriction.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a running MISP instance and valid API credentials; the MISP automation key must be obtained from the web interface's Automation section.
  • Low install friction with three core runtime dependencies (deprecated, python-dateutil, requests).
  • Active maintenance with a release on 2026-08-14 and recent commits.

License · maintenance · safety

BSD-2-Clause (permissive) — Distributed under BSD-2-Clause (permissive license), which allows commercial and private use with minimal restrictions—only requiring preservation of copyright and license notices.

last release 2026-08-14 (0 days) · last repo commit 2026-08-14 · 485 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 829,504 downloads/mo, #4,953 on PyPI

Verify before relying

pip3 install pymisp

from pymisp import PyMISP
misp = PyMISP('https://your-misp-instance.com', 'your-api-key')
events = misp.search(eventid=1)
  • Whether optional dependencies (fileobjects, virustotal, pdfexport, etc.) are required for specific use cases or truly optional.
  • Performance characteristics when working with large event datasets or high-frequency API calls.
  • Compatibility guarantees with specific MISP server versions.
Same gist for agents: .md · .json

What it is and what it does

PyMISP is a Python wrapper around the MISP REST API that lets you programmatically interact with MISP threat intelligence platforms. It abstracts away HTTP details so you can fetch events, add or update attributes, manage samples, and search for indicators using Python code instead of manual API calls. The library represents MISP objects (events, attributes, samples) as Python dictionaries through an AbstractMISP base class, making them easy to manipulate and serialize to JSON.

The package is designed for security teams, threat researchers, and automation engineers who need to integrate MISP data into workflows, build detection pipelines, or synchronize threat intelligence across systems. It has three core dependencies (deprecated, python-dateutil, requests) and optional extras for specialized tasks like PDF report generation, VirusTotal integration, and email object creation. The library is actively maintained, supports Python 3.10 through 3.14, and has been in development since 2015.

Use it for

  • Automate the ingestion of threat indicators from MISP into your detection or response platform.
  • Build scripts to bulk-create or update MISP events and attributes from external threat feeds.
  • Query MISP for indicators matching specific criteria and export them for use in firewalls or SIEMs.
  • Programmatically attach samples or malware hashes to MISP events as part of an incident response workflow.
  • Synchronize threat intelligence between multiple MISP instances or integrate MISP data into custom dashboards.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

PyMISP is actively maintained, has low install friction, carries no known vulnerabilities, and is the standard Python client for MISP platforms. Install it if you need to automate threat intelligence workflows or integrate MISP into a larger security system. The permissive BSD-2-Clause license poses no restriction.

Install

pymisp on PyPI

Before you install

Low install friction with three core runtime dependencies (deprecated, python-dateutil, requests). Active maintenance with a release on 2026-08-14 and recent commits. Supports modern Python versions (3.10–3.14).

Requires a running MISP instance and valid API credentials; the MISP automation key must be obtained from the web interface's Automation section.

License in practice

Distributed under BSD-2-Clause (permissive license), which allows commercial and private use with minimal restrictions—only requiring preservation of copyright and license notices.

Quickstart

pip3 install pymisp

from pymisp import PyMISP
misp = PyMISP('https://your-misp-instance.com', 'your-api-key')
events = misp.search(eventid=1)

Verify before relying

  • Whether optional dependencies (fileobjects, virustotal, pdfexport, etc.) are required for specific use cases or truly optional.
  • Performance characteristics when working with large event datasets or high-frequency API calls.
  • Compatibility guarantees with specific MISP server versions.

Package facts

LicenseBSD-2-Clause permissive
Python supportSupports the current Python release <4.0,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
deprecatedpython-dateutilrequests
MaintenanceActively maintained 0 days since the last release
Last repo commit
First released
Downloads829,504 / month, #4,953 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: Information TechnologyIntended Audience :: Science/ResearchIntended Audience :: Telecommunications IndustryOperating System :: POSIX :: LinuxProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: InternetTopic :: Security

Evidence: pymisp-2.5.34.2-py3-none-any.whl

Tags

Capabilities
MISP REST API clientthreat intelligence event managementfetch and update MISP eventsattribute search and creationmalware sample managementsecurity event automation
Topics
threat-intelligencemisp-integrationsecurity-automation

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “MISP REST API client”

  • pymispPyMISP is a Python library that connects to MISP platforms via their…
  • simple-rest-clientA lightweight HTTP client library for building REST API clients in…
  • agithubA lightweight REST API client with transparent Python syntax that…

Give your agent the search over MCP, or paste the wish link into any chat.

More Internet packages

botocore Worth it
PyPI · Internet · released Aug 2026

Botocore provides low-level, data-driven access to Amazon Web Services APIs, serving as the foundation for the AWS CLI and boto3 libraries.

Install it if you need programmatic access to AWS services.

permissive licensepure Python · 3.10+
1.5Bdownloads / mo
aiobotocore Worth it
PyPI · Internet · released Aug 2026

Provides an async client for AWS services using botocore and aiohttp, allowing you to call AWS APIs asynchronously within asyncio-based applications.

Install it if you need to call AWS services from async Python code; it is the standard way to do so.

Apache-2.0pure Python · 3.10+
1.2Bdownloads / mo
pydantic Worth it
PyPI · Python Modules · released May 2026

Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.

MITpure Python · 3.9+
1.1Bdownloads / mo
filelock Worth it
PyPI · Libraries · released Aug 2026

Provides a platform-independent file locking mechanism to coordinate access to files across processes and threads.

MITpure Python · 3.10+
717.1Mdownloads / mo
fastapi Worth it
PyPI · Software Development · released Jul 2026

FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.

MITpure Python · 3.10+
568.6Mdownloads / mo
googleapis-common-protos Worth it
PyPI · Internet · released Aug 2026

Provides common Protocol Buffer message definitions used across Google Cloud APIs, enabling Python clients to interact with Google services.

Apache-2.0pure Python · 3.10+
513.7Mdownloads / mo

See also simplisafe-python · imap-tools · vt-py · pdfid · pyisy · virustotal3 · OTXv2 · pyipp · cisco-ai-mcp-scanner · PyMySQL