An independent European tool index

Find your response tools.

European tools for CSIRT work, with the sources behind every listing.

The index / geographyA spread across Europe15
CSIRT / institutionEU developer

8 more countries in the filters. Country identifies the recorded project lead or developer. How we check origin

Browse by workflow.

97 profiles with reviewed primary sources. Filter, inspect, and build your shortlist.

Workflow
Funding, capabilities & integrations Filter by documented evidence

Only explicit, sourced matches appear. Missing tags mean support or funding has not been established in this pass. Inspect supported features · Explore EU-funded tools

97 tools in view

Threat intelligenceEU-developed

IntelFusions

Public threat-intelligence research platform linking adversary profiles, malware, incident claims, detection-rule references and contextual briefings for analyst investigation.

RO RomaniaFree servicePublic service
View profile

Threat intelligenceCSIRT-led

MISP

Collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools.

LU LuxembourgOpen sourceSelf-hosted
View profile

Feed automationCSIRT-led

IntelMQ

Collects and processes security feeds through message-queued bots to automate incident handling, notifications and exchange with other systems.

AT AustriaOpen sourceSelf-hosted
View profile

Feed automationCSIRT-led

n6

Collects, manages and distributes security incident and threat feeds to authorized users through a REST API and web interface.

PL PolandOpen sourceSelf-hosted
View profile

Exposure discoveryCSIRT-led

Artemis

Scans websites for security issues through modular checks and generates readable notices for administrators from the resulting findings.

PL PolandOpen sourceSelf-hostedBeta / experimental
View profile

Threat intelligenceCSIRT-led

Taranis NG

Collects open-source intelligence, supports analyst reporting and controlled team collaboration, and publishes outputs from a self-hosted Docker deployment.

SK SlovakiaOpen sourceSelf-hosted
View profile

Malware analysisCSIRT-led

MWDB Core

Stores malware samples and extracted configurations, letting analysts search relationships, share collections and integrate through its REST API.

PL PolandOpen sourceSelf-hosted
View profile

Threat intelligenceEU-developed

OpenCTI

Threat intelligence platform that structures observables and context with STIX 2, links assertions to sources, and exchanges data through APIs and connectors.

FR FranceOpen coreSelf-hosted / SaaS
View profile

Response coordinationEU-developed

TheHive

Incident response platform for triaging alerts, opening cases, coordinating investigation tasks, and analyzing observables through connected Cortex services.

FR FranceCommercialSelf-hosted / SaaS
View profile

Detection and monitoringEU-developed

Guardsix SIEM

Security information and event management product that correlates logs from hybrid infrastructure and provides detections, investigation context, and audit evidence.

DK DenmarkCommercialSelf-hosted
View profile

Detection and monitoringEU-developed

Bitdefender GravityZone XDR

Extended detection and response product that correlates endpoint, identity, network, and cloud signals to investigate incidents and coordinate response actions.

RO RomaniaCommercialSaaS
View profile

Digital forensicsEU-developed

Acquire

Collects forensic artifacts from live systems or disk images into lightweight containers for triage and subsequent independent investigation.

NL NetherlandsOpen sourceDesktop/CLI
View profile

Digital forensicsInstitution-led

ADTimeline

PowerShell utility that reconstructs partial timelines of Active Directory object changes from replication metadata for incident investigation and threat hunting.

FR FranceOpen sourceDesktop/CLIMaintenance unconfirmed
View profile

Threat intelligenceCSIRT-led

AIL Framework

Collect and analyse unstructured web, chat and file data to investigate information leaks and extract threat intelligence.

LU LuxembourgOpen sourceSelf-hosted
View profile

Detection and monitoringEU-developed

ASGARD Management Center

Incident-response console that deploys agents, schedules compromise scans, manages indicators, collects evidence, and executes response playbooks across endpoints.

DE GermanyCommercialSelf-hosted
View profile

Threat intelligenceCSIRT-led

BGP Ranking

Aggregate malicious-activity observations by autonomous system number and inspect comparative rankings and historical changes.

LU LuxembourgOpen sourceSelf-hosted / Public service
View profile

Digital forensicsEU-developed

CapLoader

Indexes large PCAP collections, identifies network protocols, filters suspicious flows and exports selected packets for deeper forensic analysis.

SE SwedenCommercialDesktop/CLI
View profile

Response coordinationCSIRT-led

Cerebrate

Maintain trusted contacts, organisational affiliations and public keys, and connect security tools across collaborating response teams.

LU LuxembourgOpen sourceSelf-hosted
View profile

Response coordinationCSIRT-led

Convey

Transforms incident logs and tables into enriched, filtered or split reports that CSIRTs can send to responsible contacts through SMTP or OTRS.

CZ CzechiaOpen sourceDesktop/CLI / Self-hosted
View profile

Feed automationEU-developed

Cortex

Observable analysis and response engine that runs analyzers and responders through a shared API, commonly connected to TheHive investigations.

FR FranceOpen sourceSelf-hosted
View profile

Detection and monitoringEU-developed

CounterCraft The Platform

Deception platform that deploys realistic decoy assets, records adversary interaction, and enriches resulting alerts with indicators and attack-technique context.

ES SpainCommercialSelf-hosted
View profile

Detection and monitoringEU-developed

CrowdSec Security Engine

Parses system and application logs to detect hostile behavior, generate local decisions and feed remediation components for blocking or challenging attackers.

FR FranceOpen sourceSelf-hosted
View profile

Threat intelligenceCSIRT-led

CVE Search

Import vulnerability and platform-enumeration data into a local database, then search it through command-line, web and API interfaces.

LU LuxembourgOpen sourceSelf-hosted
View profile

Exposure discoveryEU-developed

Cyberwatch Vulnerability Manager

Vulnerability management software that discovers assets, scans for affected technologies, prioritizes findings using context, and supports patch decisions and remediation.

FR FranceCommercialSelf-hosted
View profile

Exposure discoveryEU-developed

Cyscale Cloud Platform

Cloud security platform linking vulnerable software, exposed workloads, identities and ownership so teams can prioritize and route remediation.

RO RomaniaCommercialSaaS
View profile

Detection and monitoringCSIRT-led

D4

Build a distributed sensor network that collects security telemetry and dispatches it to configured decoders and analysers.

LU LuxembourgOpen sourceSelf-hosted
View profile

Threat intelligenceEU-developed

DCSO Threat Intelligence Engine

Aggregates selected intelligence feeds, normalizes and contextualizes indicators, then exposes tailored IoC collections through an authenticated API.

DE GermanyCommercialSaaS
View profile

Malware analysisInstitution-led

DECODE

Standalone analysis tool that ranks anomalous Windows PE files from DFIR ORC metadata and exports triage results as CSV or PDF.

FR FranceOpen sourceDesktop/CLIMaintenance unconfirmed
View profile

Digital forensicsInstitution-led

DFIR ORC

Windows forensic acquisition utility for collecting incident response artefacts from hosts into structured archives for later analysis and evidence handling.

FR FranceOpen sourceDesktop/CLI
View profile

Response coordinationCSIRT-led

DFIR-IRIS

Collaborative incident response workspace for sharing technical investigation details, organizing cases, and tracking evidence and timelines across responders.

FR FranceOpen sourceSelf-hosted
View profile

Digital forensicsInstitution-led

DFIR-O365RC

PowerShell forensic collection module that retrieves Microsoft 365 audit events and Entra sign-in logs for post-incident investigations.

FR FranceOpen sourceDesktop/CLIMaintenance unconfirmed
View profile

Digital forensicsInstitution-led

DFIR-OGRE

Command-line parser that extracts Windows artefacts from DFIR ORC archives into structured records for analysis in search and analytics systems.

FR FranceOpen sourceDesktop/CLIBeta / experimental
View profile

Response coordinationEU-developed

DFIRTrack

Tracks affected systems, incidents and investigative tasks in larger digital forensics and incident response cases through a shared web interface.

DE GermanyOpen sourceSelf-hosted
View profile

Digital forensicsEU-developed

Dissect

Opens forensic images and file collections for cross-platform artifact analysis through a modular Python framework and command-line investigation tools.

NL NetherlandsOpen sourceDesktop/CLI
View profile

Malware analysisCSIRT-led

DRAKVUF Sandbox

Runs automated agentless malware analysis in virtualized guests and exposes a web interface for submissions and examination of results.

PL PolandSource availableSelf-hosted
View profile

Detection and monitoringCSIRT-led

droid

Validates and transforms Sigma detection rules, then searches or deploys them across compatible SIEM and EDR environments through a command-line workflow.

BE BelgiumOpen sourceDesktop/CLI
View profile

Threat intelligenceEU-developed

EclecticIQ Intelligence Center

Threat intelligence platform for ingesting, structuring, analyzing, and sharing indicators and adversary context through analyst workflows, APIs, and integrations.

NL NetherlandsCommercialSelf-hosted
View profile

Detection and monitoringEU-developed

ESET Inspect On-Prem

Endpoint detection and response console that collects endpoint events, investigates anomalies and indicators, and provides response actions through an on-premises server.

SK SlovakiaCommercialSelf-hosted
View profile

Detection and monitoringEU-developed

Exein Runtime

Embedded runtime security platform with on-device agents that monitor and block malicious behavior and send fleet telemetry for investigation.

IT ItalyCommercialSaaS
View profile

Response coordinationCSIRT-led

Flowintel

Organise investigation cases, tasks and analyst notes, with templates, assignments and integrations for threat intelligence workflows.

LU LuxembourgOpen sourceSelf-hosted
View profile

Detection and monitoringEU-developed

G DATA XDR

Endpoint detection and response offering that correlates signals across devices, prioritizes incidents, and supports process termination or file quarantine.

DE GermanyCommercialSaaS
View profile

Detection and monitoringEU-developed

Gatewatcher NDR

Network detection and response platform that analyses traffic and metadata, prioritizes suspicious activity, and supports threat hunting and incident investigation.

FR FranceCommercialSelf-hosted / SaaS
View profile

Malware analysisEU-developed

GLIMPS Audit

Binary analysis product that recognizes libraries and known code across architectures, supports software reverse engineering, and exports symbols to analyst tools.

FR FranceCommercialSelf-hosted / SaaSMaintenance unconfirmed
View profile

Malware analysisEU-developed

GLIMPS Malware Expert

File analysis workspace that combines static and dynamic engines, extracts indicators and malware context, and supports investigation and threat hunting.

FR FranceCommercialSelf-hosted / SaaS
View profile

Detection and monitoringEU-developed

Guardsix NDR

Network detection and response product that analyzes network telemetry, groups related activity into attack chains, and supports investigation in on-premises environments.

DK DenmarkCommercialSelf-hosted
View profile

Detection and monitoringEU-developed

HarfangLab EDR

Endpoint detection and response software that monitors workstation and server activity, raises investigation alerts, and supports blocking and response actions.

FR FranceCommercialSelf-hosted / SaaS
View profile

Digital forensicsCSIRT-led

Hashlookup

Look up file hashes in known-file datasets to add context during incident investigation and forensic triage.

LU LuxembourgOpen sourceSelf-hosted / Public serviceBeta / experimental
View profile

Malware analysisCSIRT-led

Hfinger

Fingerprints malware HTTP requests from packet captures so analysts can compare traffic patterns and group activity associated with malware families.

PL PolandOpen sourceDesktop/CLIBeta / experimental
View profile

Exposure discoveryEU-developed

Holm Security VMP

Vulnerability management platform that scans systems, networks, and applications, tracks exposure over time, and supports risk-based remediation across an organization.

SE SwedenCommercialSaaS / Self-hosted
View profile

Threat intelligenceEU-developed

IntelOwl

Enriches files and indicators such as IP addresses, domains and hashes through configurable analyzers, with a shared REST API and investigative interface.

IT ItalyOpen sourceSelf-hosted
View profile

Detection and monitoringInstitution-led

ipfixprobe

Exports bidirectional network flow records with protocol metadata and telemetry for downstream monitoring and investigation systems.

CZ CzechiaOpen sourceSelf-hosted
View profile

Malware analysisCSIRT-led

Karton

Runs distributed malware processing tasks using Python workers, Redis messaging and S3 storage, with independent analysis services around the core framework.

PL PolandOpen sourceSelf-hosted
View profile

Detection and monitoringCSIRT-led

Kunai

Monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting.

LU LuxembourgOpen sourceDesktop/CLI
View profile

Malware analysisCSIRT-led

Kunai Sandbox

Run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering.

LU LuxembourgOpen sourceSelf-hosted / Public service
View profile

Detection and monitoringEU-developed

Loki-RS

Scans files, process memory and archives for YARA rules and indicators of compromise during endpoint triage and threat hunting.

DE GermanyOpen sourceDesktop/CLI
View profile

Threat intelligenceCSIRT-led

Lookyloo

Capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations.

LU LuxembourgOpen sourceSelf-hosted / Public service
View profile

Detection and monitoringInstitution-led

MADCAT

Runs a low-interaction network sensor that records connection attempts across services to help analysts observe mass scanning and attack patterns.

DE GermanyOpen sourceSelf-hosted
View profile

Exposure discoveryCSIRT-led

Mailgoose

Checks a domain's SPF and DMARC records and validates DKIM through a test email, with a self-hosted portal reusable by other CSIRTs.

PL PolandOpen sourceSelf-hosted / Public service
View profile

Detection and monitoringInstitution-led

Mentat

Processes structured security events in a modular SIEM, providing a web interface, searchable event records and periodic notifications to affected networks.

CZ CzechiaOpen sourceSelf-hosted
View profile

Threat intelligenceEU-developed

Mercury

Delivers analyst-reviewed threat intelligence, vulnerability alerts, contextual risk scoring, IOC access and tailored reports through a customer web portal.

DE GermanyCommercialSaaS
View profile

Malware analysisInstitution-led

Miasm

Python reverse-engineering framework for disassembly, binary rewriting, intermediate representation, emulation, unpacking and expression simplification during binary analysis.

FR FranceOpen sourceDesktop/CLI
View profile

Malware analysisCSIRT-led

mquery

Indexes local malware collections with UrsaDB and provides a web interface for analysts to search those samples using YARA rules.

PL PolandOpen sourceSelf-hosted
View profile

Detection and monitoringInstitution-led

NEMEA

Analyzes network flows through modular detectors for malicious traffic such as scans, denial-of-service activity and DNS tunneling.

CZ CzechiaOpen sourceSelf-hostedMaintenance unconfirmed
View profile

Threat intelligenceInstitution-led

NERD

Aggregates data about known malicious network entities, chiefly IP addresses, and presents the combined context to investigators.

CZ CzechiaOpen sourceSelf-hosted / Public service
View profile

Digital forensicsEU-developed

NetworkMiner

Parses PCAP traffic to reconstruct transferred files, credentials and host context for network forensic investigation and incident response.

SE SwedenOpen coreDesktop/CLI
View profile

Exposure discoveryEU-developed

ONEKEY Platform

Analyzes embedded firmware binaries to inventory components, generate SBOMs, identify known vulnerabilities and monitor product risk over subsequent releases.

DE GermanyCommercialSaaS
View profile

Exposure discoveryEU-developed

OpenAEV

Adversarial exposure validation platform for planning and running attack simulations, measuring defensive coverage, and tracking remediation against tested scenarios.

FR FranceOpen coreSelf-hosted / SaaS
View profile

Exposure discoveryEU-developed

OpenCVE

Tracks published vulnerabilities for selected vendors and products, with CVE filtering, subscriptions, notifications and shared remediation tracking for security teams.

FR FranceSource availableSelf-hosted / SaaS
View profile

Exposure discoveryEU-developed

OPENVAS SCAN

Vulnerability scanner for networks, endpoints, and containers with authenticated checks, risk prioritization, remediation guidance, and virtual-appliance deployment.

DE GermanyCommercialSelf-hosted
View profile

Detection and monitoringInstitution-led

OpenWEC

Linux-based Windows Event Collector server that receives source-initiated event forwarding without installing an additional Windows agent.

FR FranceOpen sourceSelf-hosted / Desktop/CLI
View profile

Exposure discoveryInstitution-led

ORADAD

Windows command-line utility that exports Active Directory data through LDAP, including multi-domain forests, to support directory security audits and investigations.

FR FranceOpen sourceDesktop/CLI
View profile

Exposure discoveryInstitution-led

ORADAZ

Beta command-line utility that dumps Azure configuration data through REST APIs to support security audits and manual exposure review.

FR FranceOpen sourceDesktop/CLIBeta / experimental
View profile

Digital forensicsInstitution-led

orc2timeline

Local command-line utility that processes one or more DFIR ORC forensic archives and creates a per-host timeline for incident analysis.

FR FranceOpen sourceDesktop/CLIMaintenance unconfirmed
View profile

Threat intelligenceEU-developed

Outpost24 CompassDRP

Cloud digital-risk product that combines external asset discovery with threat intelligence and monitors exposed credentials, leaked data, and phishing domains.

SE SwedenCommercialSaaS
View profile

Exposure discoveryEU-developed

Outpost24 OutscanNX

Vulnerability management product that scans network and cloud assets, prioritizes findings with exploit context, and tracks remediation through reports and workflows.

SE SwedenCommercialSaaS / Self-hosted
View profile

Malware analysisCSIRT-led

Pandora

Inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports.

LU LuxembourgOpen sourceSelf-hosted / Public service
View profile

Exposure discoveryEU-developed

Pentest-Tools.com

Hosted security testing platform for scanning and validating vulnerabilities in web applications, networks and cloud infrastructure, with findings and reporting workflows.

RO RomaniaCommercialSaaS
View profile

Exposure discoveryCSIRT-led

Plum Island

Schedule distributed perimeter scans, retain observations over time and search changes in exposed services and technical metadata.

LU LuxembourgOpen sourceSelf-hostedBeta / experimental
View profile

Response coordinationInstitution-led

Secvisogram

Creates and edits machine-readable CSAF security advisories in a web interface for coordinated publication and exchange of vulnerability information.

DE GermanyOpen sourceSelf-hosted
View profile

Detection and monitoringEU-developed

Sekoia Defend

Cloud security operations product that ingests telemetry, applies detection rules, supports alert and case investigation, and runs automated playbooks.

FR FranceCommercialSaaS
View profile

Threat intelligenceEU-developed

Sekoia Intelligence

Threat intelligence product with searchable actor, campaign, malware and indicator records, analyst reports, feeds, and APIs for dissemination to security systems.

FR FranceCommercialSaaS
View profile

Detection and monitoringEU-developed

Stormshield Endpoint Security Evolution

Endpoint detection and response software for workstations and servers, with behavioral detection, YARA-based hunting and predefined or custom remediation actions.

FR FranceCommercialSelf-hosted / SaaS
View profile

Malware analysisCSIRT-led

Suspicious

Triages suspicious emails, files, URLs and indicators through configurable analyzers, then presents investigation reports in a self-hosted web interface.

FR FranceOpen sourceSelf-hosted
View profile

Detection and monitoringEU-developed

T-Pot

Combines multiple honeypots and a local analysis stack to collect, search and visualize attempted attacks against decoy network services.

DE GermanyOpen sourceSelf-hosted
View profile

Detection and monitoringEU-developed

Tehtris EDR

Endpoint detection and response product that monitors execution and privilege activity, investigates suspicious behavior, and can block processes or isolate hosts.

FR FranceCommercialSaaS
View profile

Feed automationEU-developed

Tenzir

Collects, parses, transforms, enriches and routes security telemetry through programmable pipelines for detection, investigation and downstream security tools.

DE GermanyOpen coreSelf-hosted / SaaS
View profile

Malware analysisEU-developed

THOR APT Scanner

Portable compromise-assessment scanner that searches live hosts or forensic images using YARA, Sigma, indicators, and anomaly checks without installation.

DE GermanyCommercialDesktop/CLI
View profile

Response coordinationCSIRT-led

Tuency

Lets a CERT constituency manage organization contacts and network objects so IntelMQ can route security notifications to the appropriate recipients.

AT AustriaOpen sourceSelf-hosted
View profile

Exposure discoveryCSIRT-led

Typosquatting Finder

Generate and resolve look-alike domain names, inspect results and export findings for follow-up threat intelligence analysis.

LU LuxembourgOpen sourceSelf-hosted / Public service
View profile

Digital forensicsEU-developed

unblob

Recursively extracts firmware and other binary containers, carves unknown chunks and produces structured reports for analysts examining embedded-device images.

DE GermanyOpen sourceDesktop/CLI
View profile

Digital forensicsInstitution-led

usbsas

Linux tool for forensic examination of untrusted USB devices, with read-only mounting, disk imaging and controlled file transfer.

FR FranceOpen sourceDesktop/CLI
View profile

Malware analysisEU-developed

VMRay Platform

Analyzes suspicious files, URLs and emails with layered sandbox techniques, returning behavioral findings, verdict context and extracted indicators for responders.

DE GermanyCommercialSelf-hosted / SaaS
View profile

Threat intelligenceCSIRT-led

Vulnerability-Lookup

Correlate vulnerability records across sources, track sightings and support advisory publication and coordinated vulnerability disclosure.

LU LuxembourgOpen sourceSelf-hosted / Public service
View profile

Feed automationCSIRT-led

Warden

Shares structured security-event reports between authenticated CSIRT participants through a server, sending clients and receiving clients using the IDEA format.

CZ CzechiaOpen sourceSelf-hosted
View profile

Threat intelligenceCSIRT-led

Watcher

Monitors vulnerability, ransomware and news sources against watch terms, collecting results and sending alerts through a self-hosted analyst interface.

FR FranceOpen sourceSelf-hosted
View profile

Exposure discoveryEU-developed

WithSecure Elements Exposure Management

Cloud exposure management offering that discovers assets and vulnerabilities across devices, identities, cloud, and external surfaces, then ranks remediation work.

FI FinlandCommercialSaaS
View profile

Detection and monitoringEU-developed

WithSecure Elements XDR

Cloud extended detection and response offering that correlates endpoint, identity, email, and cloud telemetry to investigate and contain multistage attacks.

FI FinlandCommercialSaaS
View profile

Download all 97 profiles Read the selection method

Start with
the response.

Different tasks call for different tools. Explore how this catalog fits across 7 response workflows.

Read the workflow guides

Choose a workflow to update the catalog. The map follows your active filters.

Response workflows

Choose a task to focus the catalog.

97Visible profiles
All workflowsChoose a node to see matching tools
97 profiles in view

Read the record

Evidence is part
of the interface.

Who builds it. Where it comes from. How it runs.

Every profile links to its sources and makes gaps in the evidence visible. A listing is a starting point for assessment.

How we classify tools