misp-warninglists provides curated lists of known benign or false-positive indicators to enhance MISP's threat intelligence accuracy by filtering and warning users.
Warning lists to inform users of MISP about potential false-positives or other information in indicators
This tool is primarily used by threat intelligence analysts and incident responders leveraging MISP to reduce false positives by identifying well-known benign indicators such as popular IP ranges, domains, and hashes. It helps organizations improve detection quality by integrating these warning lists into their MISP events and API workflows for automated filtering and alerting.
The warning lists are designed to be optionally enabled or disabled based on organizational policies. They are reused in multiple open source projects beyond MISP, emphasizing their broad applicability. Since this repository mainly provides datasets, installation or command usage is handled within the MISP platform rather than standalone.