The web app is split into practical working areas, from a live dashboard to complete publishing workflows for each product. Here is what each area covers.
A live program snapshot: active PIRs/GIRs, stakeholder counts, the latest analyser run and pending scraper events. A built-in reference panel covers the Admiralty Scale, TLP and CTI evaluation criteria.
Who consumes CTI output: role, organisation, contacts, TLP clearance, per-product subscription modes and notification channel preferences. Linked to PIRs and GIRs for ownership and delivery.
Full lifecycle editing with decision context, priority, status, scope, delivery settings and owner fields. Scope syncs with focus points and galaxy-backed categories from MISP.
Handled from first request to closure: SLA-aware due dates, owner assignment, links to PIR or GIR, response capture and feedback tracking.
A cached view of scraper and additional MISP servers. Browse events and reports, refresh the cache, flag follow-ups, create manual entries and generate LLM summary reports back into MISP.
Turn a security newsletter, such as the ETDA CTI robot briefing, into a reviewable list of articles grouped by section and criticality. Paste an edition by hand or let zsazsa poll a mailbox over IMAP. Selected links are handed to misp-scraper; the e-mail itself is archived as its own MISP event.
Manual drafting, review queue, approval and publishing. Seed drafts from source events, build observed-fact and indicator tables, and insert action presets with one click.
The same draft, review and publish flow, with multi-CVE input, CVE-focused fields, PIR linking, expandable source-event panels and action presets.
A triage queue from scraper events, guided story writing, a draft, edit and publish flow, and a notification when you publish.
A regular strategic product for leadership: top threats, trending threat actors, key incidents, recommendations and an outlook section, stored as MISP objects.
Build a PyMISP query against MISP and get the matching indicators back. Each feed has its own no-login URL for tools to pull from, and is delivered as a value list or CSV. Feeds can be linked to a threat actor profile.
Start from what the MISP galaxies hold about an actor, then expand it with your own investigation. Each profile builds a Diamond Model view across adversary, infrastructure, capability and victim, and can link to indicator feeds.
A searchable catalogue of published outputs tagged as CTI products. Filter by type and linked PIR, inspect event reports and store feedback.
Pipeline and program views that bring together source and outcome trends, RFI and feedback KPIs, PIR coverage and MISP source health, plus a CTI-CMM maturity metrics panel.

The dashboard gives a quick overview of the pipeline, active requirements, your stakeholders and recent processing results, so the team can see where things stand at the start of the day.

The data collection view gives a cached feed with filters for source, tags and context, so analysts can work through large numbers of events quickly, then start a new product directly from the events they select.

PIR pages capture the core intelligence questions that set collection and analysis priorities. Triage lets submitted PIRs be acknowledged, approved, deferred, rejected or merged, each with a clear note on the decision.

Stakeholders are managed locally and linked to MISP organisations. Each record supports internal or external roles, multiple contact fields, TLP clearance, product subscriptions and delivery preferences.

Statistics pages combine day-to-day statistics with CTI maturity metrics. The CTI-CMM panel reads from your live data across five areas: Program, Situation, Analytical production, Operational delivery and Feedback.

AI-assisted features help with triage, relevance checking and drafting. Each feature can use its own model and prompt, and because they send raw MISP content to the model, you review the output before publishing.

The RFI workflow runs from the first request through to closure, so one-off requests for intelligence are tracked just as carefully as your standing PIRs and GIRs.

Build a profile of an actor by pulling in what the MISP galaxies already hold as a first draft, then expanding it with your own knowledge and investigation.

Build a detailed query against MISP and get back the matching list of indicators, kept as a reusable PyMISP query you can copy and run elsewhere.
The README documents every area, configuration tab and the MISP data model in detail.