MG

MISP Galaxy Threat Actor Explorer

Pivotick graph · browser-only application
Pivotick: not loaded MISP Galaxy: no local cache

Local-first galaxy exploration

When started with ./start-standalone.sh, the application loads Pivotick and MISP Galaxy directly from the bundled git submodules. Alternatively, download the latest releases or import local files. Indexed data remains in this browser’s IndexedDB for offline reuse.

No web server, backend, account, or API token is required. Open this HTML file directly in a recent Firefox, Chromium, or Edge browser.

Loading
Local data and exports

Update and import

Export

Cache

Reading cache…
GitHub data is treated as untrusted input. The application escapes metadata before inserting it into the page, and only opens HTTP(S) references. Imported files remain inside this browser profile.
Threat-actor name producers

Filter the names displayed on threat-actor graph nodes using meta.name-attribution. Producer UUIDs are resolved through the MISP producer galaxy. “All” preserves the complete set of names.

Load MISP Galaxy data to discover name producers.

All producers
Metadata graph fields

Selected metadata fields become reusable graph nodes. Double-click a metadata node, or use a Pivot button in the inspector, to reveal every galaxy value sharing it.

Load MISP Galaxy data to discover metadata fields.

No fields selected