Threat intelligenceEU-developed
IntelFusions
Public threat-intelligence research platform linking adversary profiles, malware, incident claims, detection-rule references and contextual briefings for analyst investigation.
An independent tool index
for incident response teams
An independent European tool index
European tools for CSIRT work, with the sources behind every listing.
8 more countries in the filters. Country identifies the recorded project lead or developer. How we check origin
97 profiles with reviewed primary sources. Filter, inspect, and build your shortlist.
Only explicit, sourced matches appear. Missing tags mean support or funding has not been established in this pass. Inspect supported features · Explore EU-funded tools
Threat intelligenceEU-developed
Public threat-intelligence research platform linking adversary profiles, malware, incident claims, detection-rule references and contextual briefings for analyst investigation.
Threat intelligenceCSIRT-led
Collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools.
Feed automationCSIRT-led
Collects and processes security feeds through message-queued bots to automate incident handling, notifications and exchange with other systems.
Feed automationCSIRT-led
Collects, manages and distributes security incident and threat feeds to authorized users through a REST API and web interface.
Exposure discoveryCSIRT-led
Scans websites for security issues through modular checks and generates readable notices for administrators from the resulting findings.
Threat intelligenceCSIRT-led
Collects open-source intelligence, supports analyst reporting and controlled team collaboration, and publishes outputs from a self-hosted Docker deployment.
Malware analysisCSIRT-led
Stores malware samples and extracted configurations, letting analysts search relationships, share collections and integrate through its REST API.
Threat intelligenceEU-developed
Threat intelligence platform that structures observables and context with STIX 2, links assertions to sources, and exchanges data through APIs and connectors.
Response coordinationEU-developed
Incident response platform for triaging alerts, opening cases, coordinating investigation tasks, and analyzing observables through connected Cortex services.
Detection and monitoringEU-developed
Security information and event management product that correlates logs from hybrid infrastructure and provides detections, investigation context, and audit evidence.
Detection and monitoringEU-developed
Extended detection and response product that correlates endpoint, identity, network, and cloud signals to investigate incidents and coordinate response actions.
Digital forensicsEU-developed
Collects forensic artifacts from live systems or disk images into lightweight containers for triage and subsequent independent investigation.
Digital forensicsInstitution-led
PowerShell utility that reconstructs partial timelines of Active Directory object changes from replication metadata for incident investigation and threat hunting.
Threat intelligenceCSIRT-led
Collect and analyse unstructured web, chat and file data to investigate information leaks and extract threat intelligence.
Detection and monitoringEU-developed
Incident-response console that deploys agents, schedules compromise scans, manages indicators, collects evidence, and executes response playbooks across endpoints.
Threat intelligenceCSIRT-led
Aggregate malicious-activity observations by autonomous system number and inspect comparative rankings and historical changes.
Digital forensicsEU-developed
Indexes large PCAP collections, identifies network protocols, filters suspicious flows and exports selected packets for deeper forensic analysis.
Response coordinationCSIRT-led
Maintain trusted contacts, organisational affiliations and public keys, and connect security tools across collaborating response teams.
Response coordinationCSIRT-led
Transforms incident logs and tables into enriched, filtered or split reports that CSIRTs can send to responsible contacts through SMTP or OTRS.
Feed automationEU-developed
Observable analysis and response engine that runs analyzers and responders through a shared API, commonly connected to TheHive investigations.
Detection and monitoringEU-developed
Deception platform that deploys realistic decoy assets, records adversary interaction, and enriches resulting alerts with indicators and attack-technique context.
Detection and monitoringEU-developed
Parses system and application logs to detect hostile behavior, generate local decisions and feed remediation components for blocking or challenging attackers.
Threat intelligenceCSIRT-led
Import vulnerability and platform-enumeration data into a local database, then search it through command-line, web and API interfaces.
Exposure discoveryEU-developed
Vulnerability management software that discovers assets, scans for affected technologies, prioritizes findings using context, and supports patch decisions and remediation.
Exposure discoveryEU-developed
Cloud security platform linking vulnerable software, exposed workloads, identities and ownership so teams can prioritize and route remediation.
Detection and monitoringCSIRT-led
Build a distributed sensor network that collects security telemetry and dispatches it to configured decoders and analysers.
Threat intelligenceEU-developed
Aggregates selected intelligence feeds, normalizes and contextualizes indicators, then exposes tailored IoC collections through an authenticated API.
Malware analysisInstitution-led
Standalone analysis tool that ranks anomalous Windows PE files from DFIR ORC metadata and exports triage results as CSV or PDF.
Digital forensicsInstitution-led
Windows forensic acquisition utility for collecting incident response artefacts from hosts into structured archives for later analysis and evidence handling.
Response coordinationCSIRT-led
Collaborative incident response workspace for sharing technical investigation details, organizing cases, and tracking evidence and timelines across responders.
Digital forensicsInstitution-led
PowerShell forensic collection module that retrieves Microsoft 365 audit events and Entra sign-in logs for post-incident investigations.
Digital forensicsInstitution-led
Command-line parser that extracts Windows artefacts from DFIR ORC archives into structured records for analysis in search and analytics systems.
Response coordinationEU-developed
Tracks affected systems, incidents and investigative tasks in larger digital forensics and incident response cases through a shared web interface.
Digital forensicsEU-developed
Opens forensic images and file collections for cross-platform artifact analysis through a modular Python framework and command-line investigation tools.
Malware analysisCSIRT-led
Runs automated agentless malware analysis in virtualized guests and exposes a web interface for submissions and examination of results.
Detection and monitoringCSIRT-led
Validates and transforms Sigma detection rules, then searches or deploys them across compatible SIEM and EDR environments through a command-line workflow.
Threat intelligenceEU-developed
Threat intelligence platform for ingesting, structuring, analyzing, and sharing indicators and adversary context through analyst workflows, APIs, and integrations.
Detection and monitoringEU-developed
Endpoint detection and response console that collects endpoint events, investigates anomalies and indicators, and provides response actions through an on-premises server.
Detection and monitoringEU-developed
Embedded runtime security platform with on-device agents that monitor and block malicious behavior and send fleet telemetry for investigation.
Response coordinationCSIRT-led
Organise investigation cases, tasks and analyst notes, with templates, assignments and integrations for threat intelligence workflows.
Detection and monitoringEU-developed
Endpoint detection and response offering that correlates signals across devices, prioritizes incidents, and supports process termination or file quarantine.
Detection and monitoringEU-developed
Network detection and response platform that analyses traffic and metadata, prioritizes suspicious activity, and supports threat hunting and incident investigation.
Malware analysisEU-developed
Binary analysis product that recognizes libraries and known code across architectures, supports software reverse engineering, and exports symbols to analyst tools.
Malware analysisEU-developed
File analysis workspace that combines static and dynamic engines, extracts indicators and malware context, and supports investigation and threat hunting.
Detection and monitoringEU-developed
Network detection and response product that analyzes network telemetry, groups related activity into attack chains, and supports investigation in on-premises environments.
Detection and monitoringEU-developed
Endpoint detection and response software that monitors workstation and server activity, raises investigation alerts, and supports blocking and response actions.
Digital forensicsCSIRT-led
Look up file hashes in known-file datasets to add context during incident investigation and forensic triage.
Malware analysisCSIRT-led
Fingerprints malware HTTP requests from packet captures so analysts can compare traffic patterns and group activity associated with malware families.
Exposure discoveryEU-developed
Vulnerability management platform that scans systems, networks, and applications, tracks exposure over time, and supports risk-based remediation across an organization.
Threat intelligenceEU-developed
Enriches files and indicators such as IP addresses, domains and hashes through configurable analyzers, with a shared REST API and investigative interface.
Detection and monitoringInstitution-led
Exports bidirectional network flow records with protocol metadata and telemetry for downstream monitoring and investigation systems.
Malware analysisCSIRT-led
Runs distributed malware processing tasks using Python workers, Redis messaging and S3 storage, with independent analysis services around the core framework.
Detection and monitoringCSIRT-led
Monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting.
Malware analysisCSIRT-led
Run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering.
Detection and monitoringEU-developed
Scans files, process memory and archives for YARA rules and indicators of compromise during endpoint triage and threat hunting.
Threat intelligenceCSIRT-led
Capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations.
Detection and monitoringInstitution-led
Runs a low-interaction network sensor that records connection attempts across services to help analysts observe mass scanning and attack patterns.
Exposure discoveryCSIRT-led
Checks a domain's SPF and DMARC records and validates DKIM through a test email, with a self-hosted portal reusable by other CSIRTs.
Detection and monitoringInstitution-led
Processes structured security events in a modular SIEM, providing a web interface, searchable event records and periodic notifications to affected networks.
Threat intelligenceEU-developed
Delivers analyst-reviewed threat intelligence, vulnerability alerts, contextual risk scoring, IOC access and tailored reports through a customer web portal.
Malware analysisInstitution-led
Python reverse-engineering framework for disassembly, binary rewriting, intermediate representation, emulation, unpacking and expression simplification during binary analysis.
Malware analysisCSIRT-led
Indexes local malware collections with UrsaDB and provides a web interface for analysts to search those samples using YARA rules.
Detection and monitoringInstitution-led
Analyzes network flows through modular detectors for malicious traffic such as scans, denial-of-service activity and DNS tunneling.
Threat intelligenceInstitution-led
Aggregates data about known malicious network entities, chiefly IP addresses, and presents the combined context to investigators.
Digital forensicsEU-developed
Parses PCAP traffic to reconstruct transferred files, credentials and host context for network forensic investigation and incident response.
Exposure discoveryEU-developed
Analyzes embedded firmware binaries to inventory components, generate SBOMs, identify known vulnerabilities and monitor product risk over subsequent releases.
Exposure discoveryEU-developed
Adversarial exposure validation platform for planning and running attack simulations, measuring defensive coverage, and tracking remediation against tested scenarios.
Exposure discoveryEU-developed
Tracks published vulnerabilities for selected vendors and products, with CVE filtering, subscriptions, notifications and shared remediation tracking for security teams.
Exposure discoveryEU-developed
Vulnerability scanner for networks, endpoints, and containers with authenticated checks, risk prioritization, remediation guidance, and virtual-appliance deployment.
Detection and monitoringInstitution-led
Linux-based Windows Event Collector server that receives source-initiated event forwarding without installing an additional Windows agent.
Exposure discoveryInstitution-led
Windows command-line utility that exports Active Directory data through LDAP, including multi-domain forests, to support directory security audits and investigations.
Exposure discoveryInstitution-led
Beta command-line utility that dumps Azure configuration data through REST APIs to support security audits and manual exposure review.
Digital forensicsInstitution-led
Local command-line utility that processes one or more DFIR ORC forensic archives and creates a per-host timeline for incident analysis.
Threat intelligenceEU-developed
Cloud digital-risk product that combines external asset discovery with threat intelligence and monitors exposed credentials, leaked data, and phishing domains.
Exposure discoveryEU-developed
Vulnerability management product that scans network and cloud assets, prioritizes findings with exploit context, and tracks remediation through reports and workflows.
Malware analysisCSIRT-led
Inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports.
Exposure discoveryEU-developed
Hosted security testing platform for scanning and validating vulnerabilities in web applications, networks and cloud infrastructure, with findings and reporting workflows.
Exposure discoveryCSIRT-led
Schedule distributed perimeter scans, retain observations over time and search changes in exposed services and technical metadata.
Response coordinationInstitution-led
Creates and edits machine-readable CSAF security advisories in a web interface for coordinated publication and exchange of vulnerability information.
Detection and monitoringEU-developed
Cloud security operations product that ingests telemetry, applies detection rules, supports alert and case investigation, and runs automated playbooks.
Threat intelligenceEU-developed
Threat intelligence product with searchable actor, campaign, malware and indicator records, analyst reports, feeds, and APIs for dissemination to security systems.
Detection and monitoringEU-developed
Endpoint detection and response software for workstations and servers, with behavioral detection, YARA-based hunting and predefined or custom remediation actions.
Malware analysisCSIRT-led
Triages suspicious emails, files, URLs and indicators through configurable analyzers, then presents investigation reports in a self-hosted web interface.
Detection and monitoringEU-developed
Combines multiple honeypots and a local analysis stack to collect, search and visualize attempted attacks against decoy network services.
Detection and monitoringEU-developed
Endpoint detection and response product that monitors execution and privilege activity, investigates suspicious behavior, and can block processes or isolate hosts.
Feed automationEU-developed
Collects, parses, transforms, enriches and routes security telemetry through programmable pipelines for detection, investigation and downstream security tools.
Malware analysisEU-developed
Portable compromise-assessment scanner that searches live hosts or forensic images using YARA, Sigma, indicators, and anomaly checks without installation.
Response coordinationCSIRT-led
Lets a CERT constituency manage organization contacts and network objects so IntelMQ can route security notifications to the appropriate recipients.
Exposure discoveryCSIRT-led
Generate and resolve look-alike domain names, inspect results and export findings for follow-up threat intelligence analysis.
Digital forensicsEU-developed
Recursively extracts firmware and other binary containers, carves unknown chunks and produces structured reports for analysts examining embedded-device images.
Digital forensicsInstitution-led
Linux tool for forensic examination of untrusted USB devices, with read-only mounting, disk imaging and controlled file transfer.
Malware analysisEU-developed
Analyzes suspicious files, URLs and emails with layered sandbox techniques, returning behavioral findings, verdict context and extracted indicators for responders.
Threat intelligenceCSIRT-led
Correlate vulnerability records across sources, track sightings and support advisory publication and coordinated vulnerability disclosure.
Feed automationCSIRT-led
Shares structured security-event reports between authenticated CSIRT participants through a server, sending clients and receiving clients using the IDEA format.
Threat intelligenceCSIRT-led
Monitors vulnerability, ransomware and news sources against watch terms, collecting results and sending alerts through a self-hosted analyst interface.
Exposure discoveryEU-developed
Cloud exposure management offering that discovers assets and vulnerabilities across devices, identities, cloud, and external surfaces, then ranks remediation work.
Detection and monitoringEU-developed
Cloud extended detection and response offering that correlates endpoint, identity, email, and cloud telemetry to investigate and contain multistage attacks.
Try a broader term or remove a filter. The catalog contains 97 researched profiles.
Different tasks call for different tools. Explore how this catalog fits across 7 response workflows.
Read the workflow guidesChoose a workflow to update the catalog. The map follows your active filters.
Choose a task to focus the catalog.
Read the record
Who builds it. Where it comes from. How it runs.
Every profile links to its sources and makes gaps in the evidence visible. A listing is a starting point for assessment.
How we classify tools