{
  "title": "CSIRTS.eu researched tool catalog",
  "scope": "Documented EU-27 development or project stewardship; not a claim of exclusive EU ownership or hosting.",
  "reviewedAt": "2026-10-10",
  "count": 97,
  "tools": [
    {
      "slug": "intelfusions",
      "name": "IntelFusions",
      "maker": "IntelFusions",
      "country": "Romania",
      "workflow": "Threat intelligence",
      "format": "Free service",
      "deployment": [
        "Public service"
      ],
      "description": "Public threat-intelligence research platform linking adversary profiles, malware, incident claims, detection-rule references and contextual briefings for analyst investigation.",
      "origin": "IntelFusions is a Romanian threat-intelligence research platform. Its About page identifies Antonio Radu as the founder who built it. The country was confirmed directly by the index owner on 10 October 2026.",
      "originClass": "EU-developed",
      "facts": [
        "Threat actor and malware profiles linked to an intelligence graph",
        "Detection-rule references with ATT&CK mappings and original-source links",
        "Intelligence briefings and country views for research"
      ],
      "sources": [
        {
          "label": "Official platform",
          "url": "https://www.intelfusions.com/"
        },
        {
          "label": "About, founder and methodology",
          "url": "https://www.intelfusions.com/about"
        },
        {
          "label": "Detection-rule reference",
          "url": "https://www.intelfusions.com/rules"
        },
        {
          "label": "Service terms and permitted use",
          "url": "https://www.intelfusions.com/terms"
        },
        {
          "label": "Controller disclosure",
          "url": "https://www.intelfusions.com/privacy"
        },
        {
          "label": "Contact information",
          "url": "https://www.intelfusions.com/contact"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Website terms; third-party datasets retain separate licenses",
      "maintenance": "Active",
      "scopeNote": "The terms describe an informational research resource, exclude alerting or monitoring services, and promise no SLA. Incident claims require independent verification. No public open-source software license or self-hosted release was verified. Public access does not permit substantial database reuse.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities"
          ],
          "url": "https://www.intelfusions.com/about",
          "checkedAt": "2026-10-10",
          "observation": "The rendered About page identifies IntelFusions as a cyber threat analysis platform, names Antonio Radu as founder and builder, and describes briefings, adversary tracking, AI security coverage, country views and a threat graph."
        },
        {
          "claims": [
            "capabilities",
            "deployment",
            "maintenance"
          ],
          "url": "https://www.intelfusions.com/",
          "checkedAt": "2026-10-10",
          "observation": "The public homepage was accessible without an account and linked briefings, threat actors, malware, rules and country views. It displayed published briefings dated 5 October 2026 and actor entries added 8 October 2026, establishing observed publication activity, not an uptime or support guarantee."
        },
        {
          "claims": [
            "capabilities",
            "deployment"
          ],
          "url": "https://www.intelfusions.com/rules",
          "checkedAt": "2026-10-10",
          "observation": "The public Rules page provides search and severity controls and describes Sigma/Splunk rule metadata with source links and ATT&CK mappings. It distinguishes mirrored metadata from IntelFusions Original rules published in full. No claim is made here that the platform executes detections."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://www.intelfusions.com/terms",
          "checkedAt": "2026-10-10",
          "observation": "Terms last updated 24 August 2026 describe an independently operated free informational research service, with no SLA and no available accounts. Reading, searching, citing and linking are allowed; substantial reuse and certain scraping require permission. Third-party datasets keep their own licenses."
        },
        {
          "claims": [
            "identity"
          ],
          "url": "https://www.intelfusions.com/privacy",
          "checkedAt": "2026-10-10",
          "observation": "The privacy policy names IntelFusions as data controller and supplies its contact email."
        },
        {
          "claims": [
            "identity"
          ],
          "url": "https://www.intelfusions.com/contact",
          "checkedAt": "2026-10-10",
          "observation": "The official Contact page supplies contact channels for IntelFusions."
        },
        {
          "claims": [
            "country"
          ],
          "sourceType": "editorial-confirmation",
          "sourceLabel": "Project owner confirmation",
          "checkedAt": "2026-10-10",
          "observation": "The CSIRTS.eu project owner directly confirmed on 10 October 2026 that IntelFusions is from Romania. This country attribution comes from that confirmation, separately from the public-page review."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "misp",
      "name": "MISP",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools.",
      "origin": "The EU CSIRTs Network tooling directory identifies CIRCL as the CSIRT lead. The project also credits Belgian Defence and international contributors; Luxembourg records CIRCL stewardship, not exclusive authorship.",
      "originClass": "CSIRT-led",
      "facts": [
        "Correlates indicators and related intelligence objects.",
        "Supports MISP, STIX and detection-rule export workflows."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/MISP/MISP"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://csirt-tooling-org.github.io/tooling-directory/"
        },
        {
          "label": "Software license",
          "url": "https://github.com/MISP/MISP/blob/2.5/LICENSE"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "This profile covers the upstream software. Hosting providers and their terms require separate review.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/MISP/MISP",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://csirt-tooling-org.github.io/tooling-directory/",
          "checkedAt": "2026-10-10",
          "observation": "The EU CSIRTs Network tooling directory identifies CIRCL as the CSIRT lead. The project also credits Belgian Defence and international contributors; Luxembourg records CIRCL stewardship, not exclusive authorship."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/MISP/MISP/blob/2.5/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/MISP/MISP",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-10-10. This is an activity signal, not a support guarantee."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "MISP-NG",
          "grantId": "2016-LU-IA-0098",
          "scope": "The 2017–2019 action supported development of MISP for information sharing. This is a completed funding action, not a statement about current financing.",
          "sources": [
            {
              "label": "MISP governance and funding history",
              "url": "https://www.misp-project.org/governance/"
            },
            {
              "label": "HaDEA CEF cybersecurity action register (December 2021 status)",
              "url": "https://hadea.ec.europa.eu/system/files/2022-06/DSI%20fiche%20Cybersecurity_final_version.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "stix",
          "note": "Imports and exports STIX 1.1.1, 1.2, 2.0 and 2.1 through the MISP-STIX converter used by MISP core. Conversion uses mapped object types; it is not a guarantee of lossless exchange.",
          "sources": [
            {
              "label": "MISP-STIX converter documentation",
              "url": "https://github.com/MISP/misp-stix"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "suricata",
          "note": "Exports indicators in Suricata rule format. This describes rule export, not a bundled Suricata sensor.",
          "sources": [
            {
              "label": "MISP import and export formats",
              "url": "https://misp-project.org/features/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "sigma",
          "note": "Stores Sigma rules and their references in a dedicated Sigma object template. This is rule storage and exchange, not execution of Sigma detections.",
          "sources": [
            {
              "label": "MISP Sigma object definition",
              "url": "https://github.com/MISP/misp-objects/blob/main/objects/sigma/definition.json"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "yara",
          "note": "Stores YARA rules, rule names, supported versions and optional test-sample hashes in a dedicated YARA object template.",
          "sources": [
            {
              "label": "MISP YARA object definition",
              "url": "https://github.com/MISP/misp-objects/blob/main/objects/yara/definition.json"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "intelmq",
      "name": "IntelMQ",
      "maker": "CERT.at / IntelMQ community",
      "country": "Austria",
      "workflow": "Feed automation",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Collects and processes security feeds through message-queued bots to automate incident handling, notifications and exchange with other systems.",
      "origin": "EU CSIRTs Network Tooling WG names CERT.at as lead; upstream credits a wider European CERT community.",
      "originClass": "CSIRT-led",
      "facts": [
        "Feed collection and processing",
        "Automated incident notifications",
        "Message-queue architecture"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/certtools/intelmq"
        },
        {
          "label": "License",
          "url": "https://github.com/certtools/intelmq/blob/develop/LICENSE"
        },
        {
          "label": "CSIRTs Network Tooling WG",
          "url": "https://github.com/csirt-tooling-org/tooling-directory"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Multi-CSIRT project; Austria identifies the directory-listed lead, not every contributor or all engineering.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/certtools/intelmq",
          "checkedAt": "2026-10-10",
          "observation": "README describes message-queued security-feed processing and automated incident workflows for CERTs and CSIRTs."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/certtools/intelmq/blob/develop/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license text is GNU Affero General Public License version 3."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/csirt-tooling-org/tooling-directory",
          "checkedAt": "2026-10-10",
          "observation": "The CSIRTs Network Tooling WG lists IntelMQ with CERT.at as lead."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/certtools/intelmq/blob/develop/NEWS.md",
          "checkedAt": "2026-10-10",
          "observation": "Upstream NEWS records version 3.5.0 released 1 November 2025 and documents a 3.5.1 patch under development."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Enhancing Cybersecurity in Austria",
          "grantId": "2018-AT-IA-0111",
          "scope": "CERT.at reports funded IntelMQ development, including the 2.1 and 2.2 releases, under this 2019–2021 action. The action has closed.",
          "sources": [
            {
              "label": "CERT.at 2020 report: CEF action and IntelMQ development",
              "url": "https://www.cert.at/de/berichte/2020/2020-chap03-4"
            },
            {
              "label": "HaDEA CEF cybersecurity action register (December 2021 status)",
              "url": "https://hadea.ec.europa.eu/system/files/2022-06/DSI%20fiche%20Cybersecurity_final_version.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "misp",
          "note": "MISP bots collect events, look up matching source IPs, create MISP feeds and create events through the MISP API.",
          "sources": [
            {
              "label": "IntelMQ MISP integration guide",
              "url": "https://docs.intelmq.org/latest/admin/integrations/misp/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "elastic",
          "note": "Documents event delivery to Elasticsearch through a Redis output bot and Logstash. The walkthrough targets ELK 6.8.0, so current-version setup needs adaptation.",
          "sources": [
            {
              "label": "IntelMQ Elasticsearch integration guide",
              "url": "https://docs.intelmq.org/latest/admin/database/elasticsearch/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "splunk",
          "note": "Documents sending events with its TCP output bot to a configured Splunk TCP input.",
          "sources": [
            {
              "label": "IntelMQ Splunk integration guide",
              "url": "https://docs.intelmq.org/latest/admin/database/splunk/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "n6",
      "name": "n6",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Feed automation",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Collects, manages and distributes security incident and threat feeds to authorized users through a REST API and web interface.",
      "origin": "Upstream README explicitly attributes development to CERT Polska.",
      "originClass": "CSIRT-led",
      "facts": [
        "Feed handling",
        "REST API and web portal",
        "Authorized distribution"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CERT-Polska/n6"
        },
        {
          "label": "License",
          "url": "https://github.com/CERT-Polska/n6/blob/master/LICENSE.txt"
        },
        {
          "label": "Upstream activity metadata",
          "url": "https://api.github.com/repos/CERT-Polska/n6"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "The CERT.PL web portal is a deployment, not evidence of a generally offered SaaS product.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CERT-Polska/n6",
          "checkedAt": "2026-10-10",
          "observation": "README describes collection, management and distribution of security information; identifies CERT Polska as developer and includes Docker deployment files."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/n6/blob/master/LICENSE.txt",
          "checkedAt": "2026-10-10",
          "observation": "Actual license text is GNU Affero General Public License version 3."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/CERT-Polska",
          "checkedAt": "2026-10-10",
          "observation": "Verified organization identifies Warsaw and the Polish CERT.PL domain."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/CERT-Polska/n6",
          "checkedAt": "2026-10-10",
          "observation": "Upstream GitHub API reports nonarchived repository with code pushed 2026-06-04; an activity signal, not a support guarantee."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Joint Threat Analysis Network (JTAN)",
          "grantId": "2020-EU-IA-0260",
          "scope": "JTAN supported n6 authentication, data-source, performance and portal improvements. The project finished in June 2024.",
          "sources": [
            {
              "label": "CERT Polska 2024 report, JTAN and FETTA sections (printed pages 75–82)",
              "url": "https://cert.pl/uploads/docs/Report_CP_2024.pdf"
            },
            {
              "label": "CERT.LV project register: JTAN funding and completion",
              "url": "https://cert.gov.lv/en/about-us/international-projects"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "misp",
          "note": "Includes a configurable MISP collector that fetches events and attached samples through PyMISP and publishes them to n6 queues. This is ingestion into n6, not a bidirectional connector.",
          "sources": [
            {
              "label": "n6 MISP collector implementation",
              "url": "https://github.com/CERT-Polska/n6/blob/master/N6DataSources/n6datasources/collectors/misp.py"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "artemis",
      "name": "Artemis",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Exposure discovery",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Scans websites for security issues through modular checks and generates readable notices for administrators from the resulting findings.",
      "origin": "Maintained under CERT Polska's verified upstream organization.",
      "originClass": "CSIRT-led",
      "facts": [
        "Modular web checks",
        "Automatic reports",
        "Experimental upstream"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CERT-Polska/Artemis"
        },
        {
          "label": "License",
          "url": "https://github.com/CERT-Polska/Artemis/blob/main/LICENSE"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "BSD-3-Clause",
      "maintenance": "Experimental",
      "scopeNote": "README explicitly says experimental; some additional modules have different licenses and are omitted.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "maintenance",
            "deployment"
          ],
          "url": "https://github.com/CERT-Polska/Artemis",
          "checkedAt": "2026-10-10",
          "observation": "README presents modular web scanning, automated readable reports, installation guidance and explicit experimental status."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/Artemis/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license has three-clause BSD conditions and CERT Polska copyright."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/CERT-Polska",
          "checkedAt": "2026-10-10",
          "observation": "Verified organization identifies Polish institutional location."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "taranis-ng",
      "name": "Taranis NG",
      "maker": "SK-CERT",
      "country": "Slovakia",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Collects open-source intelligence, supports analyst reporting and controlled team collaboration, and publishes outputs from a self-hosted Docker deployment.",
      "origin": "README explicitly credits SK-CERT and the wider CSIRT community.",
      "originClass": "CSIRT-led",
      "facts": [
        "OSINT collection",
        "Analyst reports",
        "Team collaboration"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/SK-CERT/Taranis-NG"
        },
        {
          "label": "License",
          "url": "https://github.com/SK-CERT/Taranis-NG/blob/main/LICENSE.md"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "EUPL-1.2",
      "maintenance": "Active",
      "scopeNote": "Distinct from discontinued Dutch Taranis3; follow current Docker guide for operational warnings.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/SK-CERT/Taranis-NG",
          "checkedAt": "2026-10-10",
          "observation": "README credits SK-CERT, describes OSINT collection, reports, collaboration and Docker Compose deployment."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/SK-CERT/Taranis-NG/blob/main/LICENSE.md",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE.md is European Union Public Licence version 1.2."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/SK-CERT/Taranis-NG/blob/main/CHANGELOG.md",
          "checkedAt": "2026-10-10",
          "observation": "Upstream changelog documents release 26.02.1 dated 10 February 2026 and further documented work."
        }
      ],
      "funding": [
        {
          "programme": "European Regional Development Fund (ERDF)",
          "project": "Operational Programme Integrated Infrastructure (OPII)",
          "scope": "The upstream project credits ERDF support through OPII for Taranis NG. It does not identify the specific action or funding dates in this acknowledgement.",
          "sources": [
            {
              "label": "Taranis NG upstream funding acknowledgement",
              "url": "https://github.com/SK-CERT/Taranis-NG"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "MeliCERTes Facility",
          "grantId": "SMART2018/1024",
          "scope": "The upstream project credits CEF support through the MeliCERTes Facility. SMART2018/1024 is a contract reference; the acknowledgement does not establish ongoing funding.",
          "sources": [
            {
              "label": "Taranis NG upstream funding acknowledgement",
              "url": "https://github.com/SK-CERT/Taranis-NG"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Joint Threat Analysis Network (JTAN)",
          "grantId": "2020-EU-IA-0260",
          "scope": "The upstream project credits JTAN for Taranis NG development. The project finished in June 2024; this records historical support.",
          "sources": [
            {
              "label": "Taranis NG upstream funding acknowledgement",
              "url": "https://github.com/SK-CERT/Taranis-NG"
            },
            {
              "label": "CERT.LV project register: JTAN funding and completion",
              "url": "https://cert.gov.lv/en/about-us/international-projects"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "mwdb-core",
      "name": "MWDB Core",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Stores malware samples and extracted configurations, letting analysts search relationships, share collections and integrate through its REST API.",
      "origin": "Maintained in CERT Polska's upstream organization.",
      "originClass": "CSIRT-led",
      "facts": [
        "Sample and configuration repository",
        "Search and relationships",
        "REST API"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CERT-Polska/mwdb-core"
        },
        {
          "label": "License",
          "url": "https://github.com/CERT-Polska/mwdb-core/blob/master/LICENSE"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0-or-later with plugin exception",
      "maintenance": "Active",
      "scopeNote": "Core license includes a plugin exception; plugin code may carry other terms.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CERT-Polska/mwdb-core",
          "checkedAt": "2026-10-10",
          "observation": "README documents self-hosted malware sample and configuration repository, search, relationships, sharing and API."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/mwdb-core/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license is GNU AGPL version 3 or later with an API plugin exception."
        },
        {
          "claims": [
            "country",
            "maintenance"
          ],
          "url": "https://github.com/CERT-Polska",
          "checkedAt": "2026-10-10",
          "observation": "Verified Polish CERT organization lists MWDB Core with a 2026 update."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Joint Threat Analysis Network (JTAN)",
          "grantId": "2020-EU-IA-0260",
          "scope": "JTAN supported MWDB Core visualisation, structured analysis results and MISP sharing improvements. The project finished in June 2024.",
          "sources": [
            {
              "label": "CERT Polska 2024 report, JTAN and FETTA sections (printed pages 75–82)",
              "url": "https://cert.pl/uploads/docs/Report_CP_2024.pdf"
            },
            {
              "label": "CERT.LV project register: JTAN funding and completion",
              "url": "https://cert.gov.lv/en/about-us/international-projects"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "opencti",
      "name": "OpenCTI",
      "maker": "Filigran",
      "country": "France",
      "workflow": "Threat intelligence",
      "format": "Open core",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Threat intelligence platform that structures observables and context with STIX 2, links assertions to sources, and exchanges data through APIs and connectors.",
      "origin": "Designed and developed by French company Filigran; the repository does not establish that every contributor or hosting region is French.",
      "originClass": "EU-developed",
      "facts": [
        "Stores linked technical and nontechnical threat intelligence with source references.",
        "Imports and exports STIX 2 and CSV data and exposes a GraphQL API.",
        "Community Edition uses Apache-2.0; Enterprise Edition has a separate license."
      ],
      "sources": [
        {
          "label": "Upstream repository and README",
          "url": "https://github.com/OpenCTI-Platform/opencti"
        },
        {
          "label": "Upstream license",
          "url": "https://github.com/OpenCTI-Platform/opencti/blob/master/LICENSE"
        },
        {
          "label": "Filigran product and deployment",
          "url": "https://filigran.io/products/opencti"
        },
        {
          "label": "Current edition license agreements",
          "url": "https://filigran.io/licenses"
        },
        {
          "label": "Filigran France legal identity",
          "url": "https://filigran.io/privacy-policy"
        },
        {
          "label": "Releases",
          "url": "https://github.com/OpenCTI-Platform/opencti/releases"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Mixed: Apache-2.0 Community Edition; OpenCTI Enterprise Edition License",
      "maintenance": "Active",
      "scopeNote": "The freely accessible demonstration instance is not the SaaS offer; edition-specific capabilities and hosting location need individual checking.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/OpenCTI-Platform/opencti",
          "checkedAt": "2026-10-10",
          "observation": "The project README calls OpenCTI a STIX 2 threat intelligence platform, names Filigran as designer and developer, and documents Docker/manual installation, API, import/export and connectors."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://filigran.io/privacy-policy",
          "checkedAt": "2026-10-10",
          "observation": "Filigran's current privacy policy identifies Filigran SAS as its French group entity at 66 avenue des Champs Élysées, Paris."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/OpenCTI-Platform/opencti/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Current upstream license distinguishes Apache-2.0 Community Edition source from separately licensed Enterprise Edition source."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://filigran.io/products/opencti",
          "checkedAt": "2026-10-10",
          "observation": "Filigran offers self-hosted Community and Enterprise editions and a fully managed OpenCTI Enterprise Edition SaaS service, distinct from its live demo and trial."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://filigran.io/licenses",
          "checkedAt": "2026-10-10",
          "observation": "Filigran's current license page links a separate OpenCTI Enterprise Edition agreement and says Community Edition remains Apache-2.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/OpenCTI-Platform/opencti/releases",
          "checkedAt": "2026-10-10",
          "observation": "Upstream release list has current 2026 platform releases."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "taxii",
          "note": "Exposes filtered intelligence collections through a TAXII 2.1 server; the collections require access credentials.",
          "sources": [
            {
              "label": "OpenCTI integration documentation",
              "url": "https://docs.opencti.io/latest/deployment/integrations/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "stix",
          "note": "Exposes STIX 2.1 data through filtered live streams using HTTP server-sent events. Stream connectors can consume create, update and delete events.",
          "sources": [
            {
              "label": "OpenCTI integrations and live streams",
              "url": "https://docs.opencti.io/latest/deployment/integrations/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "misp",
          "note": "Optional external-import connector pulls MISP events and attributes into OpenCTI as STIX 2.1 objects. It requires MISP API access; this connector imports in one direction.",
          "sources": [
            {
              "label": "OpenCTI MISP connector README",
              "url": "https://github.com/OpenCTI-Platform/connectors/blob/master/external-import/misp/README.md"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "thehive",
      "name": "TheHive",
      "maker": "StrangeBee",
      "country": "France",
      "workflow": "Response coordination",
      "format": "Commercial",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Incident response platform for triaging alerts, opening cases, coordinating investigation tasks, and analyzing observables through connected Cortex services.",
      "origin": "Began in an unnamed European financial institution CSIRT; current developer and licensor is French company StrangeBee. The original CSIRT country was not established.",
      "originClass": "EU-developed",
      "facts": [
        "Turns alerts into cases and tracks investigation work.",
        "Community license is free for on-prem use but requires activation; cloud is a paid Platinum option.",
        "TheHive 5 Community license restricts modification and redistribution."
      ],
      "sources": [
        {
          "label": "Current license and edition documentation",
          "url": "https://docs.strangebee.com/thehive/installation/licenses/about-licenses/"
        },
        {
          "label": "Community license terms",
          "url": "https://strangebee.com/wp-content/uploads/2024/06/TheHive-5-Community-License-General-Terms-latest.pdf"
        },
        {
          "label": "Alert management documentation",
          "url": "https://docs.strangebee.com/thehive/how-to/alert-management/"
        },
        {
          "label": "Release policy",
          "url": "https://docs.strangebee.com/thehive/installation/release-and-maintenance-policy/"
        },
        {
          "label": "StrangeBee company history",
          "url": "https://strangebee.com/about-strangebee/"
        },
        {
          "label": "StrangeBee SaaS legal agreement",
          "url": "https://strangebee.com/wp-content/uploads/2024/06/TheHive-Cloud-Platform-SaaS-Agreement-latest.pdf"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "Current TheHive 5 is proprietary despite older TheHive 4 AGPL releases. Cloud placement is not guaranteed in France; a trial becomes read-only without an activated license.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://docs.strangebee.com/thehive/how-to/alert-management/",
          "checkedAt": "2026-10-10",
          "observation": "TheHive documentation covers alert triage and conversion to cases, supporting its incident-response workflow classification."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://docs.strangebee.com/thehive/installation/licenses/about-licenses/",
          "checkedAt": "2026-10-10",
          "observation": "Current documentation says Community is free but activated and on-prem only; Gold is paid on-prem; Platinum is paid on-prem or cloud; expired trial becomes read-only."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://strangebee.com/wp-content/uploads/2024/06/TheHive-5-Community-License-General-Terms-latest.pdf",
          "checkedAt": "2026-10-10",
          "observation": "TheHive 5 Community terms forbid modification, reverse engineering and redistribution, so free Community use is not open source."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://strangebee.com/about-strangebee/",
          "checkedAt": "2026-10-10",
          "observation": "StrangeBee's history describes TheHive's inception in a European financial institution's CSIRT and its subsequent development by StrangeBee."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://strangebee.com/wp-content/uploads/2024/06/TheHive-Cloud-Platform-SaaS-Agreement-latest.pdf",
          "checkedAt": "2026-10-10",
          "observation": "StrangeBee's own SaaS agreement identifies the company as a French SAS based in Paris."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://docs.strangebee.com/thehive/installation/release-and-maintenance-policy/",
          "checkedAt": "2026-10-10",
          "observation": "The current release policy lists maintained TheHive 5 versions and 2026 release activity."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "misp",
          "note": "Imports MISP events as alerts and exports case observables marked as IOCs to MISP. Connecting multiple MISP servers requires a paid TheHive license.",
          "sources": [
            {
              "label": "TheHive MISP connection guide",
              "url": "https://docs.strangebee.com/thehive/administration/misp-integration/connect-a-misp-server/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "cortex",
          "note": "Connects to a separately installed Cortex server for analyzers and responders. Multiple Cortex servers require a paid license; TheHive 5.5 drops support for Cortex 3.1.5 and earlier.",
          "sources": [
            {
              "label": "TheHive Cortex server guide",
              "url": "https://docs.strangebee.com/thehive/administration/cortex/add-a-cortex-server/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "splunk",
          "note": "A separately installed Splunk add-on turns saved-search results into TheHive alerts, with explicit field mapping and an alert action.",
          "sources": [
            {
              "label": "TheHive Splunk integration guide",
              "url": "https://docs.strangebee.com/thehive/how-to/splunk-integration/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "guardsix-siem",
      "name": "Guardsix SIEM",
      "maker": "Guardsix",
      "country": "Denmark",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Security information and event management product that correlates logs from hybrid infrastructure and provides detections, investigation context, and audit evidence.",
      "origin": "Guardsix traces its SIEM to Danish Logpoint; its published history records a Danish startup acquisition behind the first SIEM. Current shareholders and all engineering locations are not established here.",
      "originClass": "EU-developed",
      "facts": [
        "Collects logs across hybrid, on-premises, OT, and cloud environments.",
        "Supports self-hosted and air-gapped deployment.",
        "Formerly named Logpoint SIEM; the current Guardsix name is a rebrand."
      ],
      "sources": [
        {
          "label": "Current SIEM product",
          "url": "https://guardsix.com/product/siem"
        },
        {
          "label": "Rebrand FAQ",
          "url": "https://guardsix.com/rebrand-faq"
        },
        {
          "label": "Company history",
          "url": "https://guardsix.com/about-us"
        },
        {
          "label": "Guardsix EULA",
          "url": "https://guardsix.com/eula"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "Vendor sovereignty statements are marketing claims, not independently verified ownership or legal conclusions. Command Centre is an umbrella name.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://guardsix.com/product/siem",
          "checkedAt": "2026-10-10",
          "observation": "The current commercial SIEM page names the product, describes detections and log visibility, offers a demo and pricing context, and explicitly says self-hosted and air-gappable."
        },
        {
          "claims": [
            "identity",
            "maintenance"
          ],
          "url": "https://guardsix.com/rebrand-faq",
          "checkedAt": "2026-10-10",
          "observation": "The FAQ maps Logpoint SIEM to Guardsix SIEM and explains that Command Centre is a portfolio umbrella, not a separately purchasable product."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://guardsix.com/about-us",
          "checkedAt": "2026-10-10",
          "observation": "The company's own history places its founding in Denmark and says the original Logpoint SIEM followed acquisition of Danish startup Immune/LogEx."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://guardsix.com/eula",
          "checkedAt": "2026-10-10",
          "observation": "The current Guardsix EULA grants a paid nontransferable right to use SIEM and network-monitoring software, retains source and intellectual-property rights, and prohibits redistribution."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "gravityzone-xdr",
      "name": "Bitdefender GravityZone XDR",
      "maker": "Bitdefender",
      "country": "Romania",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Extended detection and response product that correlates endpoint, identity, network, and cloud signals to investigate incidents and coordinate response actions.",
      "origin": "Bitdefender identifies its Bucharest research and innovation hub and Romanian product R&D centers; the exact engineering split for GravityZone XDR is not public.",
      "originClass": "EU-developed",
      "facts": [
        "Correlates telemetry across multiple security sensors.",
        "Supports investigation and response from the GravityZone console.",
        "The XDR feature matrix labels XDR as GravityZone Cloud only."
      ],
      "sources": [
        {
          "label": "GravityZone XDR product",
          "url": "https://www.bitdefender.com/en-us/business/products/gravityzone-xdr"
        },
        {
          "label": "Official feature matrix",
          "url": "https://www.bitdefender.com/business/support/en/77212-376324-features-by-asset-type.html"
        },
        {
          "label": "Company and R&D history",
          "url": "https://www.bitdefender.com/en-us/company/"
        },
        {
          "label": "Business-solutions agreement",
          "url": "https://www.bitdefender.com/en-us/site/view/eula-business-solutions"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "Cloud only applies to XDR, not every GravityZone product. Cloud hosting geography and ultimate ownership are not established by the cited pages.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://www.bitdefender.com/en-us/business/products/gravityzone-xdr",
          "checkedAt": "2026-10-10",
          "observation": "Bitdefender's commercial XDR page describes cross-sensor incident detection, investigation, and response in GravityZone."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://www.bitdefender.com/business/support/en/77212-376324-features-by-asset-type.html",
          "checkedAt": "2026-10-10",
          "observation": "The official asset-type feature table marks GravityZone XDR as available in GravityZone Cloud only."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.bitdefender.com/en-us/company/",
          "checkedAt": "2026-10-10",
          "observation": "The company timeline connects its global headquarters and RED innovation hub to Bucharest, identifies Romanian innovation centers, and lists XDR in its product history."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.bitdefender.com/en-us/site/view/eula-business-solutions",
          "checkedAt": "2026-10-10",
          "observation": "The business-solutions master agreement explicitly covers purchased XDR sensors and reserves Bitdefender intellectual-property rights under customer licenses."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.bitdefender.com/business/support/en/77212-376324-features-by-asset-type.html",
          "checkedAt": "2026-10-10",
          "observation": "The official XDR feature matrix bears a 7 October 2026 modification date and continues to mark XDR as GravityZone Cloud only."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "acquire",
      "name": "Acquire",
      "maker": "Fox-IT",
      "country": "Netherlands",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Collects forensic artifacts from live systems or disk images into lightweight containers for triage and subsequent independent investigation.",
      "origin": "Dissect Team at Fox-IT publishes Acquire as a separate installable tool.",
      "originClass": "EU-developed",
      "facts": [
        "Live or image acquisition",
        "Artifact profiles",
        "Lightweight container output"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/fox-it/acquire"
        },
        {
          "label": "License",
          "url": "https://github.com/fox-it/acquire/blob/main/LICENSE"
        },
        {
          "label": "Developer organization",
          "url": "https://github.com/fox-it"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Part of the Dissect ecosystem but independently installable and usable for artifact collection; Fox-IT has UK group ownership.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/fox-it/acquire",
          "checkedAt": "2026-10-10",
          "observation": "README describes independent pip installation and acquisition of forensic artifacts from live hosts and disk images; requires privileged access for raw disks."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/fox-it/acquire/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license text is GNU Affero General Public License version 3."
        },
        {
          "claims": [
            "country",
            "maintenance"
          ],
          "url": "https://github.com/fox-it",
          "checkedAt": "2026-10-10",
          "observation": "Verified Dutch developer organization identifies NCC Group parent and shows Acquire updated in August 2026."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "adtimeline",
      "name": "ADTimeline",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "PowerShell utility that reconstructs partial timelines of Active Directory object changes from replication metadata for incident investigation and threat hunting.",
      "origin": "Published by ANSSI with French agency presentations of the method in 2019.",
      "originClass": "Institution-led",
      "facts": [
        "Builds partial timelines of selected Active Directory objects and attribute changes.",
        "Includes a Splunk app with dashboards for suspicious directory changes.",
        "Highlights group, ACL and privileged-account changes for analyst triage."
      ],
      "sources": [
        {
          "label": "Upstream README and installation",
          "url": "https://github.com/ANSSI-FR/ADTimeline"
        },
        {
          "label": "Upstream license",
          "url": "https://github.com/ANSSI-FR/ADTimeline/blob/master/LICENSE"
        },
        {
          "label": "ANSSI portfolio",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        }
      ],
      "license": "GPL-3.0",
      "maintenance": "Unknown",
      "scopeNote": "Replication metadata yields only a partial timeline; suspicious-change dashboards require analyst review. No recent upstream release or support guarantee was verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment",
            "license"
          ],
          "url": "https://github.com/ANSSI-FR/ADTimeline",
          "checkedAt": "2026-10-10",
          "observation": "README describes the PowerShell timeline script, partial AD replication metadata history, suspicious-activity Splunk dashboards and GPL-3.0 licensing."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI profile identifies this organization as a home for agency-developed projects."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/ADTimeline",
          "checkedAt": "2026-10-10",
          "observation": "The repository documents historical 2019 presentations but no recent release or explicit current maintenance commitment was verified."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "ail",
      "name": "AIL Framework",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Collect and analyse unstructured web, chat and file data to investigate information leaks and extract threat intelligence.",
      "origin": "The upstream README explicitly states that AIL was originally developed at CIRCL, the Computer Incident Response Center Luxembourg.",
      "originClass": "CSIRT-led",
      "facts": [
        "Keyword, regular-expression and YARA tracking with historical hunts.",
        "Extracts indicators and exports findings to MISP."
      ],
      "sources": [
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/ail-project/ail-framework"
        },
        {
          "label": "Software license",
          "url": "https://github.com/ail-project/ail-framework/blob/master/LICENSE"
        },
        {
          "label": "CIRCL project inventory",
          "url": "https://www.circl.lu/projects/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0-or-later",
      "maintenance": "Active",
      "scopeNote": "Crawlers, feeds and optional analysis services require separate configuration.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/ail-project/ail-framework",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes collect and analyse unstructured web, chat and file data to investigate information leaks and extract threat intelligence. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/ail-project/ail-framework",
          "checkedAt": "2026-10-10",
          "observation": "The upstream README explicitly states that AIL was originally developed at CIRCL, the Computer Incident Response Center Luxembourg."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/ail-project/ail-framework/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0-or-later."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/ail-project/ail-framework",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.circl.lu/projects/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL lists AIL among its open-source projects in Luxembourg."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/ail-project/ail-framework",
          "checkedAt": "2026-10-10",
          "observation": "The README applies version 3 or any later version to this software."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Joint Threat Analysis Network (JTAN)",
          "grantId": "2020-EU-IA-0260",
          "scope": "AIL identifies its instance synchronisation protocol, released in version 4.0 in December 2021, as JTAN-funded development. JTAN finished in June 2024.",
          "sources": [
            {
              "label": "AIL 4.0 release and JTAN-funded synchronisation",
              "url": "https://www.ail-project.org/blog/2021/12/02/AIL-v4.0.released/"
            },
            {
              "label": "CERT.LV project register: JTAN funding and completion",
              "url": "https://cert.gov.lv/en/about-us/international-projects"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "yara",
          "note": "Uses YARA trackers on collected content and supports retrospective YARA hunts over historical data.",
          "sources": [
            {
              "label": "AIL detection and tracking documentation",
              "url": "https://github.com/ail-project/ail-framework"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "misp",
          "note": "Exports AIL objects and investigations in MISP formats, with automatic exports configurable for selected detections and tags.",
          "sources": [
            {
              "label": "AIL export and integration documentation",
              "url": "https://github.com/ail-project/ail-framework"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "nextron-asgard",
      "name": "ASGARD Management Center",
      "maker": "Nextron Systems",
      "country": "Germany",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Incident-response console that deploys agents, schedules compromise scans, manages indicators, collects evidence, and executes response playbooks across endpoints.",
      "origin": "Nextron's German engineering team created the THOR/ASGARD product line and remains the named steward; exact locations of all current contributors are unpublished.",
      "originClass": "EU-developed",
      "facts": [
        "Controls endpoint scans and custom indicator checks.",
        "Runs response playbooks for quarantine, collection, and remote commands.",
        "Ships as a hardened virtual appliance."
      ],
      "sources": [
        {
          "label": "ASGARD product",
          "url": "https://www.nextron-systems.com/asgard-management-center/"
        },
        {
          "label": "Nextron history",
          "url": "https://www.nextron-systems.com/about/"
        },
        {
          "label": "ASGARD migration and license",
          "url": "https://knowledge.nextron-systems.com/management-center/migrating-the-management-to-a-new-server"
        },
        {
          "label": "Management Center support index",
          "url": "https://knowledge.nextron-systems.com/management-center"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "ASGARD is separately deployable and integrates THOR scanning. Vendor installer documentation requires a product-matched license; full current end-user rights were not publicly readable.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.nextron-systems.com/asgard-management-center/",
          "checkedAt": "2026-10-10",
          "observation": "Nextron describes ASGARD as a virtual appliance with endpoint agents, IOC management and response playbooks, offered as its commercial incident-response platform."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.nextron-systems.com/about/",
          "checkedAt": "2026-10-10",
          "observation": "The Nextron company history traces creation of the company's scanner and response software to its German founders and identifies German stewardship."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://knowledge.nextron-systems.com/management-center/migrating-the-management-to-a-new-server",
          "checkedAt": "2026-10-10",
          "observation": "Nextron's current self-hosted Management Center migration guide requires customer-portal access and a valid, activated license; public full license terms were not found."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://knowledge.nextron-systems.com/management-center",
          "checkedAt": "2026-10-10",
          "observation": "Nextron’s Management Center support index dates version 4.2.1 to 29 September 2026."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "bgp-ranking",
      "name": "BGP Ranking",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Aggregate malicious-activity observations by autonomous system number and inspect comparative rankings and historical changes.",
      "origin": "The project history describes CIRCL support from its 2010 origin and a rewrite within the CIRCL-led D4 project.",
      "originClass": "CSIRT-led",
      "facts": [
        "Ranks ASNs using configured malicious-activity datasets.",
        "Exposes historical ASN information through an API."
      ],
      "sources": [
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/D4-project/BGP-Ranking"
        },
        {
          "label": "Software license",
          "url": "https://github.com/D4-project/BGP-Ranking/blob/main/LICENSE"
        },
        {
          "label": "CIRCL service",
          "url": "https://www.circl.lu/services/bgp-ranking/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Rankings describe observations in the contributing datasets; they are not a complete assessment of an operator’s security.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/D4-project/BGP-Ranking",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes aggregate malicious-activity observations by autonomous system number and inspect comparative rankings and historical changes. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/D4-project/BGP-Ranking",
          "checkedAt": "2026-10-10",
          "observation": "The project history describes CIRCL support from its 2010 origin and a rewrite within the CIRCL-led D4 project."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/D4-project/BGP-Ranking/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/D4-project/BGP-Ranking",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-01-08. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "origin",
            "country",
            "deployment"
          ],
          "url": "https://www.circl.lu/services/bgp-ranking/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL provides the public BGP Ranking service and identifies its Luxembourg role."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "D4 Platform",
          "grantId": "2017-LU-IA-0099",
          "scope": "BGP Ranking identifies its late-2018 Python rewrite as work within the EU co-funded D4 project. This concerns that development phase, not all subsequent releases.",
          "sources": [
            {
              "label": "BGP Ranking upstream project history",
              "url": "https://github.com/D4-project/BGP-Ranking"
            },
            {
              "label": "HaDEA CEF cybersecurity action register (December 2021 status)",
              "url": "https://hadea.ec.europa.eu/system/files/2022-06/DSI%20fiche%20Cybersecurity_final_version.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "caploader",
      "name": "CapLoader",
      "maker": "NETRESEC AB",
      "country": "Sweden",
      "workflow": "Digital forensics",
      "format": "Commercial",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Indexes large PCAP collections, identifies network protocols, filters suspicious flows and exports selected packets for deeper forensic analysis.",
      "origin": "Netresec says it develops its network forensic products in Sweden, and its official CapLoader page identifies this product as one of those tools.",
      "originClass": "EU-developed",
      "facts": [
        "Large-PCAP flow indexing and filtering",
        "Protocol identification and suspicious-flow alerts",
        "Packet export and carving from memory or disk images"
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "CapLoader is a separate Windows desktop product with a 30-day restricted trial and commercial licenses; it is not the GPL NetworkMiner edition. The vendor publishes license options and feature limits, but not the complete current end-user contract. .NET Framework 4.8 is required.",
      "sources": [
        {
          "label": "Official product and feature matrix",
          "url": "https://www.netresec.com/?page=CapLoader"
        },
        {
          "label": "Swedish developer",
          "url": "https://www.netresec.com/?page=AboutNetresec"
        },
        {
          "label": "License and delivery options",
          "url": "https://www.netresec.com/files/CapLoader_Product-Specifications.pdf"
        },
        {
          "label": "2026 release record",
          "url": "https://www.netresec.com/?page=blog&tag=caploader"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.netresec.com/?page=CapLoader",
          "checkedAt": "2026-10-10",
          "observation": "Official CapLoader page identifies a Windows application for indexing/filtering large PCAP/PcapNG collections and exporting flows to analyzers; it documents protocol identification, packet carving and .NET requirement."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.netresec.com/?page=CapLoader",
          "checkedAt": "2026-10-10",
          "observation": "Vendor matrix distinguishes 30-day restricted trial from paid Professional edition and publishes price and feature differences; no open-source grant is made."
        },
        {
          "claims": [
            "country",
            "origin"
          ],
          "url": "https://www.netresec.com/?page=AboutNetresec",
          "checkedAt": "2026-10-10",
          "observation": "Netresec says it develops and sells network-forensic software and lists its Swedish address, supporting the Swedish product lead."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.netresec.com/files/CapLoader_Product-Specifications.pdf",
          "checkedAt": "2026-10-10",
          "observation": "Vendor PDF lists paid single-user and corporate licenses, three-year versus perpetual validity, and electronic delivery. It is a specification sheet, not a complete EULA."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.netresec.com/?page=CapLoader",
          "checkedAt": "2026-10-10",
          "observation": "Official CapLoader change log lists version 2.1 dated 27 May 2026 with TLS fingerprint reassembly improvements."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "cerebrate",
      "name": "Cerebrate",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Response coordination",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Maintain trusted contacts, organisational affiliations and public keys, and connect security tools across collaborating response teams.",
      "origin": "The upstream README credits CIRCL in Luxembourg and contributors; the CSIRTs Network tooling directory identifies CIRCL as project lead.",
      "originClass": "CSIRT-led",
      "facts": [
        "Synchronises contact information between Cerebrate instances.",
        "Provides APIs and tooling connections for community coordination."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/cerebrate-project/cerebrate"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://csirt-tooling-org.github.io/tooling-directory/"
        },
        {
          "label": "Software license",
          "url": "https://github.com/cerebrate-project/cerebrate/blob/main/LICENSE"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Supports response coordination and contact management; it is not an incident case-management system.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/cerebrate-project/cerebrate",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes maintain trusted contacts, organisational affiliations and public keys, and connect security tools across collaborating response teams. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://csirt-tooling-org.github.io/tooling-directory/",
          "checkedAt": "2026-10-10",
          "observation": "The upstream README credits CIRCL in Luxembourg and contributors; the CSIRTs Network tooling directory identifies CIRCL as project lead."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/cerebrate-project/cerebrate/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/cerebrate-project/cerebrate",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-09-23. This is an activity signal, not a support guarantee."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "MeliCERTes Facility",
          "grantId": "SMART2018/1024",
          "scope": "Cerebrate credits CEF co-funding through the MeliCERTes Facility for the project. SMART2018/1024 is a contract reference, and the source does not establish ongoing funding.",
          "sources": [
            {
              "label": "Cerebrate project funding statement",
              "url": "https://www.cerebrate-project.org/about.html"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "misp",
          "note": "Orchestrates connected MISP communities and can push sharing groups for restricted information exchange.",
          "sources": [
            {
              "label": "Cerebrate administration guide",
              "url": "https://doc.cerebrate-project.org/administration/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "convey",
      "name": "Convey",
      "maker": "CSIRT.cz / CZ.NIC",
      "country": "Czechia",
      "workflow": "Response coordination",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI",
        "Self-hosted"
      ],
      "description": "Transforms incident logs and tables into enriched, filtered or split reports that CSIRTs can send to responsible contacts through SMTP or OTRS.",
      "origin": "Upstream README explicitly says Convey is brought by CSIRT.cz within the Czech CZ.NIC organization.",
      "originClass": "CSIRT-led",
      "facts": [
        "Log/table conversion and enrichment",
        "Split by incident contact",
        "SMTP or OTRS delivery"
      ],
      "sources": [
        {
          "label": "Upstream README",
          "url": "https://github.com/CZ-NIC/convey"
        },
        {
          "label": "Actual license",
          "url": "https://github.com/CZ-NIC/convey/blob/main/LICENSE.txt"
        },
        {
          "label": "Official documentation",
          "url": "https://cz-nic.github.io/convey/"
        },
        {
          "label": "CZ.NIC association and Prague registration",
          "url": "https://podpora.nic.cz/en/about-the-association/"
        },
        {
          "label": "Repository activity",
          "url": "https://api.github.com/repos/CZ-NIC/convey"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "GPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Primarily a Python CLI with an optional web-service mode; it processes reports but is not a full case-management platform.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CZ-NIC/convey",
          "checkedAt": "2026-10-10",
          "observation": "README credits CSIRT.cz and documents pip installation, CLI/web-service modes, CSV/log conversion, filtering, splitting and SMTP/OTRS sending."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CZ-NIC/convey/blob/main/LICENSE.txt",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE.txt text is GNU General Public License version 3."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/CZ-NIC/convey",
          "checkedAt": "2026-10-10",
          "observation": "Upstream GitHub API reports nonarchived repository with code pushed 1 October 2026; this is activity, not a support guarantee."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://podpora.nic.cz/en/about-the-association/",
          "checkedAt": "2026-10-10",
          "observation": "CZ.NIC's current first-party association page identifies its Czech domain-registry and cybersecurity role, and registration at the Municipal Court in Prague."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "cortex",
      "name": "Cortex",
      "maker": "StrangeBee",
      "country": "France",
      "workflow": "Feed automation",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Observable analysis and response engine that runs analyzers and responders through a shared API, commonly connected to TheHive investigations.",
      "origin": "Fully developed and maintained by French company StrangeBee since 2018, according to its official documentation.",
      "originClass": "EU-developed",
      "facts": [
        "Automates observable analysis through analyzers.",
        "Runs responders as investigation actions.",
        "Licensed under AGPL-3.0 and deployable with packages, Docker or Kubernetes."
      ],
      "sources": [
        {
          "label": "Official Cortex documentation",
          "url": "https://docs.strangebee.com/cortex/"
        },
        {
          "label": "Upstream repository",
          "url": "https://github.com/TheHive-Project/Cortex"
        },
        {
          "label": "Upstream releases",
          "url": "https://github.com/TheHive-Project/Cortex/releases"
        },
        {
          "label": "StrangeBee SaaS legal agreement",
          "url": "https://strangebee.com/wp-content/uploads/2024/06/TheHive-Cloud-Platform-SaaS-Agreement-latest.pdf"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Cortex itself remains open source; that does not make current TheHive 5 open source. External analyzers can have separate terms.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "license",
            "deployment"
          ],
          "url": "https://docs.strangebee.com/cortex/",
          "checkedAt": "2026-10-10",
          "observation": "StrangeBee docs describe analyzers/responders, deployment methods and AGPL licensing, and say StrangeBee has fully developed and maintained Cortex since 2018."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://strangebee.com/wp-content/uploads/2024/06/TheHive-Cloud-Platform-SaaS-Agreement-latest.pdf",
          "checkedAt": "2026-10-10",
          "observation": "StrangeBee's legal agreement locates the developer in Paris, France."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/TheHive-Project/Cortex/releases",
          "checkedAt": "2026-10-10",
          "observation": "Upstream release list includes a Cortex 4.1.0 release in June 2026."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "thehive",
          "note": "TheHive calls Cortex analyzers for observable analysis and Cortex responders for response actions. Each analyzer or responder needs its own configuration.",
          "sources": [
            {
              "label": "Cortex overview and TheHive integration",
              "url": "https://docs.strangebee.com/cortex/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "originClass": "EU-developed",
      "format": "Commercial",
      "maintenance": "Active",
      "reviewedAt": "2026-10-10",
      "slug": "countercraft-platform",
      "name": "CounterCraft The Platform",
      "maker": "CounterCraft",
      "country": "Spain",
      "workflow": "Detection and monitoring",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Deception platform that deploys realistic decoy assets, records adversary interaction, and enriches resulting alerts with indicators and attack-technique context.",
      "origin": "CounterCraft's founders identify San Sebastián, Spain, as their research-and-development headquarters; group entities also operate in the US and UK.",
      "facts": [
        "Deploys decoy systems that mirror production assets.",
        "Records interactions and adds indicator, TTP and MITRE ATT&CK context.",
        "Product terms grant a limited license to access, install and deploy where applicable."
      ],
      "sources": [
        {
          "label": "The Platform product",
          "url": "https://www.countercraftsec.com/products/"
        },
        {
          "label": "Founders on Spanish R&D",
          "url": "https://www.countercraftsec.com/blog/letter-from-the-founders/"
        },
        {
          "label": "Product license terms",
          "url": "https://www.countercraftsec.com/terms-and-conditions-of-sale-of-products-and-provision-of-services/"
        },
        {
          "label": "On-premises deployment",
          "url": "https://www.countercraftsec.com/solutions/government-industry/"
        },
        {
          "label": "2026 platform update",
          "url": "https://www.countercraftsec.com/blog/countercraft-cyber-deception-platform-for-your-managed-security-services-portfolio/"
        }
      ],
      "license": "Proprietary",
      "scopeNote": "The public product page says cloud and hybrid environments are supported, but it does not establish that the management console is vendor-hosted SaaS. US and UK group entities exist; ultimate control and data residency require review.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.countercraftsec.com/products/",
          "checkedAt": "2026-10-10",
          "observation": "CounterCraft describes decoys/digital twins, real-time interaction data, enriched TTP/IoC context, and on-premises/cloud/hybrid configurations; the page does not establish SaaS tenancy."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.countercraftsec.com/blog/letter-from-the-founders/",
          "checkedAt": "2026-10-10",
          "observation": "Founders' signed 23 December 2021 letter locates the company's R&D headquarters in San Sebastián, Spain, and says they built the deception platform."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://www.countercraftsec.com/terms-and-conditions-of-sale-of-products-and-provision-of-services/",
          "checkedAt": "2026-10-10",
          "observation": "Sales terms define CounterCraft S.L., Inc. and Ltd. group entities, grant a nonexclusive, nontransferable limited-term license to access/install/deploy, prohibit copying and reverse engineering, and retain product IP."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://www.countercraftsec.com/solutions/government-industry/",
          "checkedAt": "2026-10-10",
          "observation": "Government solution page describes on-premises/air-gapped use of the platform without external connectivity; supports Self-hosted classification."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.countercraftsec.com/blog/countercraft-cyber-deception-platform-for-your-managed-security-services-portfolio/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor's 2019 platform article carries an editorial July 2026 update explicitly discussing continued MSSP use. This is active commercial commentary, not a dated code release."
        }
      ],
      "funding": [
        {
          "programme": "Horizon 2020",
          "project": "COUNTERCRAFT",
          "grantId": "767383",
          "scope": "The 2017–2019 SME Instrument action supported development of CounterCraft’s deception platform. This is historical product development support, not an endorsement of its current edition.",
          "sources": [
            {
              "label": "CORDIS grant record and project dates",
              "url": "https://cordis.europa.eu/project/id/767383"
            },
            {
              "label": "CounterCraft account of funded platform development",
              "url": "https://www.countercraftsec.com/blog/h2020/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "crowdsec",
      "name": "CrowdSec Security Engine",
      "maker": "CrowdSec",
      "country": "France",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Parses system and application logs to detect hostile behavior, generate local decisions and feed remediation components for blocking or challenging attackers.",
      "origin": "CrowdSec's own account says French Grand Défi Cyber funding supported development of its open-source software and expansion of its R&D team; the publisher is registered in Montrouge, France.",
      "originClass": "EU-developed",
      "facts": [
        "Log-based attack detection",
        "Local API decisions",
        "Optional remediation components"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/crowdsecurity/crowdsec"
        },
        {
          "label": "Actual Security Engine license",
          "url": "https://github.com/crowdsecurity/crowdsec/blob/master/LICENSE"
        },
        {
          "label": "Official product documentation",
          "url": "https://docs.crowdsec.net/"
        },
        {
          "label": "French publisher legal notice",
          "url": "https://www.crowdsec.net/legal-notices"
        },
        {
          "label": "French software R&D origin",
          "url": "https://www.crowdsec.net/blog/crowdsec-wins-grand-defi-cyber"
        },
        {
          "label": "Software versus data licensing FAQ",
          "url": "https://www.crowdsec.net/faq"
        },
        {
          "label": "Current upstream release",
          "url": "https://github.com/crowdsecurity/crowdsec/releases/tag/v1.8.1"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "MIT",
      "maintenance": "Active",
      "scopeNote": "The self-hosted Security Engine is MIT-licensed; CrowdSec-supplied community blocklist and other vendor threat data have separate terms restricting redistribution, and the optional hosted Console is a distinct service. Blocking requires a configured remediation component; the engine alone detects and makes local decisions. The France label reflects documented French R&D and the French SAS legal notice, not every current contributor, data host or ultimate owner.",
      "evidence": [
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.crowdsec.net/blog/crowdsec-wins-grand-defi-cyber",
          "checkedAt": "2026-10-10",
          "observation": "CrowdSec's September 2021 account says France's Grand Défi Cyber funded development of essential components of the open-source software and planned expansion of its existing R&D team. This is historical French development evidence, not a claim that all current contributors are French."
        },
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/crowdsecurity/crowdsec",
          "checkedAt": "2026-10-10",
          "observation": "Upstream repository describes installable IDS/IPS, WAF and bot detection software with detection scenarios for brute force, port scans and web scans on Linux, Windows, Docker and Kubernetes."
        },
        {
          "claims": [
            "capabilities",
            "deployment"
          ],
          "url": "https://docs.crowdsec.net/",
          "checkedAt": "2026-10-10",
          "observation": "Official documentation distinguishes the server-installed Security Engine, which parses logs and applies scenarios, from optional hosted Console, blocklists, and remediation integrations."
        },
        {
          "claims": [
            "license",
            "origin"
          ],
          "url": "https://github.com/crowdsecurity/crowdsec/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual root LICENSE contains the MIT grant and CrowdSec copyright; it governs the software repository, not the separately licensed threat data."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.crowdsec.net/faq",
          "checkedAt": "2026-10-10",
          "observation": "CrowdSec's FAQ explicitly says the software is MIT-licensed but data received through it is subject to a separate EULA with redistribution and marketing restrictions."
        },
        {
          "claims": [
            "country",
            "origin"
          ],
          "url": "https://www.crowdsec.net/legal-notices",
          "checkedAt": "2026-10-10",
          "observation": "Publisher's legal notice identifies CrowdSec SAS and its registered office in Montrouge, France; this is paired with the official code repository, rather than treated as proof of all engineering locations."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/crowdsecurity/crowdsec/releases/tag/v1.8.1",
          "checkedAt": "2026-10-10",
          "observation": "The upstream v1.8.1 release is marked latest and dated 3 September on the release page during the 2026 release series; release activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "misp",
          "note": "The optional MISP Feed Generator polls CrowdSec decisions and exposes them as a MISP feed over HTTP(S). Requires a CrowdSec Local API key and a separately configured feed subscription in MISP.",
          "sources": [
            {
              "label": "CrowdSec MISP Feed Generator",
              "url": "https://docs.crowdsec.net/u/bouncers/misp-feed-generator/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "cve-search",
      "name": "CVE Search",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Import vulnerability and platform-enumeration data into a local database, then search it through command-line, web and API interfaces.",
      "origin": "CIRCL’s published tooling document identifies CIRCL as the CSIRT lead for CVE Search. Its current inventory still includes the project, which also has independent contributors.",
      "originClass": "CSIRT-led",
      "facts": [
        "Supports local CVE and CPE lookups.",
        "Provides searchable vulnerability records through a web interface and API."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/cve-search/cve-search"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/CIRCL/compliance/blob/master/csirt-tooling-best-practices/index.md"
        },
        {
          "label": "Software license",
          "url": "https://github.com/cve-search/cve-search/blob/master/LICENSE"
        },
        {
          "label": "Current project inventory",
          "url": "https://www.circl.lu/projects/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "CIRCL’s former public CVE Search service has been superseded by Vulnerability-Lookup. This record covers the separately maintained self-hosted project.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/cve-search/cve-search",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes import vulnerability and platform-enumeration data into a local database, then search it through command-line, web and API interfaces. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/CIRCL/compliance/blob/master/csirt-tooling-best-practices/index.md",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL’s published tooling document identifies CIRCL as the CSIRT lead for CVE Search. Its current inventory still includes the project, which also has independent contributors."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/cve-search/cve-search/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/cve-search/cve-search",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-09-30. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.circl.lu/projects/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL still includes CVE Search in its current project inventory."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "cyberwatch-vulnerability-manager",
      "name": "Cyberwatch Vulnerability Manager",
      "maker": "Cyberwatch",
      "country": "France",
      "workflow": "Exposure discovery",
      "format": "Commercial",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Vulnerability management software that discovers assets, scans for affected technologies, prioritizes findings using context, and supports patch decisions and remediation.",
      "origin": "Built by Cyberwatch’s product team in France; the company identifies itself as a Framatome Cybersecurity subsidiary since 2022.",
      "originClass": "EU-developed",
      "facts": [
        "Maps assets and continuously detects relevant published vulnerabilities.",
        "Prioritizes risk using business context and supports remediation.",
        "Runs within customer-controlled local or cloud infrastructure."
      ],
      "sources": [
        {
          "label": "Vulnerability Manager product",
          "url": "https://cyberwatch.fr/en/our-platform/vulnerability-manager/"
        },
        {
          "label": "Platform and deployment",
          "url": "https://cyberwatch.fr/en/"
        },
        {
          "label": "French development team",
          "url": "https://cyberwatch.fr/en/about/"
        },
        {
          "label": "Cyberwatch deployment and license-file documentation",
          "url": "https://docs.cyberwatch.com/help/en/deploy/standard/swarm/deploy/"
        },
        {
          "label": "September 2026 product update",
          "url": "https://cyberwatch.fr/actualite/cyber-resilience-act-les-premieres-obligations-entrent-en-application/"
        }
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Commercial on-premises product; the vendor’s compliance and patch modules are not counted as independent tools. Customer-controlled cloud installation is not vendor SaaS. The documented license file controls access to the vulnerability database; application-code rights were not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://cyberwatch.fr/en/our-platform/vulnerability-manager/",
          "checkedAt": "2026-10-10",
          "observation": "Product page documents vulnerability discovery, mapping, prioritization and remediation support."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://cyberwatch.fr/en/",
          "checkedAt": "2026-10-10",
          "observation": "The vendor says software deploys in a customer-controlled local or cloud infrastructure and can run agentless/offline scans."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://cyberwatch.fr/en/about/",
          "checkedAt": "2026-10-10",
          "observation": "Cyberwatch says its team develops on-premises commercial products, lists its software stack and Paris/Massy addresses, and identifies its Framatome Cybersecurity relationship."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://cyberwatch.fr/actualite/cyber-resilience-act-les-premieres-obligations-entrent-en-application/",
          "checkedAt": "2026-10-10",
          "observation": "Cyberwatch published a September 2026 product-focused update discussing vulnerability and patch-management capabilities."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://docs.cyberwatch.com/help/en/deploy/standard/swarm/deploy/",
          "checkedAt": "2026-10-10",
          "observation": "Official deployment instructions require a vendor-supplied license file to access the vulnerability database. This does not establish the application-code rights, and full product license terms were not publicly verified."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "originClass": "EU-developed",
      "format": "Commercial",
      "maintenance": "Active",
      "reviewedAt": "2026-10-10",
      "slug": "cyscale-cloud-platform",
      "name": "Cyscale Cloud Platform",
      "maker": "Cyscale Limited",
      "country": "Romania",
      "workflow": "Exposure discovery",
      "deployment": [
        "SaaS"
      ],
      "description": "Cloud security platform linking vulnerable software, exposed workloads, identities and ownership so teams can prioritize and route remediation.",
      "origin": "Cyscale advertises Romanian engineering and product roles that build the platform, while the contracting company is registered in England and Wales.",
      "facts": [
        "Maps vulnerable packages and images to deployed cloud workloads.",
        "Adds internet exposure, reachability and ownership context to triage.",
        "Delivers the platform by SaaS under Cyscale Limited's EULA."
      ],
      "sources": [
        {
          "label": "Cloud vulnerability management",
          "url": "https://cyscale.com/products/cloud-vulnerability-management/"
        },
        {
          "label": "Romanian backend engineering role",
          "url": "https://cyscale.com/careers/backend-developer/"
        },
        {
          "label": "Romanian product role",
          "url": "https://cyscale.com/careers/product-manager/"
        },
        {
          "label": "European build statement",
          "url": "https://cyscale.com/cloud-security-made-in-europe/"
        },
        {
          "label": "Company registration",
          "url": "https://cyscale.com/contact-us/"
        },
        {
          "label": "Platform EULA",
          "url": "https://cyscale.com/resources/Cyscale-EULA.pdf"
        },
        {
          "label": "2026 platform availability",
          "url": "https://cyscale.com/blog/cyscale-aws-marketplace-cnapp-procurement-security-operations/"
        }
      ],
      "license": "Proprietary",
      "scopeNote": "Romania is the evidenced product-development location, not the licensor's country: Cyscale Limited is registered in England and Wales, its EULA selects Israeli law, and EU ownership or exclusive EU hosting is not established.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://cyscale.com/products/cloud-vulnerability-management/",
          "checkedAt": "2026-10-10",
          "observation": "The product page describes correlated packages, images and deployed workloads, exposure-aware triage and remediation ownership within Cyscale's platform."
        },
        {
          "claims": [
            "origin",
            "country",
            "deployment"
          ],
          "url": "https://cyscale.com/careers/backend-developer/",
          "checkedAt": "2026-10-10",
          "observation": "Cyscale's Romania engineering job explicitly assigns development of new Cyscale backend platform features and calls the Cyscale Cloud Platform a SaaS product; this evidences Romanian product engineering, not exclusive development or control."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://cyscale.com/careers/product-manager/",
          "checkedAt": "2026-10-10",
          "observation": "Current product-manager opening lists Romania and asks the hire to use and test the Cyscale product; it supports Romanian product stewardship alongside the engineering role."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://cyscale.com/cloud-security-made-in-europe/",
          "checkedAt": "2026-10-10",
          "observation": "Cyscale markets the platform as Europe-built; this general statement is qualified by the specific Romania engineering evidence and the UK company record."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://cyscale.com/contact-us/",
          "checkedAt": "2026-10-10",
          "observation": "Contact page identifies Cyscale Limited as registered in England and Wales; this is the contracting company, not the editorial country of documented engineering."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://cyscale.com/resources/Cyscale-EULA.pdf",
          "checkedAt": "2026-10-10",
          "observation": "EULA grants a limited, nonexclusive, nontransferable SaaS access license, bars copying/modification/reverse engineering, retains platform IP, and selects Israeli governing law."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://cyscale.com/blog/cyscale-aws-marketplace-cnapp-procurement-security-operations/",
          "checkedAt": "2026-10-10",
          "observation": "4 March 2026 vendor announcement says the platform became available through AWS Marketplace; it is evidence of active commercial distribution."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "d4",
      "name": "D4",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Build a distributed sensor network that collects security telemetry and dispatches it to configured decoders and analysers.",
      "origin": "The D4 project identifies CIRCL, Luxembourg House of Cybersecurity, Luxembourg, as its project contact and organisation.",
      "originClass": "CSIRT-led",
      "facts": [
        "Registers and manages sensors through a central server.",
        "Carries telemetry streams to downstream decoders and analysis queues."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/D4-project/d4-core"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://www.d4-project.org/about.html"
        },
        {
          "label": "Software license",
          "url": "https://github.com/D4-project/d4-core/blob/master/LICENSE"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "This entry groups the core server and sensor transport. Detection depends on the sensors and analysers deployed.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/D4-project/d4-core",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes build a distributed sensor network that collects security telemetry and dispatches it to configured decoders and analysers. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.d4-project.org/about.html",
          "checkedAt": "2026-10-10",
          "observation": "The D4 project identifies CIRCL, Luxembourg House of Cybersecurity, Luxembourg, as its project contact and organisation."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/D4-project/d4-core/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/D4-project/d4-core",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-07-14. This is an activity signal, not a support guarantee."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "D4 Platform",
          "grantId": "2017-LU-IA-0099",
          "scope": "The D4 sensor and analysis platform was supported by this action from November 2018 to April 2021. The completed grant does not establish funding for every later D4 component.",
          "sources": [
            {
              "label": "D4 project description and funding",
              "url": "https://www.d4-project.org/about.html"
            },
            {
              "label": "HaDEA CEF cybersecurity action register (December 2021 status)",
              "url": "https://hadea.ec.europa.eu/system/files/2022-06/DSI%20fiche%20Cybersecurity_final_version.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "dcso-tie",
      "name": "DCSO Threat Intelligence Engine",
      "maker": "DCSO Deutsche Cyber-Sicherheitsorganisation GmbH",
      "country": "Germany",
      "workflow": "Threat intelligence",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Aggregates selected intelligence feeds, normalizes and contextualizes indicators, then exposes tailored IoC collections through an authenticated API.",
      "origin": "DCSO describes TIE as its own platform and operates the threat-intelligence service from its Berlin-based GmbH; its team performs research and feed integration.",
      "originClass": "EU-developed",
      "facts": [
        "Indicator aggregation and contextualization",
        "Tailored API feeds and STIX/TAXII access",
        "DCSO analyst and sensor enrichment"
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "TIE is a provider-operated, contracted API/feed service, not downloadable open-source software or a free public endpoint. DCSO may combine its own, public, commercial and customer-licensed intelligence, so access to underlying data has source-specific conditions. Public TIE documentation does not publish a complete customer license or promise customer-hosted deployment.",
      "sources": [
        {
          "label": "TIE service description",
          "url": "https://dcso.de/en/service/threat-intelligence/"
        },
        {
          "label": "TIE API v2 documentation",
          "url": "https://docs.dcso.de/docs/tie/v2/index.html"
        },
        {
          "label": "DCSO and Berlin office",
          "url": "https://dcso.de/en/"
        },
        {
          "label": "DCSO 2025 threat-intelligence whitepaper",
          "url": "https://dcso.de/wp-content/uploads/2025/10/TI_Whitepaper_DCSO.pdf"
        },
        {
          "label": "December 2025 TIE service Q&A",
          "url": "https://dcso.de/webcast-aufzeichnung-qualitaet-und-schnelligkeit/"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://dcso.de/en/service/threat-intelligence/",
          "checkedAt": "2026-10-10",
          "observation": "DCSO says its TIE aggregates, normalizes and contextualizes IOCs from chosen sources and makes tailored feeds available through its API as part of its threat-intelligence service."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://docs.dcso.de/docs/tie/v2/index.html",
          "checkedAt": "2026-10-10",
          "observation": "DCSO documents a remote TAXII/STIX 2.1 API with collections and authenticated consumer access; it does not provide customer-hosted TIE installation."
        },
        {
          "claims": [
            "origin",
            "license"
          ],
          "url": "https://dcso.de/wp-content/uploads/2025/10/TI_Whitepaper_DCSO.pdf",
          "checkedAt": "2026-10-10",
          "observation": "DCSO calls TIE its own platform for integrating DCSO, public and commercial data into customer environments; the document markets a service but does not contain complete software or feed-license terms."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://dcso.de/en/",
          "checkedAt": "2026-10-10",
          "observation": "DCSO names its German GmbH and Berlin office in the site footer; paired with its own-platform statement this supports a German product lead, not all contributor locations."
        },
        {
          "claims": [
            "maintenance",
            "license"
          ],
          "url": "https://dcso.de/webcast-aufzeichnung-qualitaet-und-schnelligkeit/",
          "checkedAt": "2026-10-10",
          "observation": "Dated 18 December 2025 vendor Q&A explains live TIE source harmonization, standards integration and external feed licensing; it shows continuing operation within the review window, not a support guarantee."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "decode",
      "name": "DECODE",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Standalone analysis tool that ranks anomalous Windows PE files from DFIR ORC metadata and exports triage results as CSV or PDF.",
      "origin": "Developed and managed by ANSSI, the French national cybersecurity agency, for analysis of DFIR ORC collection output.",
      "originClass": "Institution-led",
      "facts": [
        "Ranks Windows PE files by metadata-based anomaly scores.",
        "Accepts DFIR ORC NTFSInfo CSV files or archives.",
        "Exports CSV and PDF views, with an optional Splunk dashboard."
      ],
      "sources": [
        {
          "label": "Upstream DECODE README",
          "url": "https://github.com/ANSSI-FR/DECODE"
        },
        {
          "label": "Upstream BSD-3-Clause license",
          "url": "https://github.com/ANSSI-FR/DECODE/blob/main/LICENSE"
        },
        {
          "label": "ANSSI open-source portfolio",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        }
      ],
      "license": "BSD-3-Clause",
      "maintenance": "Unknown",
      "scopeNote": "Requires DFIR ORC collection output; anomaly ranks are triage leads, not confirmed malicious verdicts. No recent release or explicit maintenance policy was verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/ANSSI-FR/DECODE",
          "checkedAt": "2026-10-10",
          "observation": "Upstream README calls DECODE a stand-alone tool, names ANSSI as manager, documents pip installation and machine_analysis CLI, and describes metadata-based PE anomaly ranking with CSV/PDF/Splunk outputs."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/ANSSI-FR/DECODE/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license text is BSD 3-Clause with ANSSI copyright for 2020–2024."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI describes its organization as publishing projects developed by the French national cybersecurity agency."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/DECODE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream repository shows no release listing or explicit present-day maintenance policy; the dated license copyright ends in 2024, so maintenance is Unknown rather than assumed active."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "dfir-orc",
      "name": "DFIR ORC",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Windows forensic acquisition utility for collecting incident response artefacts from hosts into structured archives for later analysis and evidence handling.",
      "origin": "Managed by ANSSI, the French cybersecurity agency, with the repository explicitly naming ANSSI stewardship.",
      "originClass": "Institution-led",
      "facts": [
        "Collects forensic artefacts from Microsoft Windows systems.",
        "Packages collections through a configurable Windows executable.",
        "Current upstream release is v10.4.0."
      ],
      "sources": [
        {
          "label": "Upstream repository",
          "url": "https://github.com/DFIR-ORC/dfir-orc"
        },
        {
          "label": "License text",
          "url": "https://github.com/DFIR-ORC/dfir-orc/blob/main/LICENSE.txt"
        },
        {
          "label": "Release history",
          "url": "https://github.com/DFIR-ORC/dfir-orc/releases"
        },
        {
          "label": "ANSSI open-source portfolio",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        }
      ],
      "license": "LGPL-2.1",
      "maintenance": "Active",
      "scopeNote": "Windows-only collection tool. Its release notes concern forensic acquisition; no claim of evidentiary integrity certification is implied.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/DFIR-ORC/dfir-orc",
          "checkedAt": "2026-10-10",
          "observation": "The repository describes Windows forensic artefact collection, documents building the executable, and expressly says ANSSI manages the project."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/DFIR-ORC/dfir-orc/blob/main/LICENSE.txt",
          "checkedAt": "2026-10-10",
          "observation": "Upstream license is GNU Lesser General Public License 2.1."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/DFIR-ORC/dfir-orc/releases",
          "checkedAt": "2026-10-10",
          "observation": "Release v10.4.0 was published 8 October 2026 with collection and upload changes."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI organization profile identifies its repositories as agency-developed projects and its French national agency role."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": [
        {
          "id": "yara",
          "note": "Uses configured YARA rules for file matching. In the documented 10.3.x scanner, blocks currently falls back to file-mapping behavior for compatibility; legacy block scanning can miss whole-file matches. Timeouts and scan-method limits apply.",
          "sources": [
            {
              "label": "DFIR ORC YARA scanner configuration",
              "url": "https://dfir-orc.github.io/release/10.3.x/configuring_yara.html"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "dfir-iris",
      "name": "DFIR-IRIS",
      "maker": "DFIR-IRIS community",
      "country": "France",
      "workflow": "Response coordination",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Collaborative incident response workspace for sharing technical investigation details, organizing cases, and tracking evidence and timelines across responders.",
      "origin": "Originated inside the Airbus Cybersecurity commercial CSIRT in France in 2019; now maintained by the independent DFIR-IRIS project.",
      "originClass": "CSIRT-led",
      "facts": [
        "Multi-user web workspace shares investigation details and cases.",
        "Stable v2.4.29 remains recommended for production while v3 is beta.",
        "The umbrella project is licensed LGPL-3.0."
      ],
      "sources": [
        {
          "label": "Project founding account",
          "url": "https://blog.dfir-iris.org/blog/iris_mid_year_summary/"
        },
        {
          "label": "Upstream repository and installation",
          "url": "https://github.com/dfir-iris/iris-web"
        },
        {
          "label": "License text",
          "url": "https://github.com/dfir-iris/iris-web/blob/master/LICENSE.txt"
        },
        {
          "label": "Latest stable release",
          "url": "https://github.com/dfir-iris/iris-web/releases/tag/v2.4.29"
        }
      ],
      "license": "LGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "The current v3 branch is beta and the README advises using stable v2.4.29 for production; the preview deployment is only a demonstration.",
      "evidence": [
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://blog.dfir-iris.org/blog/iris_mid_year_summary/",
          "checkedAt": "2026-10-10",
          "observation": "The project team recounts that the idea and first implementation arose within the Airbus Cybersecurity commercial CSIRT in France in 2019, with open release supported by Airbus in 2021."
        },
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/dfir-iris/iris-web",
          "checkedAt": "2026-10-10",
          "observation": "Current umbrella README describes a collaborative investigation web platform, its Docker Compose deployment, and the three coordinated v3 repositories."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/dfir-iris/iris-web/blob/master/LICENSE.txt",
          "checkedAt": "2026-10-10",
          "observation": "Upstream license text is GNU Lesser General Public License version 3."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/dfir-iris/iris-web/releases/tag/v2.4.29",
          "checkedAt": "2026-10-10",
          "observation": "The latest stable release page lists v2.4.29 with security and UI fixes; the README separately identifies the v3 branch as beta."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": [
        {
          "id": "misp",
          "note": "The bundled IrisMISP module enriches supported IOC types using one configured MISP instance. It needs configuration before use; automatic lookups on IOC creation or update are opt-in.",
          "sources": [
            {
              "label": "IRIS MISP module configuration",
              "url": "https://docs.dfir-iris.org/operations/modules/natives/IrisMISP/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "dfir-o365rc",
      "name": "DFIR-O365RC",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "PowerShell forensic collection module that retrieves Microsoft 365 audit events and Entra sign-in logs for post-incident investigations.",
      "origin": "Published under ANSSI’s official repository and described as an incident-response forensic tool.",
      "originClass": "Institution-led",
      "facts": [
        "Collects Microsoft 365 Unified Audit Log and Entra sign-in/audit records as JSON.",
        "Offers Docker and PowerShell installation.",
        "Can optionally retrieve Azure Monitor and Azure DevOps audit logs."
      ],
      "sources": [
        {
          "label": "Upstream README and requirements",
          "url": "https://github.com/ANSSI-FR/DFIR-O365RC"
        },
        {
          "label": "Upstream GPL license",
          "url": "https://github.com/ANSSI-FR/DFIR-O365RC/blob/main/LICENSE"
        },
        {
          "label": "ANSSI portfolio",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        }
      ],
      "license": "GPL-3.0",
      "maintenance": "Unknown",
      "scopeNote": "Requires appropriate tenant permissions and Microsoft licensing; the upstream warns its optional Purview retrieval path remains beta/unusable and this is not a live SIEM.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/ANSSI-FR/DFIR-O365RC",
          "checkedAt": "2026-10-10",
          "observation": "README defines forensic collection functions, JSON output, Docker and PowerShell installation, and optional Azure sources, while explicitly distinguishing collection from real-time monitoring."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/ANSSI-FR/DFIR-O365RC/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Repository license text is GPL version 3."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI describes its GitHub repositories as agency-developed open-source projects."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/DFIR-O365RC",
          "checkedAt": "2026-10-10",
          "observation": "The README documents a v2.0.0 authentication update in August 2024, but no recent release or explicit current maintenance policy was verified."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://github.com/ANSSI-FR/DFIR-O365RC",
          "checkedAt": "2026-10-10",
          "observation": "README lists Microsoft 365/Entra permissions and an Entra ID P1 requirement for Entra log retrieval."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "dfir-ogre",
      "name": "DFIR-OGRE",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Command-line parser that extracts Windows artefacts from DFIR ORC archives into structured records for analysis in search and analytics systems.",
      "origin": "Managed by ANSSI and announced in its official open-source portfolio in May 2026.",
      "originClass": "Institution-led",
      "facts": [
        "Parses browser, file-system, process and Windows event artefacts in ORC archives.",
        "Outputs structured data for Splunk, ELK or other stores.",
        "Upstream README explicitly labels the project beta."
      ],
      "sources": [
        {
          "label": "Upstream repository and beta notice",
          "url": "https://github.com/ANSSI-FR/dfir-ogre"
        },
        {
          "label": "Official documentation",
          "url": "https://anssi-fr.github.io/dfir-ogre-documentation/"
        },
        {
          "label": "ANSSI portfolio and publication date",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        }
      ],
      "license": "Apache-2.0",
      "maintenance": "Experimental",
      "scopeNote": "Beta software with potentially breaking changes and unstabilized parsers; requires DFIR ORC archive input and a separate Windows parser plugin repository.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities",
            "license",
            "deployment",
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/dfir-ogre",
          "checkedAt": "2026-10-10",
          "observation": "The ANSSI repository describes the command-line parser, archive input, supported artefact groups, installation, Apache-2.0 license, and its explicit beta state."
        },
        {
          "claims": [
            "origin",
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI portfolio records publication of DFIR-OGRE on 21 May 2026 and identifies it as an agency project."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://anssi-fr.github.io/dfir-ogre-documentation/",
          "checkedAt": "2026-10-10",
          "observation": "Project documentation covers local command-line use and configuring parsers for ORC archives."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "dfirtrack",
      "name": "DFIRTrack",
      "maker": "Mathias Stuhlmacher / DFIRTrack project",
      "country": "Germany",
      "workflow": "Response coordination",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Tracks affected systems, incidents and investigative tasks in larger digital forensics and incident response cases through a shared web interface.",
      "origin": "The lead contributor and copyright holder Mathias Stuhlmacher publicly lists Germany as his location; this does not establish every contributor's country.",
      "originClass": "EU-developed",
      "facts": [
        "System-based incident tracking",
        "Shared case and task records",
        "Ubuntu, Docker and Ansible installation routes"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/dfirtrack/dfirtrack"
        },
        {
          "label": "Actual MIT license",
          "url": "https://github.com/dfirtrack/dfirtrack/blob/master/LICENSE"
        },
        {
          "label": "Lead maintainer profile",
          "url": "https://github.com/stuhli"
        },
        {
          "label": "Upstream branch activity",
          "url": "https://github.com/dfirtrack/dfirtrack/commits/master.atom"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "MIT",
      "maintenance": "Active",
      "scopeNote": "The upstream README explicitly warns against exposing DFIRTrack on a publicly available server. The German country label is tied to its evidenced lead maintainer.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/dfirtrack/dfirtrack",
          "checkedAt": "2026-10-10",
          "observation": "README presents a system-based incident tracking application for large cases and documents Ubuntu, Docker and Ansible setup; it warns against public-facing deployment."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/stuhli",
          "checkedAt": "2026-10-10",
          "observation": "Lead contributor's self-reported profile identifies Mathias Stuhlmacher and Germany; used only for lead origin."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/dfirtrack/dfirtrack/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual root license contains MIT License text with Mathias Stuhlmacher copyright."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/dfirtrack/dfirtrack/commits/master.atom",
          "checkedAt": "2026-10-10",
          "observation": "Upstream default-branch Atom feed records a commit on 2026-01-13; branch activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "dissect",
      "name": "Dissect",
      "maker": "Fox-IT",
      "country": "Netherlands",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Opens forensic images and file collections for cross-platform artifact analysis through a modular Python framework and command-line investigation tools.",
      "origin": "Upstream identifies Dutch Fox-IT's Dissect Team as developer.",
      "originClass": "EU-developed",
      "facts": [
        "Image and filesystem parsing",
        "target-query and target-shell",
        "Modular artifact parsers"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/fox-it/dissect"
        },
        {
          "label": "License",
          "url": "https://github.com/fox-it/dissect/blob/main/LICENSE"
        },
        {
          "label": "Developer organization",
          "url": "https://github.com/fox-it"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Fox-IT is part of UK-based NCC Group; Dutch development does not imply EU ownership or hosting. Count the suite once, not its parser modules.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/fox-it/dissect",
          "checkedAt": "2026-10-10",
          "observation": "README credits Fox-IT's Dissect Team and documents installation, artifact analysis and target-query/target-shell CLI."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/fox-it/dissect/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license text is GNU Affero General Public License version 3."
        },
        {
          "claims": [
            "country",
            "maintenance"
          ],
          "url": "https://github.com/fox-it",
          "checkedAt": "2026-10-10",
          "observation": "Verified developer organization states Netherlands, NCC Group affiliation and a repository update on 9 October 2026."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "yara",
          "note": "The yara plugin scans files inside a forensic target using local rule files. Files above the configured maximum size are skipped; rule checking and decompression are configurable.",
          "sources": [
            {
              "label": "Dissect YARA plugin",
              "url": "https://docs.dissect.tools/en/latest/plugins/yara.html"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "drakvuf-sandbox",
      "name": "DRAKVUF Sandbox",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Malware analysis",
      "format": "Source available",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Runs automated agentless malware analysis in virtualized guests and exposes a web interface for submissions and examination of results.",
      "origin": "Upstream maintainers use CERT.PL contact and credit CERT Polska among creators.",
      "originClass": "CSIRT-led",
      "facts": [
        "Hypervisor-level analysis",
        "Web upload and results",
        "Installer provided"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CERT-Polska/drakvuf-sandbox"
        },
        {
          "label": "License",
          "url": "https://github.com/CERT-Polska/drakvuf-sandbox/blob/master/LICENSE"
        },
        {
          "label": "CERT Polska organization",
          "url": "https://github.com/CERT-Polska"
        },
        {
          "label": "Upstream activity metadata",
          "url": "https://api.github.com/repos/CERT-Polska/drakvuf-sandbox"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Custom: GPL-2.0 with DRAKVUF Sandbox clarifications and exceptions",
      "maintenance": "Active",
      "scopeNote": "The custom GPL-2.0-derived license has additional clarifications and exceptions, so standard open-source compatibility is unverified. Requires Intel VT-x/EPT and supported Linux/Windows guests; upstream says cloud VM support is unavailable and maintenance is difficult.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CERT-Polska/drakvuf-sandbox",
          "checkedAt": "2026-10-10",
          "observation": "README calls it automated black-box analysis, documents web submission, installer, hardware/guest requirements and maintainer contact at cert.pl."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/drakvuf-sandbox/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE states GPL version 2 only with explicit nonstandard clarifications and exceptions, including interpretations of derivative works; it permits alternative proprietary licensing by agreement. Source is inspectable, but standard open-source compatibility is unverified."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/CERT-Polska",
          "checkedAt": "2026-10-10",
          "observation": "Verified CERT Polska organization is located in Warsaw, Poland."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/CERT-Polska/drakvuf-sandbox",
          "checkedAt": "2026-10-10",
          "observation": "Upstream GitHub API reports nonarchived repository with code pushed 2026-10-09; an activity signal, not a support guarantee."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Joint Threat Analysis Network (JTAN)",
          "grantId": "2020-EU-IA-0260",
          "scope": "JTAN supported DRAKVUF Sandbox installation, maintenance and Intel Processor Trace work. The project finished in June 2024.",
          "sources": [
            {
              "label": "CERT Polska 2024 report, JTAN and FETTA sections (printed pages 75–82)",
              "url": "https://cert.pl/uploads/docs/Report_CP_2024.pdf"
            },
            {
              "label": "CERT.LV project register: JTAN funding and completion",
              "url": "https://cert.gov.lv/en/about-us/international-projects"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "droid",
      "name": "droid",
      "maker": "CERT-EU",
      "country": "Belgium",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Validates and transforms Sigma detection rules, then searches or deploys them across compatible SIEM and EDR environments through a command-line workflow.",
      "origin": "The project is published by CERT-EU, the EU institutions' computer emergency response team based in Brussels, Belgium.",
      "originClass": "CSIRT-led",
      "facts": [
        "Sigma detection-as-code workflow",
        "Rule validation and transformation",
        "SIEM and EDR query or deployment"
      ],
      "sources": [
        {
          "label": "CERT-EU upstream project",
          "url": "https://github.com/certeu/droid"
        },
        {
          "label": "Official installation documentation",
          "url": "https://certeu.github.io/droid-docs/getting-started/"
        },
        {
          "label": "Actual EUPL license",
          "url": "https://github.com/certeu/droid/blob/main/LICENSE"
        },
        {
          "label": "CERT-EU identity",
          "url": "https://www.cert.europa.eu/about-us"
        },
        {
          "label": "CERT-EU Brussels contact",
          "url": "https://www.cert.europa.eu/contact-us"
        },
        {
          "label": "Upstream branch activity",
          "url": "https://github.com/certeu/droid/commits/main.atom"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "EUPL-1.2",
      "maintenance": "Active",
      "scopeNote": "The README marks Atomic Red Team testing as work in progress. Country denotes CERT-EU's Brussels base, not a claim that every contributor works in Belgium.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://github.com/certeu/droid",
          "checkedAt": "2026-10-10",
          "observation": "README defines droid as a pySigma wrapper for detection-as-code and describes validation, transformation, searching and deployment to supported SIEM/EDR systems; Atomic testing is work in progress."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://certeu.github.io/droid-docs/getting-started/",
          "checkedAt": "2026-10-10",
          "observation": "Official getting-started documentation installs detect-droid with pip and configures a local command-line environment."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.cert.europa.eu/about-us",
          "checkedAt": "2026-10-10",
          "observation": "CERT-EU describes itself as the interinstitutional cybersecurity service and computer emergency response team for EU institutions."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.cert.europa.eu/contact-us",
          "checkedAt": "2026-10-10",
          "observation": "Official contact page gives a Brussels, Belgium physical address; this is the institutional base of the publisher."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/certeu/droid/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual project LICENSE contains European Union Public Licence version 1.2 text."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/certeu/droid/commits/main.atom",
          "checkedAt": "2026-10-10",
          "observation": "Upstream default-branch Atom feed records a commit on 2026-09-29; branch activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "sigma",
          "note": "Uses pySigma to validate and convert Sigma rules with platform and log-source transformations, then search or deploy them to configured platforms.",
          "sources": [
            {
              "label": "droid README",
              "url": "https://github.com/certeu/droid"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "splunk",
          "note": "Searches and deploys rules as Splunk saved searches using a configured Splunk platform and credentials. Sigma conversion requires the separately installed Splunk backend.",
          "sources": [
            {
              "label": "droid Splunk platform guide",
              "url": "https://certeu.github.io/droid-docs/platforms/splunk/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "elastic",
          "note": "Searches and exports Elastic Security rules through configured Elasticsearch and Kibana endpoints. Supports EQL and ES|QL; the guide limits Sigma correlation rules to ES|QL.",
          "sources": [
            {
              "label": "droid Elastic Security platform guide",
              "url": "https://certeu.github.io/droid-docs/platforms/elastic_security/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "eclecticiq-intelligence-center",
      "name": "EclecticIQ Intelligence Center",
      "maker": "EclecticIQ",
      "country": "Netherlands",
      "workflow": "Threat intelligence",
      "format": "Commercial",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Threat intelligence platform for ingesting, structuring, analyzing, and sharing indicators and adversary context through analyst workflows, APIs, and integrations.",
      "origin": "EclecticIQ began its Intelligence Center platform in Amsterdam and received Dutch/EU financing for platform R&D. The vendor also disclosed an India engineering hub; the exact current engineering split is not public.",
      "originClass": "EU-developed",
      "facts": [
        "Current Intelligence Center 3.9 release documents threat intelligence workflows and integrations.",
        "Official installation guide covers customer-hosted and offline deployment.",
        "The vendor requires an instance-specific license key; full current core rights terms were not publicly readable."
      ],
      "sources": [
        {
          "label": "Current 3.9 release",
          "url": "https://docs.eclecticiq.com/ic/current/release/3.9/"
        },
        {
          "label": "Installation guide",
          "url": "https://docs.eclecticiq.com/ic/current/install-configure-upgrade/index.html"
        },
        {
          "label": "Dutch platform R&D financing",
          "url": "https://www.eclecticiq.com/news/31-august-2021-dutch-scale-up-eclecticiq-receives-15-million-in-eu-financing-to-boost-development-of-next-gen-cyber-security-platform"
        },
        {
          "label": "India engineering disclosure",
          "url": "https://www.eclecticiq.com/news/08-june-2021-eclecticiq-establishes-engineering-hub-in-bengaluru-india"
        },
        {
          "label": "Register vendor license",
          "url": "https://docs.eclecticiq.com/ic/current/install-configure-upgrade/configure-ic-settings/intelligence-center-system-settings/register-the-license/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "The Dutch product/R&D origin is documented, but EU-only engineering and ownership are not. A vendor license key and paid upgrade do not establish proprietary rights; full core terms need review.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "maintenance"
          ],
          "url": "https://docs.eclecticiq.com/ic/current/release/3.9/",
          "checkedAt": "2026-10-10",
          "observation": "First-party 3.9 documentation contains a September 2026 release and current Intelligence Center threat-data, API and integration changes."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://docs.eclecticiq.com/ic/current/install-configure-upgrade/index.html",
          "checkedAt": "2026-10-10",
          "observation": "Current official installation and configuration guide covers deployment to customer hosts, including an offline installation route."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.eclecticiq.com/news/31-august-2021-dutch-scale-up-eclecticiq-receives-15-million-in-eu-financing-to-boost-development-of-next-gen-cyber-security-platform",
          "checkedAt": "2026-10-10",
          "observation": "The vendor and EIB identify EclecticIQ as a Dutch cybersecurity company financed to expand research and development of its own cyber platform, supporting Dutch product stewardship rather than an EU-only engineering conclusion."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.eclecticiq.com/news/08-june-2021-eclecticiq-establishes-engineering-hub-in-bengaluru-india",
          "checkedAt": "2026-10-10",
          "observation": "EclecticIQ disclosed an India R&D hub focused initially on endpoint/XDR and potentially broader technology, so international engineering must remain visible as a caveat."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://docs.eclecticiq.com/ic/current/install-configure-upgrade/configure-ic-settings/intelligence-center-system-settings/register-the-license/",
          "checkedAt": "2026-10-10",
          "observation": "Official current product instructions require an instance-specific vendor license key. They establish license-controlled commercial distribution but do not expose full core rights or prove a proprietary code license."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "taxii",
          "note": "Documents incoming and outgoing TAXII 2.1 feeds. Its extension notes disclose nonstandard default version filtering and STIX object-version limitations.",
          "sources": [
            {
              "label": "EclecticIQ TAXII 2.1 extension and known issues",
              "url": "https://docs.eclecticiq.com/extensions/current/generic/taxii21/index.html"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "stix",
          "note": "Imports and exports STIX 2.1 through configured TAXII feeds. Modified entities may receive new STIX IDs on export; the documented extension does not fully preserve STIX object versioning.",
          "sources": [
            {
              "label": "EclecticIQ STIX versioning limitations",
              "url": "https://docs.eclecticiq.com/extensions/current/generic/taxii21/index.html"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "eset-inspect-on-prem",
      "name": "ESET Inspect On-Prem",
      "maker": "ESET",
      "country": "Slovakia",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Endpoint detection and response console that collects endpoint events, investigates anomalies and indicators, and provides response actions through an on-premises server.",
      "origin": "ESET's Slovak product R&D operation includes its EDR line; public evidence does not isolate every ESET Inspect developer or component location.",
      "originClass": "EU-developed",
      "facts": [
        "On-premises server, connectors, and web console are documented.",
        "Includes incident investigation, rules, and response features.",
        "Inspect Cloud's separate console was consolidated into ESET PROTECT; On-Prem remains documented."
      ],
      "sources": [
        {
          "label": "Inspect On-Prem guide",
          "url": "https://help.eset.com/ei_navigate/2.6/en-US/"
        },
        {
          "label": "Cloud consolidation FAQ",
          "url": "https://help.eset.com/ei_cloud/en-US/consolidation_faq.html"
        },
        {
          "label": "ESET Slovakia sustainability report",
          "url": "https://www.eset.com/fileadmin/ESET/SK/Docs/ESET-Sustainability-Report-Slovakia-2018.pdf"
        },
        {
          "label": "Inspect On-Prem EULA",
          "url": "https://help.eset.com/ei_deploy/2.6/en-US/eula.html"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "Inspect On-Prem requires compatible ESET endpoint/management components. Do not equate it with the consolidated cloud console.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment",
            "license"
          ],
          "url": "https://help.eset.com/ei_navigate/2.6/en-US/",
          "checkedAt": "2026-10-10",
          "observation": "ESET's Inspect On-Prem documentation describes its server, connectors, web interface and EDR use, with licensed ESET endpoint integration."
        },
        {
          "claims": [
            "identity",
            "maintenance"
          ],
          "url": "https://help.eset.com/ei_cloud/en-US/consolidation_faq.html",
          "checkedAt": "2026-10-10",
          "observation": "ESET's FAQ says the cloud Inspect interface moved into ESET PROTECT while Inspect On-Prem continues as a separate deployment."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.eset.com/fileadmin/ESET/SK/Docs/ESET-Sustainability-Report-Slovakia-2018.pdf",
          "checkedAt": "2026-10-10",
          "observation": "The company report describes product development in the Slovak Technology Division in Bratislava and discusses its EDR tool; this establishes line-level Slovak R&D, not every Inspect engineer's location."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://help.eset.com/ei_deploy/2.6/en-US/eula.html",
          "checkedAt": "2026-10-10",
          "observation": "The ESET Inspect On-Prem EULA grants a time-limited nontransferable executable-code license and prohibits distribution and source-code modification."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "originClass": "EU-developed",
      "format": "Commercial",
      "maintenance": "Active",
      "reviewedAt": "2026-10-10",
      "slug": "exein-runtime",
      "name": "Exein Runtime",
      "maker": "Exein S.p.A.",
      "country": "Italy",
      "workflow": "Detection and monitoring",
      "deployment": [
        "SaaS"
      ],
      "description": "Embedded runtime security platform with on-device agents that monitor and block malicious behavior and send fleet telemetry for investigation.",
      "origin": "Exein's EULA names Rome-based Exein S.p.A. as developer and licensor of Exein Runtime; the company also has non-Italian offices.",
      "facts": [
        "Kernel-level agents monitor and block suspicious behavior on embedded systems.",
        "Fleet console traces incidents and produces runtime evidence.",
        "Customer devices exchange information with Exein resources under the SaaS model in its EULA."
      ],
      "sources": [
        {
          "label": "Exein Runtime product",
          "url": "https://www.exein.io/platform/exein-runtime"
        },
        {
          "label": "Exein EULA",
          "url": "https://www.exein.io/eula"
        },
        {
          "label": "Exein company and offices",
          "url": "https://www.exein.io/about"
        },
        {
          "label": "September 2026 Runtime update",
          "url": "https://www.exein.io/blog/cra-article-14-how-exein-helps-manufacturers-meet-the-reporting-deadlines"
        }
      ],
      "license": "Proprietary",
      "scopeNote": "Runtime runs an agent inside customer devices while the current EULA describes connected SaaS resources; offline behavior, tenancy and hosting region need contract-level verification. This is industrial/embedded detection rather than a general SOC EDR.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://www.exein.io/platform/exein-runtime",
          "checkedAt": "2026-10-10",
          "observation": "Product page identifies Runtime, kernel-native protection, fleet incident tracing, telemetry, and forensic reconstruction."
        },
        {
          "claims": [
            "origin",
            "country",
            "license",
            "deployment"
          ],
          "url": "https://www.exein.io/eula",
          "checkedAt": "2026-10-10",
          "observation": "Current EULA identifies Exein S.p.A. in Rome, expressly names Exein Runtime as a solution developed by Exein, calls operation SaaS with device-resource exchange, reserves proprietary IP, and prohibits copying, modification and source derivation."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.exein.io/about",
          "checkedAt": "2026-10-10",
          "observation": "Company page identifies Rome headquarters and offices in Germany, Taiwan and the US, limiting any exclusive-Italian inference."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.exein.io/blog/cra-article-14-how-exein-helps-manufacturers-meet-the-reporting-deadlines",
          "checkedAt": "2026-10-10",
          "observation": "23 September 2026 product article discusses Exein Runtime's current agent, rule rollout and evidence use; evidence of active product work, not an independent efficacy test."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "flowintel",
      "name": "Flowintel",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Response coordination",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Organise investigation cases, tasks and analyst notes, with templates, assignments and integrations for threat intelligence workflows.",
      "origin": "Flowintel’s README credits CIRCL in Luxembourg and David Cruciani, and identifies CIRCL and the EU FETTA project as funders.",
      "originClass": "CSIRT-led",
      "facts": [
        "Case and task templates support repeatable response procedures.",
        "Integrates MISP taxonomies and galaxy data, with export modules."
      ],
      "sources": [
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/flowintel/flowintel"
        },
        {
          "label": "Software license",
          "url": "https://github.com/flowintel/flowintel/blob/main/LICENSE"
        },
        {
          "label": "CSIRT lead directory",
          "url": "https://csirt-tooling-org.github.io/tooling-directory/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Deployment and integration setup remain the operator’s responsibility.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/flowintel/flowintel",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes organise investigation cases, tasks and analyst notes, with templates, assignments and integrations for threat intelligence workflows. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/flowintel/flowintel",
          "checkedAt": "2026-10-10",
          "observation": "Flowintel’s README credits CIRCL in Luxembourg and David Cruciani, and identifies CIRCL and the EU FETTA project as funders."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/flowintel/flowintel/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/flowintel/flowintel",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-09-24. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://csirt-tooling-org.github.io/tooling-directory/",
          "checkedAt": "2026-10-10",
          "observation": "The tooling working group identifies CIRCL as Flowintel’s CSIRT lead."
        }
      ],
      "funding": [
        {
          "programme": "Digital Europe Programme (DEP)",
          "project": "FETTA",
          "grantId": "101128030",
          "scope": "FlowIntel acknowledges FETTA support for its case and task management project. FETTA began in 2024 as a three-year action; the source does not allocate funding by feature.",
          "sources": [
            {
              "label": "FlowIntel upstream funding statement",
              "url": "https://github.com/flowintel/flowintel"
            },
            {
              "label": "CIRCL FETTA project announcement",
              "url": "https://circl.lu/pub/press/20240131/"
            },
            {
              "label": "CERT Polska 2024 report, JTAN and FETTA sections (printed pages 75–82)",
              "url": "https://cert.pl/uploads/docs/Report_CP_2024.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "misp",
          "note": "Provides export modules for MISP and enrichment using misp-modules, alongside MISP taxonomies and galaxies for case context.",
          "sources": [
            {
              "label": "Flowintel documented features",
              "url": "https://github.com/flowintel/flowintel"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "g-data-xdr",
      "name": "G DATA XDR",
      "maker": "G DATA CyberDefense",
      "country": "Germany",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Endpoint detection and response offering that correlates signals across devices, prioritizes incidents, and supports process termination or file quarantine.",
      "origin": "G DATA explicitly states that this XDR product is developed in Germany; the product page also says the hosted console stores data in German data centers.",
      "originClass": "EU-developed",
      "facts": [
        "Correlates endpoint signals in a browser console.",
        "Responds by quarantining files or terminating processes.",
        "Vendor says development and hosting are in Germany."
      ],
      "sources": [
        {
          "label": "G DATA XDR product",
          "url": "https://www.gdata.de/en/business/xdr"
        },
        {
          "label": "XDR product information",
          "url": "https://www.gdata.de/help-en/xdr/ProductInformation/ProductLaunch/"
        },
        {
          "label": "G DATA software EULA",
          "url": "https://www.gdata.de/en/eula"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "German development and data-center location are vendor statements. They do not establish every subcontractor, legal exposure, or independently verified security status.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.gdata.de/en/business/xdr",
          "checkedAt": "2026-10-10",
          "observation": "The vendor product page says XDR is developed entirely in Germany, uses a web console without a customer management server, stores data in German data centers, and correlates endpoint detections for response."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.gdata.de/help-en/xdr/ProductInformation/ProductLaunch/",
          "checkedAt": "2026-10-10",
          "observation": "G DATA maintains current first-party documentation for its XDR product and deployment."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.gdata.de/en/eula",
          "checkedAt": "2026-10-10",
          "observation": "G DATA’s software EULA calls its software proprietary, reserves rights, and restricts copying, modification, sublicensing and distribution."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "gatewatcher-ndr",
      "name": "Gatewatcher NDR",
      "maker": "Gatewatcher",
      "country": "France",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Network detection and response platform that analyses traffic and metadata, prioritizes suspicious activity, and supports threat hunting and incident investigation.",
      "origin": "Developed by French company Gatewatcher, which identifies its own NDR platform and has headquarters in France.",
      "originClass": "EU-developed",
      "facts": [
        "Analyzes network communications and metadata for behavioral threats.",
        "Aggregates and prioritizes alerts for SOC investigation.",
        "Vendor describes on-premises, SaaS and hybrid deployment options."
      ],
      "sources": [
        {
          "label": "Current NDR product",
          "url": "https://www.gatewatcher.com/en/product/gatewatcher-ndr/"
        },
        {
          "label": "Gatewatcher development statement",
          "url": "https://www.gatewatcher.com/en/press/gatewatcher-secures-e25-million-investment-from-the-european-investment-bank-to-accelerate-growth-and-reinforce-european-cyber-resilience/"
        },
        {
          "label": "Deployment customer story",
          "url": "https://www.gatewatcher.com/en/resource/customer-story-of-a-key-player-in-aerospace-and-defense-lynred/"
        },
        {
          "label": "French headquarters",
          "url": "https://www.gatewatcher.com/en/our-locations/"
        }
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Gatewatcher NDR is one platform; Decision Center, AIonIQ, sensors, and TAPs are not split as standalone CSIRT software here. Full product license terms were not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://www.gatewatcher.com/en/product/gatewatcher-ndr/",
          "checkedAt": "2026-10-10",
          "observation": "Current product page describes AIonIQ network analysis, metadata visibility, alert aggregation, triage and threat hunting."
        },
        {
          "claims": [
            "origin",
            "country",
            "maintenance"
          ],
          "url": "https://www.gatewatcher.com/en/press/gatewatcher-secures-e25-million-investment-from-the-european-investment-bank-to-accelerate-growth-and-reinforce-european-cyber-resilience/",
          "checkedAt": "2026-10-10",
          "observation": "Official 2026 company statement calls Gatewatcher French, says it developed its NDR platform, and describes ongoing platform development."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.gatewatcher.com/en/our-locations/",
          "checkedAt": "2026-10-10",
          "observation": "The official locations page lists Gatewatcher headquarters at La Défense, France."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://www.gatewatcher.com/en/resource/customer-story-of-a-key-player-in-aerospace-and-defense-lynred/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor case page explicitly describes on-premises, SaaS and hybrid deployment of the commercial NDR solution."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.gatewatcher.com/en/product/gatewatcher-ndr/",
          "checkedAt": "2026-10-10",
          "observation": "The official NDR offer presents commercial deployment but does not publish full customer software rights or product license terms in the reviewed page."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "glimps-audit",
      "name": "GLIMPS Audit",
      "maker": "GLIMPS",
      "country": "France",
      "workflow": "Malware analysis",
      "format": "Commercial",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Binary analysis product that recognizes libraries and known code across architectures, supports software reverse engineering, and exports symbols to analyst tools.",
      "origin": "Offered by French publisher GLIMPS as a distinct reverse-engineering product.",
      "originClass": "EU-developed",
      "facts": [
        "Identifies static libraries and known code in binary files.",
        "Supports multiple processor architectures and symbol transfer to IDA and Ghidra.",
        "Can be used on-premises without an internet connection."
      ],
      "sources": [
        {
          "label": "Official GLIMPS Audit product",
          "url": "https://www.glimps.re/en/glimps-audit-automatic-software-reverse-engineering/"
        },
        {
          "label": "Official product portfolio",
          "url": "https://www.glimps.re/en/"
        },
        {
          "label": "ANSSI legal notice naming software publisher",
          "url": "https://jecliqueoupas.cyber.gouv.fr/mentions-legales"
        }
      ],
      "license": "License terms not publicly verified",
      "maintenance": "Unknown",
      "scopeNote": "Primarily software auditing and reverse engineering, with vendor-listed incident response use; current release cadence was not verified. Distinct binary-code recognition function from Malware Expert. Audit-specific license terms were not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.glimps.re/en/glimps-audit-automatic-software-reverse-engineering/",
          "checkedAt": "2026-10-10",
          "observation": "Official product page describes binary library recognition, multi-architecture support, IDA/Ghidra symbol transfer, on-premises offline and SaaS delivery."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://jecliqueoupas.cyber.gouv.fr/mentions-legales",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI legal notice identifies GLIMPS SAS, the software publisher, at a French registered address."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.glimps.re/en/glimps-audit-automatic-software-reverse-engineering/",
          "checkedAt": "2026-10-10",
          "observation": "Product page remains public, but no dated current release or maintenance statement was verified; status remains unknown."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.glimps.re/en/glimps-audit-automatic-software-reverse-engineering/",
          "checkedAt": "2026-10-10",
          "observation": "The official Audit product page offers SaaS and on-premises delivery, but does not state the Audit software license model or full customer rights; the Expert EULA is not evidence for Audit."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "glimps-malware-expert",
      "name": "GLIMPS Malware Expert",
      "maker": "GLIMPS",
      "country": "France",
      "workflow": "Malware analysis",
      "format": "Commercial",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "File analysis workspace that combines static and dynamic engines, extracts indicators and malware context, and supports investigation and threat hunting.",
      "origin": "Developed by French publisher GLIMPS; an ANSSI service legal notice independently names GLIMPS as its software publisher in Cesson-Sévigné.",
      "originClass": "EU-developed",
      "facts": [
        "Analyzes submitted files with static, dynamic and hybrid engines.",
        "Extracts malware families, malicious functions, indicators and ATT&CK mapping.",
        "Supports YARA rules, retro hunting and MISP/STIX/JSON exports."
      ],
      "sources": [
        {
          "label": "Official Malware Expert product",
          "url": "https://www.glimps.re/en/glimps-malware-expert/"
        },
        {
          "label": "Official GLIMPS product portfolio",
          "url": "https://www.glimps.re/en/"
        },
        {
          "label": "ANSSI legal notice naming software publisher",
          "url": "https://jecliqueoupas.cyber.gouv.fr/mentions-legales"
        },
        {
          "label": "Malware Expert access and EULA requirement",
          "url": "https://poc.gmalware.glimps.re/expert/en/help/presentation"
        }
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Only Expert is counted; Malware Detect and Kiosk are linked ingestion/user-facing offerings in the same analysis ecosystem. Vendor efficacy figures are not represented as verified results. Full Malware Expert EULA terms were not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.glimps.re/en/glimps-malware-expert/",
          "checkedAt": "2026-10-10",
          "observation": "Official product page describes commercial Expert analysis capabilities, exports, YARA, and both on-premises and SaaS delivery."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://jecliqueoupas.cyber.gouv.fr/mentions-legales",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI legal notice names GLIMPS SAS as the software publisher and lists its Cesson-Sévigné address in France."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.glimps.re/en/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor product portfolio actively offers Malware Expert and a trial; no discontinuation notice appears."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://poc.gmalware.glimps.re/expert/en/help/presentation",
          "checkedAt": "2026-10-10",
          "observation": "Vendor documentation requires EULA acceptance to use Malware Expert, establishing license-controlled access. The full EULA rights were not available in the reviewed public documentation."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "guardsix-ndr",
      "name": "Guardsix NDR",
      "maker": "Guardsix",
      "country": "Denmark",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Network detection and response product that analyzes network telemetry, groups related activity into attack chains, and supports investigation in on-premises environments.",
      "origin": "Guardsix NDR continues a product line acquired from Danish Muninn; current engineering distribution and ultimate control require separate verification.",
      "originClass": "EU-developed",
      "facts": [
        "Analyzes network telemetry for suspicious behavior.",
        "Presents correlated activity as attack chains.",
        "The vendor describes on-premises and hybrid deployment."
      ],
      "sources": [
        {
          "label": "NDR product",
          "url": "https://guardsix.com/product/ndr"
        },
        {
          "label": "Muninn acquisition support note",
          "url": "https://servicedesk.guardsix.com/hc/en-us/articles/27186583865117-Support-for-Logpoint-NDR-Muninn"
        },
        {
          "label": "Company history",
          "url": "https://guardsix.com/about-us"
        },
        {
          "label": "Guardsix EULA",
          "url": "https://guardsix.com/eula"
        },
        {
          "label": "NDR 2.33 release",
          "url": "https://guardsix.com/product-updates/guardsix-ndr-2.33-release?hs_amp=true"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "Guardsix promotes SIEM integration; the public pages do not establish whether NDR can operate without any other Guardsix license.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://guardsix.com/product/ndr",
          "checkedAt": "2026-10-10",
          "observation": "The current NDR product page describes network telemetry analysis, chain-of-events investigation, on-premises/hybrid deployment, and a commercial demo path."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://servicedesk.guardsix.com/hc/en-us/articles/27186583865117-Support-for-Logpoint-NDR-Muninn",
          "checkedAt": "2026-10-10",
          "observation": "The vendor support note identifies Danish Muninn as the NDR predecessor acquired by Logpoint in 2024."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://guardsix.com/eula",
          "checkedAt": "2026-10-10",
          "observation": "The Guardsix EULA covers its network-monitoring software, retains source and intellectual-property rights, and grants a paid nontransferable use right."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://guardsix.com/product-updates/guardsix-ndr-2.33-release?hs_amp=true",
          "checkedAt": "2026-10-10",
          "observation": "The vendor dated the NDR 2.33 release 18 August 2026 and describes licensed on-premises network sensors."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "harfanglab-edr",
      "name": "HarfangLab EDR",
      "maker": "HarfangLab",
      "country": "France",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Endpoint detection and response software that monitors workstation and server activity, raises investigation alerts, and supports blocking and response actions.",
      "origin": "Created by HarfangLab, whose founders built its EDR; HarfangLab describes its engineering and teams as Europe-based and itself as a French company.",
      "originClass": "EU-developed",
      "facts": [
        "Endpoint agents detect and block threats on workstations and servers.",
        "Analysts can tune alerting, access telemetry and investigate via console and API.",
        "Offers both cloud and on-premises console deployment."
      ],
      "sources": [
        {
          "label": "EDR product and deployment",
          "url": "https://harfanglab.io/fr/edr/"
        },
        {
          "label": "Company history and development",
          "url": "https://harfanglab.io/about/"
        },
        {
          "label": "French company statement and current news",
          "url": "https://harfanglab.io/press/"
        }
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Other HarfangLab ASM, EPP and ITDR capabilities are integrated offerings and are not split here. Vendor hosting claims are not independently audited by this index. Full product license terms were not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities"
          ],
          "url": "https://harfanglab.io/about/",
          "checkedAt": "2026-10-10",
          "observation": "HarfangLab says its founders created the EDR to detect and neutralize attacks on servers and workstations, and describes its platform development as Europe-based."
        },
        {
          "claims": [
            "country",
            "deployment"
          ],
          "url": "https://harfanglab.io/press/",
          "checkedAt": "2026-10-10",
          "observation": "The company calls itself French and lists cloud, private, SecNumCloud and own-infrastructure hosting choices."
        },
        {
          "claims": [
            "capabilities",
            "deployment"
          ],
          "url": "https://harfanglab.io/fr/edr/",
          "checkedAt": "2026-10-10",
          "observation": "Product page describes endpoint agents, console investigation, alert tuning, and equivalent cloud/on-premises deployment."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://harfanglab.io/press/",
          "checkedAt": "2026-10-10",
          "observation": "Official newsroom has September 2026 product and company updates."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://harfanglab.io/fr/edr/",
          "checkedAt": "2026-10-10",
          "observation": "The reviewed official EDR offer describes a commercial product and demo path, but does not state the customer rights or full license terms for the EDR software."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": [
        {
          "id": "opencti",
          "note": "The optional HarfangLab Intel connector sends OpenCTI live-stream indicators to HarfangLab. Documented requirements include OpenCTI 6.4+, HarfangLab Threat Response 2.x+ and Python 3.11; changed patterns require deletion and recreation.",
          "sources": [
            {
              "label": "OpenCTI HarfangLab Intel connector",
              "url": "https://github.com/OpenCTI-Platform/connectors/blob/master/stream/harfanglab-intel/README.md"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "sigma",
          "note": "Behavioral detection evaluates endpoint events with configurable Sigma rules. The documented OpenCTI connector can forward Sigma rules, but does not parse or validate them.",
          "sources": [
            {
              "label": "HarfangLab behavioral engine",
              "url": "https://harfanglab.io/edr/behavioral-engine-sigma/"
            },
            {
              "label": "OpenCTI HarfangLab Intel connector",
              "url": "https://github.com/OpenCTI-Platform/connectors/blob/master/stream/harfanglab-intel/README.md"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "yara",
          "note": "Signature detection scans file content, injected threads and process memory with configurable YARA rules. The OpenCTI connector can forward rules without validating them.",
          "sources": [
            {
              "label": "HarfangLab signature engine",
              "url": "https://harfanglab.io/edr/signatures-engine-yara/"
            },
            {
              "label": "OpenCTI HarfangLab Intel connector",
              "url": "https://github.com/OpenCTI-Platform/connectors/blob/master/stream/harfanglab-intel/README.md"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "stix",
          "note": "The optional OpenCTI HarfangLab Intel connector converts selected STIX indicator patterns into IOC rules for IP addresses, domains, URLs and file hashes. It is not a general STIX object import.",
          "sources": [
            {
              "label": "OpenCTI HarfangLab Intel connector",
              "url": "https://github.com/OpenCTI-Platform/connectors/blob/master/stream/harfanglab-intel/README.md"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "hashlookup",
      "name": "Hashlookup",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Look up file hashes in known-file datasets to add context during incident investigation and forensic triage.",
      "origin": "The server README credits CIRCL, Computer Incident Response Center Luxembourg, and Alexandre Dulaunoy.",
      "originClass": "CSIRT-led",
      "facts": [
        "Supports individual and bulk hash lookups through a REST API.",
        "Can import NSRL and other supported file-hash datasets."
      ],
      "sources": [
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/hashlookup/hashlookup-server"
        },
        {
          "label": "Software license",
          "url": "https://github.com/hashlookup/hashlookup-server/blob/main/LICENSE"
        },
        {
          "label": "Public API and limits",
          "url": "https://www.circl.lu/services/hashlookup/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Experimental",
      "scopeNote": "A matching hash is context, not a benign or malicious verdict. The server README labels the implementation beta; CIRCL’s public service is best-effort.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/hashlookup/hashlookup-server",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes look up file hashes in known-file datasets to add context during incident investigation and forensic triage. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/hashlookup/hashlookup-server",
          "checkedAt": "2026-10-10",
          "observation": "The server README credits CIRCL, Computer Incident Response Center Luxembourg, and Alexandre Dulaunoy."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/hashlookup/hashlookup-server/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/hashlookup/hashlookup-server",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-01-26. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "capabilities",
            "deployment"
          ],
          "url": "https://www.circl.lu/services/hashlookup/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL offers a free best-effort API and explicitly says a match alone does not establish maliciousness."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/hashlookup/hashlookup-server",
          "checkedAt": "2026-10-10",
          "observation": "The upstream README explicitly describes the software as beta or experimental."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "hfinger",
      "name": "Hfinger",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Fingerprints malware HTTP requests from packet captures so analysts can compare traffic patterns and group activity associated with malware families.",
      "origin": "CERT Polska publishes the Python/Tshark prototype as a standalone CLI and library.",
      "originClass": "CSIRT-led",
      "facts": [
        "HTTP request fingerprints",
        "PCAP file or folder input",
        "JSON output"
      ],
      "sources": [
        {
          "label": "Upstream README",
          "url": "https://github.com/CERT-Polska/hfinger"
        },
        {
          "label": "Actual license",
          "url": "https://github.com/CERT-Polska/hfinger/blob/master/LICENSE"
        },
        {
          "label": "Repository metadata",
          "url": "https://api.github.com/repos/CERT-Polska/hfinger"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "GPL-3.0",
      "maintenance": "Experimental",
      "scopeNote": "README calls this a working prototype/PoC and recommends isolated execution; repository API shows latest code push in May 2023, so ongoing maintenance is unverified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment",
            "maintenance"
          ],
          "url": "https://github.com/CERT-Polska/hfinger",
          "checkedAt": "2026-10-10",
          "observation": "README identifies malware HTTP request fingerprinting, PCAP CLI/PyPI usage, JSON output, CERT Polska repository and working-prototype status."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/hfinger/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE text is GNU General Public License version 3."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/CERT-Polska/hfinger",
          "checkedAt": "2026-10-10",
          "observation": "GitHub API reports nonarchived repository but latest code push 16 May 2023; no current support inference is made."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/CERT-Polska",
          "checkedAt": "2026-10-10",
          "observation": "Verified organization identifies the Polish CERT team in Warsaw."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Advanced Threat Monitoring and Cooperation on the European and National Levels (AMCE)",
          "grantId": "2018-PL-IA-0168",
          "scope": "CERT Polska identifies Hfinger development in 2020 as AMCE work and expressly credits CEF co-financing. This is historical development funding.",
          "sources": [
            {
              "label": "CERT Polska 2020 report, AMCE and Hfinger sections (printed pages 59 and 73)",
              "url": "https://cert.pl/en/uploads/docs/Report_CP_2020.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "holm-security-vmp",
      "name": "Holm Security VMP",
      "maker": "Holm Security",
      "country": "Sweden",
      "workflow": "Exposure discovery",
      "format": "Commercial",
      "deployment": [
        "SaaS",
        "Self-hosted"
      ],
      "description": "Vulnerability management platform that scans systems, networks, and applications, tracks exposure over time, and supports risk-based remediation across an organization.",
      "origin": "Holm Security says its platform is built in Europe and identifies itself as a Swedish company; the exact engineering country and staffing are unpublished.",
      "originClass": "EU-developed",
      "facts": [
        "Scans systems and network exposure through one platform.",
        "Provides both cloud and on-premises platform deployments.",
        "The vendor says its SaaS data center is in Sweden."
      ],
      "sources": [
        {
          "label": "System and network security product",
          "url": "https://www.holmsecurity.com/products/system-network-security"
        },
        {
          "label": "On-premises platform documentation",
          "url": "https://support.holmsecurity.com/knowledge/on-prem-platform-deployment"
        },
        {
          "label": "Company and development history",
          "url": "https://www.holmsecurity.com/company/about-us"
        },
        {
          "label": "Data center FAQ",
          "url": "https://support.holmsecurity.com/knowledge/which-data-center-is-holm-security-using"
        },
        {
          "label": "Holm customer terms (Benelux)",
          "url": "https://www.holmsecurity.com/hubfs/Hubspot%20support/PDF%20folder/Holm%20Security%20Benelux%20B.V.%20-%20General%20terms%20and%20conditions%20-%20end%20customers%20-%20ver2.5.pdf"
        },
        {
          "label": "VMP release index",
          "url": "https://support.holmsecurity.com/knowledge/product-news"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "System/network/web scanning are capabilities of one VMP, not separate catalog products; Swedish hosting is vendor-stated for its SaaS offer.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://www.holmsecurity.com/products/system-network-security",
          "checkedAt": "2026-10-10",
          "observation": "The current commercial page describes vulnerability assessment and management of systems and networks within Holm's platform."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://support.holmsecurity.com/knowledge/on-prem-platform-deployment",
          "checkedAt": "2026-10-10",
          "observation": "Official support documentation describes a customer on-premises deployment of the platform."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.holmsecurity.com/company/about-us",
          "checkedAt": "2026-10-10",
          "observation": "Holm calls itself a European company and says its platform is built and hosted in Europe. Its Swedish legal domicile is documented separately; this page does not localize all engineering to Sweden."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://support.holmsecurity.com/knowledge/which-data-center-is-holm-security-using",
          "checkedAt": "2026-10-10",
          "observation": "The vendor names its cloud data-center provider and Swedish location."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.holmsecurity.com/hubfs/Hubspot%20support/PDF%20folder/Holm%20Security%20Benelux%20B.V.%20-%20General%20terms%20and%20conditions%20-%20end%20customers%20-%20ver2.5.pdf",
          "checkedAt": "2026-10-10",
          "observation": "Holm customer terms reserve all platform software intellectual-property rights and give customers a limited license to use the product."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://support.holmsecurity.com/knowledge/product-news",
          "checkedAt": "2026-10-10",
          "observation": "The official platform news index lists dated 2026 vulnerability-management releases, including 12 August 2026."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "intelowl",
      "name": "IntelOwl",
      "maker": "Certego / IntelOwl project",
      "country": "Italy",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Enriches files and indicators such as IP addresses, domains and hashes through configurable analyzers, with a shared REST API and investigative interface.",
      "origin": "Certego says it created IntelOwl in 2020; upstream says project management moved fully to Certego with version 6.8.0. Certego is based in Modena, Italy.",
      "originClass": "EU-developed",
      "facts": [
        "File and observable enrichment",
        "REST API and analyst web interface",
        "Docker Compose deployment"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/intelowlproject/IntelOwl"
        },
        {
          "label": "Actual license",
          "url": "https://github.com/intelowlproject/IntelOwl/blob/master/LICENSE"
        },
        {
          "label": "Upstream installation guide",
          "url": "https://intelowlproject.github.io/docs/IntelOwl/installation/"
        },
        {
          "label": "Certego project history",
          "url": "https://www.certego.net/it/blog/intelowl-compie-gli-anni-5-anni-di-evoluzioni-della-piattaforma-di-threat-intelligence-di-certego/"
        },
        {
          "label": "Certego company and location",
          "url": "https://www.certego.net/it/company/about-us/"
        },
        {
          "label": "Current upstream release",
          "url": "https://github.com/intelowlproject/IntelOwl/releases/tag/v6.8.0"
        },
        {
          "label": "Third-party tool legal notice",
          "url": "https://github.com/intelowlproject/IntelOwl/blob/master/.github/legal_notice.md"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Certego is the Italian project steward, with international community contributors; this does not establish Italian origin for every analyzer. Self-hosting uses Docker Compose and is supported/tested chiefly on Ubuntu; bundled third-party analyzers and external services have separate terms or credentials. The hosted Honeynet demo requires an invitation and is not listed as a public service. The v6.8.0 release warns that its Docker build lacks ARM support.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "origin"
          ],
          "url": "https://github.com/intelowlproject/IntelOwl",
          "checkedAt": "2026-10-10",
          "observation": "Upstream README identifies IntelOwl as a threat-intelligence platform, describes file/observable enrichment, REST API and web GUI, and says management is fully in Certego's hands since version 6.8.0."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.certego.net/it/blog/intelowl-compie-gli-anni-5-anni-di-evoluzioni-della-piattaforma-di-threat-intelligence-di-certego/",
          "checkedAt": "2026-10-10",
          "observation": "Certego's January 2025 retrospective says its team launched IntelOwl at the start of 2020 and credits both Certego and international open-source contributors."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.certego.net/it/company/about-us/",
          "checkedAt": "2026-10-10",
          "observation": "Certego's company page describes it as an Italian provider headquartered in Modena; this establishes the country of the project steward, not every contributor."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/intelowlproject/IntelOwl/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream root LICENSE is the complete GNU Affero General Public License version 3 text."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://intelowlproject.github.io/docs/IntelOwl/installation/",
          "checkedAt": "2026-10-10",
          "observation": "Official instructions install the server with Docker Compose, initialize environment files and start a local web application; they say Ubuntu is the tested platform."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/intelowlproject/IntelOwl/releases/tag/v6.8.0",
          "checkedAt": "2026-10-10",
          "observation": "Upstream lists v6.8.0 as latest, released 31 August during GSoC 2026 work, with a release note that ARM Docker builds are unavailable for this version; release activity is not a support guarantee."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://github.com/intelowlproject/IntelOwl/blob/master/.github/legal_notice.md",
          "checkedAt": "2026-10-10",
          "observation": "Upstream legal notice requires users to review separate terms for third-party packages, tools and media downloaded or installed with IntelOwl."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "yara",
          "note": "The local Yara analyzer scans files using documented community rule collections and operator-supplied signatures.",
          "sources": [
            {
              "label": "IntelOwl file analyzer documentation",
              "url": "https://intelowlproject.github.io/docs/IntelOwl/usage/#file-analyzers"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "suricata",
          "note": "The Suricata analyzer inspects submitted PCAP files with the Suricata engine and IDS signatures.",
          "sources": [
            {
              "label": "IntelOwl file analyzer documentation",
              "url": "https://intelowlproject.github.io/docs/IntelOwl/usage/#file-analyzers"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "misp",
          "note": "MISP analyzers look up observables and hashes; a configured connector creates a MISP event linking an IntelOwl analysis.",
          "sources": [
            {
              "label": "IntelOwl analyzer and connector documentation",
              "url": "https://intelowlproject.github.io/docs/IntelOwl/usage/#connectors"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "opencti",
          "note": "An OpenCTI analyzer looks up observables; a configured connector creates an observable and linked report for an IntelOwl analysis.",
          "sources": [
            {
              "label": "IntelOwl analyzer and connector documentation",
              "url": "https://intelowlproject.github.io/docs/IntelOwl/usage/#connectors"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "ipfixprobe",
      "name": "ipfixprobe",
      "maker": "CESNET",
      "country": "Czechia",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Exports bidirectional network flow records with protocol metadata and telemetry for downstream monitoring and investigation systems.",
      "origin": "CESNET's upstream repository and license identify the Czech association.",
      "originClass": "Institution-led",
      "facts": [
        "Bidirectional IPFIX export",
        "Protocol parsers",
        "High-speed capture options"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CESNET/ipfixprobe"
        },
        {
          "label": "License",
          "url": "https://github.com/CESNET/ipfixprobe/blob/master/LICENSE"
        },
        {
          "label": "2026 releases",
          "url": "https://github.com/CESNET/ipfixprobe/releases"
        },
        {
          "label": "CESNET institutional origin",
          "url": "https://www.cesnet.cz/en/about-us"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "BSD-3-Clause",
      "maintenance": "Active",
      "scopeNote": "A telemetry producer, not an alerting engine by itself; optional hardware acceleration does not mean hardware is required.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CESNET/ipfixprobe",
          "checkedAt": "2026-10-10",
          "observation": "README describes modular bidirectional flow export, TLS/QUIC/HTTP/DNS parsers and package installation."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CESNET/ipfixprobe/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license text identifies BSD 3-Clause and CESNET copyright."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.cesnet.cz/en/about-us",
          "checkedAt": "2026-10-10",
          "observation": "CESNET identifies itself as an association operating across the Czech Republic."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/CESNET/ipfixprobe/releases",
          "checkedAt": "2026-10-10",
          "observation": "Upstream release list has versions 5.4.0 and 5.5.0 dated 7 and 9 October 2026."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "karton",
      "name": "Karton",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Runs distributed malware processing tasks using Python workers, Redis messaging and S3 storage, with independent analysis services around the core framework.",
      "origin": "CERT Polska publishes and maintains the upstream framework.",
      "originClass": "CSIRT-led",
      "facts": [
        "Distributed processing framework",
        "Redis task routing",
        "S3 sample exchange"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CERT-Polska/karton"
        },
        {
          "label": "License",
          "url": "https://github.com/CERT-Polska/karton/blob/master/LICENSE"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "BSD-3-Clause",
      "maintenance": "Active",
      "scopeNote": "Count the framework once; individual Karton workers and plugins are not separate entries.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CERT-Polska/karton",
          "checkedAt": "2026-10-10",
          "observation": "README identifies distributed malware processing framework and documents Python, Redis, S3 and installation."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/karton/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license text is three-clause BSD and credits CERT Polska."
        },
        {
          "claims": [
            "country",
            "maintenance"
          ],
          "url": "https://github.com/CERT-Polska",
          "checkedAt": "2026-10-10",
          "observation": "Verified Polish CERT organization lists Karton with a 2026 update."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Advanced Threat Monitoring and Cooperation on the European and National Levels (AMCE)",
          "grantId": "2018-PL-IA-0168",
          "scope": "NASK identifies Karton as a tool developed under AMCE, which ran from June 2019 to December 2021. The funding record is historical.",
          "sources": [
            {
              "label": "NASK AMCE project results and dates",
              "url": "https://archiwum.nask.pl/pl/dzialalnosc/nauka-i-biznes/projekty-badawcze/4333,Advance-threat-Monitoring-and-Cooperation-on-the-European-and-national-levels-AM.html"
            },
            {
              "label": "CERT Polska 2020 report, AMCE and Hfinger sections (printed pages 59 and 73)",
              "url": "https://cert.pl/en/uploads/docs/Report_CP_2020.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "yara",
          "note": "The optional karton-yaramatcher service applies supplied YARA rules to pipeline files and tags matching samples. Rules are not included.",
          "sources": [
            {
              "label": "Karton YARA matcher service and configuration",
              "url": "https://github.com/CERT-Polska/karton-yaramatcher"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "kunai",
      "name": "Kunai",
      "maker": "CIRCL / Kunai Project",
      "country": "Luxembourg",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting.",
      "origin": "CIRCL’s own technical article explicitly describes developing Kunai for Linux security monitoring. CIRCL is based in Luxembourg; the project also accepts wider contributions.",
      "originClass": "CSIRT-led",
      "facts": [
        "Produces chronologically ordered Linux activity events.",
        "Provides container-aware monitoring in a standalone Rust binary."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/kunai-project/kunai"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/kunai-project"
        },
        {
          "label": "Software license",
          "url": "https://github.com/kunai-project/kunai/blob/main/LICENSE"
        },
        {
          "label": "Compatibility and operation",
          "url": "https://why.kunai.rocks/docs/quickstart/"
        },
        {
          "label": "CIRCL project",
          "url": "https://www.circl.lu/projects/kunai/"
        },
        {
          "label": "CIRCL development account",
          "url": "https://www.circl.lu/pub/learning-from-falcon-sensor-outage/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "GPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Linux support depends on the documented kernel compatibility. Running eBPF probes requires elevated privileges.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/kunai-project/kunai",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/kunai-project",
          "checkedAt": "2026-10-10",
          "observation": "The Kunai developer organisation identifies its location as Luxembourg. CIRCL also lists Kunai in its own open-source project inventory."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/kunai-project/kunai/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies GPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/kunai-project/kunai",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-10-08. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://why.kunai.rocks/docs/quickstart/",
          "checkedAt": "2026-10-10",
          "observation": "The quick-start documents running the local executable with privileges and links kernel compatibility requirements."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.circl.lu/projects/kunai/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL includes Kunai in its project portfolio."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.circl.lu/pub/learning-from-falcon-sensor-outage/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL explicitly says it developed Kunai and describes the project; the page identifies CIRCL as Luxembourg’s response centre."
        }
      ],
      "funding": [
        {
          "programme": "Digital Europe Programme (DEP)",
          "project": "Next Generation Security Operator Training Infrastructure (NGSOTI)",
          "grantId": "101127921",
          "scope": "Kunai acknowledges NGSOTI support for the project. The action runs from January 2024 to December 2026; funding by feature is not specified.",
          "sources": [
            {
              "label": "Kunai upstream funding statement",
              "url": "https://github.com/kunai-project/kunai"
            },
            {
              "label": "Restena NGSOTI project: programme, grant and dates",
              "url": "https://www.restena.lu/en/project/ngsoti"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "kunai-sandbox",
      "name": "Kunai Sandbox",
      "maker": "Kunai Project / CIRCL",
      "country": "Luxembourg",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering.",
      "origin": "The Kunai Project is based in Luxembourg; CIRCL identifies this as its Linux malware sandbox and links the upstream installation source.",
      "originClass": "CSIRT-led",
      "facts": [
        "Supports x86_64 and aarch64 sandbox environments.",
        "Records host activity alongside network captures."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/kunai-project/sandbox"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://www.circl.lu/services/kunai-sandbox/"
        },
        {
          "label": "Software license",
          "url": "https://github.com/kunai-project/sandbox/blob/main/LICENSE"
        },
        {
          "label": "Design and limitations",
          "url": "https://www.d4-project.org/2024/10/02/Enhancing-Detection-Engineering-with-Automated-Malware-Sandboxing.html"
        },
        {
          "label": "Sandbox UI license",
          "url": "https://github.com/kunai-project/sandbox-ui/blob/main/LICENSE"
        },
        {
          "label": "Sandbox UI and conflicting README notice",
          "url": "https://github.com/kunai-project/sandbox-ui"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "GPL-3.0 (sandbox engine)",
      "maintenance": "Active",
      "scopeNote": "Linux sample analysis; CIRCL notes limits against evasive malware. The engine is GPL-3.0. The separate web UI has conflicting notices: its LICENSE contains AGPL-3.0, while its README says MIT; confirm the UI terms with upstream before reuse.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/kunai-project/sandbox",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country",
            "deployment"
          ],
          "url": "https://www.circl.lu/services/kunai-sandbox/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL identifies Kunai Sandbox as its Linux malware-analysis service, states that its web interface is publicly accessible, and links the self-hosted source. CIRCL identifies itself as the Luxembourg incident-response centre."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/kunai-project/sandbox/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies GPL-3.0 (sandbox engine)."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/kunai-project/sandbox",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-07-21. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "origin",
            "capabilities"
          ],
          "url": "https://www.d4-project.org/2024/10/02/Enhancing-Detection-Engineering-with-Automated-Malware-Sandboxing.html",
          "checkedAt": "2026-10-10",
          "observation": "The CIRCL-led D4 project describes creating the QEMU/Kunai sandbox and cautions that it does not provide the stealth of specialised hypervisors."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/kunai-project/sandbox-ui/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The UI LICENSE contains GNU AGPL version 3, in conflict with the MIT statement in its README."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/kunai-project/sandbox-ui",
          "checkedAt": "2026-10-10",
          "observation": "The UI README states MIT, but links to a LICENSE containing AGPL-3.0. The catalog license field is scoped to the separately licensed sandbox engine."
        }
      ],
      "funding": [
        {
          "programme": "Digital Europe Programme (DEP)",
          "project": "Next Generation Security Operator Training Infrastructure (NGSOTI)",
          "grantId": "101127921",
          "scope": "Kunai Sandbox acknowledges NGSOTI support for its Linux sandbox project. The action runs from January 2024 to December 2026; funding by feature is not specified.",
          "sources": [
            {
              "label": "Kunai Sandbox upstream funding statement",
              "url": "https://github.com/kunai-project/sandbox"
            },
            {
              "label": "Restena NGSOTI project: programme, grant and dates",
              "url": "https://www.restena.lu/en/project/ngsoti"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "loki-rs",
      "name": "Loki-RS",
      "maker": "Florian Roth",
      "country": "Germany",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Scans files, process memory and archives for YARA rules and indicators of compromise during endpoint triage and threat hunting.",
      "origin": "The current Rust successor is developed by Florian Roth, whose upstream profile identifies Frankfurt, Germany; the older Python LOKI is deprecated.",
      "originClass": "EU-developed",
      "facts": [
        "YARA and IOC endpoint scans",
        "File, process memory and archive coverage",
        "Command-line and prebuilt binary use"
      ],
      "sources": [
        {
          "label": "Current Rust project",
          "url": "https://github.com/Neo23x0/Loki-RS"
        },
        {
          "label": "Actual project license",
          "url": "https://github.com/Neo23x0/Loki-RS/blob/master/LICENSE"
        },
        {
          "label": "Lead developer profile",
          "url": "https://github.com/Neo23x0"
        },
        {
          "label": "Recent upstream release",
          "url": "https://github.com/Neo23x0/Loki-RS/releases/tag/v2.13.1"
        },
        {
          "label": "Deprecated predecessor",
          "url": "https://github.com/Neo23x0/Loki"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "GPL-3.0",
      "maintenance": "Active",
      "scopeNote": "The README calls Loki-RS a side project for practical triage and experimentation and points professional support to THOR. The separate Python LOKI predecessor is officially deprecated.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/Neo23x0/Loki-RS",
          "checkedAt": "2026-10-10",
          "observation": "README calls Loki-RS the Rust rewrite of LOKI and describes multithreaded YARA/IOC scanning across files, process memory and ZIP archives, with CLI and prebuilt binaries."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/Neo23x0",
          "checkedAt": "2026-10-10",
          "observation": "Author Florian Roth self-identifies Frankfurt, Germany and Nextron Systems on his upstream profile; country is tied to the identified lead."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/Neo23x0/Loki-RS/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual repository LICENSE contains GNU GPL version 3 text."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/Neo23x0/Loki-RS/releases/tag/v2.13.1",
          "checkedAt": "2026-10-10",
          "observation": "Upstream v2.13.1 release was published 2026-09-27; a release is activity, not a guarantee of efficacy."
        },
        {
          "claims": [
            "capabilities"
          ],
          "url": "https://github.com/Neo23x0/Loki-RS",
          "checkedAt": "2026-10-10",
          "observation": "README calls this a side project for triage and experimentation and points users seeking professional support to THOR."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "yara",
          "note": "Scans files and process memory using YARA-X, with YARA Forge Core rules as its default rule source. The project is beta; process-memory access has platform and permission limits.",
          "sources": [
            {
              "label": "Loki-RS scanning and signature documentation",
              "url": "https://github.com/Neo23x0/Loki-RS"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "lookyloo",
      "name": "Lookyloo",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations.",
      "origin": "The software license credits CIRCL in Luxembourg alongside the project authors and Viper Framework. CIRCL operates the documented public instance.",
      "originClass": "CSIRT-led",
      "facts": [
        "Visualises relationships between domains involved in a capture.",
        "Provides a REST API for capture workflows."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/Lookyloo/lookyloo"
        },
        {
          "label": "Software license",
          "url": "https://github.com/Lookyloo/lookyloo/blob/main/LICENSE"
        },
        {
          "label": "Public service and limits",
          "url": "https://www.circl.lu/services/lookyloo/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "BSD-3-Clause",
      "maintenance": "Active",
      "scopeNote": "Public-instance submissions follow CIRCL’s service conditions. Results support investigation and do not establish that a file or URL is safe.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/Lookyloo/lookyloo",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/Lookyloo/lookyloo/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The software license credits CIRCL in Luxembourg alongside the project authors and Viper Framework. CIRCL operates the documented public instance."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/Lookyloo/lookyloo/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies BSD-3-Clause."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/Lookyloo/lookyloo",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://www.circl.lu/services/lookyloo/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL’s current service page explicitly offers public access and documents running a private instance."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "misp",
          "note": "Optional modules look up captured indicators in MISP and push captures as events. Both are disabled by default and require a MISP API key; publish and lookup actions require an authenticated Lookyloo user.",
          "sources": [
            {
              "label": "Lookyloo MISP module configuration",
              "url": "https://www.lookyloo.eu/docs/main/lookyloo-integration.html#_misp"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "madcat",
      "name": "MADCAT",
      "maker": "German Federal Office for Information Security (BSI)",
      "country": "Germany",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Runs a low-interaction network sensor that records connection attempts across services to help analysts observe mass scanning and attack patterns.",
      "origin": "The upstream MADCAT v2 project is published by Germany's Federal Office for Information Security, whose project organization lists Bonn, Germany.",
      "originClass": "Institution-led",
      "facts": [
        "Low-interaction network sensor",
        "Connection attempt logging",
        "Attack-pattern observation"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/BSI-Bund/MADCAT_v2"
        },
        {
          "label": "Actual GPL license",
          "url": "https://github.com/BSI-Bund/MADCAT_v2/blob/main/LICENSE.md"
        },
        {
          "label": "BSI project organization",
          "url": "https://github.com/BSI-Bund"
        },
        {
          "label": "Upstream branch activity",
          "url": "https://github.com/BSI-Bund/MADCAT_v2/commits/main.atom"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "GPL-3.0",
      "maintenance": "Active",
      "scopeNote": "The README describes higher-interaction response, DPI routing proxy and Docker appliance as planned or in progress. Bundled libraries retain their respective licenses; no production fitness claim is made.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/BSI-Bund/MADCAT_v2",
          "checkedAt": "2026-10-10",
          "observation": "README describes a self-built low-interaction, honeypot-like connection sensor, with Linux build instructions, that records contact attempts."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/BSI-Bund",
          "checkedAt": "2026-10-10",
          "observation": "Project is in the official German BSI GitHub organization, which identifies the federal security office and Bonn location."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/BSI-Bund/MADCAT_v2/blob/main/LICENSE.md",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE.md contains GNU GPL version 3 text; the README identifies separately licensed included libraries."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/BSI-Bund/MADCAT_v2/commits/main.atom",
          "checkedAt": "2026-10-10",
          "observation": "Upstream default-branch Atom feed records a commit on 2026-08-07; branch activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "mailgoose",
      "name": "Mailgoose",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Exposure discovery",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Checks a domain's SPF and DMARC records and validates DKIM through a test email, with a self-hosted portal reusable by other CSIRTs.",
      "origin": "CERT Polska published the former Bezpieczna Poczta code as a white-label tool for other national CSIRTs; Lithuania NCSC runs an instance.",
      "originClass": "CSIRT-led",
      "facts": [
        "SPF, DMARC and DKIM checks",
        "Domain and test-email methods",
        "Reusable CSIRT deployment"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CERT-Polska/mailgoose"
        },
        {
          "label": "Actual license",
          "url": "https://github.com/CERT-Polska/mailgoose/blob/main/LICENSE"
        },
        {
          "label": "Deployment guide",
          "url": "https://mailgoose.readthedocs.io/en/latest/quick-start.html"
        },
        {
          "label": "CERT Polska project article",
          "url": "https://cert.pl/en/posts/2024/07/mailgoose/"
        },
        {
          "label": "CERT Polska public instance",
          "url": "https://bezpiecznapoczta.cert.pl/"
        },
        {
          "label": "Upstream activity metadata",
          "url": "https://api.github.com/repos/CERT-Polska/mailgoose"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "BSD-3-Clause",
      "maintenance": "Active",
      "scopeNote": "Email-domain protection assessment rather than incident handling. CERT Polska's Polish instance offers public domain and test-email checks; Lithuania NCSC also operates an instance. These are public institutional services, not a general commercial SaaS offering.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://bezpiecznapoczta.cert.pl/",
          "checkedAt": "2026-10-10",
          "observation": "CERT Polska's live Bezpieczna Poczta public interface offers domain checks and test-email checks; its page explains that DKIM requires the test-email route."
        },
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities"
          ],
          "url": "https://cert.pl/en/posts/2024/07/mailgoose/",
          "checkedAt": "2026-10-10",
          "observation": "CERT Polska says it developed Bezpieczna Poczta, published white-label Mailgoose for other national CSIRTs, identifies Lithuania NCSC use and describes domain and test-email checks."
        },
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://github.com/CERT-Polska/mailgoose",
          "checkedAt": "2026-10-10",
          "observation": "Upstream README calls Mailgoose a web application for SPF, DMARC and DKIM configuration checks and identifies its Polish institutional instance."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/mailgoose/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual license contains the three BSD-style redistribution conditions and 2023 CERT Polska copyright."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://mailgoose.readthedocs.io/en/latest/quick-start.html",
          "checkedAt": "2026-10-10",
          "observation": "Upstream quick start documents Docker Compose self-hosting and separate production deployment requirements."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/CERT-Polska/mailgoose",
          "checkedAt": "2026-10-10",
          "observation": "Upstream GitHub API reports nonarchived repository with code pushed 2026-10-08; an activity signal, not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "mentat",
      "name": "Mentat",
      "maker": "CESNET",
      "country": "Czechia",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Processes structured security events in a modular SIEM, providing a web interface, searchable event records and periodic notifications to affected networks.",
      "origin": "CESNET publishes the Mentat SIEM source and attributes the system copyright to the Czech association.",
      "originClass": "Institution-led",
      "facts": [
        "IDEA event processing",
        "Web interface and API",
        "Per-network event reporting"
      ],
      "sources": [
        {
          "label": "Upstream README",
          "url": "https://gitlab.cesnet.cz/api/v4/projects/888/repository/files/README.rst/raw?ref=master"
        },
        {
          "label": "Actual license",
          "url": "https://gitlab.cesnet.cz/api/v4/projects/888/repository/files/LICENSE.txt/raw?ref=master"
        },
        {
          "label": "Current manual",
          "url": "https://713.gitlab-pages.cesnet.cz/mentat/mentat/master/html/manual.html"
        },
        {
          "label": "Reporting documentation",
          "url": "https://713.gitlab-pages.cesnet.cz/mentat/mentat/master/html/_doclib/reporting.html"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "MIT",
      "maintenance": "Active",
      "scopeNote": "The CESNET-hosted Mentat service and the self-installable software are one system; setup uses several components and can require advanced administration.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country"
          ],
          "url": "https://gitlab.cesnet.cz/api/v4/projects/888/repository/files/README.rst/raw?ref=master",
          "checkedAt": "2026-10-10",
          "observation": "Upstream README names Mentat SIEM and credits CESNET as copyright holder."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://gitlab.cesnet.cz/api/v4/projects/888/repository/files/LICENSE.txt/raw?ref=master",
          "checkedAt": "2026-10-10",
          "observation": "Actual repository LICENSE.txt grants MIT terms with CESNET copyright."
        },
        {
          "claims": [
            "capabilities"
          ],
          "url": "https://713.gitlab-pages.cesnet.cz/mentat/mentat/master/html/_doclib/reporting.html",
          "checkedAt": "2026-10-10",
          "observation": "Upstream manual documents event reports by group/severity, web report detail and feedback, and classified event data."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://713.gitlab-pages.cesnet.cz/mentat/mentat/master/html/manual.html",
          "checkedAt": "2026-10-10",
          "observation": "Upstream manual provides self-installation, quickstart, web interface and API sections."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://gitlab.cesnet.cz/api/v4/projects/888/repository/commits?per_page=1",
          "checkedAt": "2026-10-10",
          "observation": "Upstream latest commit records version 2.15.4 deployment on 25 June 2026."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "mercury",
      "name": "Mercury",
      "maker": "QuoIntelligence GmbH",
      "country": "Germany",
      "workflow": "Threat intelligence",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Delivers analyst-reviewed threat intelligence, vulnerability alerts, contextual risk scoring, IOC access and tailored reports through a customer web portal.",
      "origin": "QuoIntelligence says it was founded in Frankfurt in 2020 and its Mercury-backed platform is developed and operated within the EU; its current entities and team span Germany, Italy and Spain.",
      "originClass": "EU-developed",
      "facts": [
        "Curated threat and vulnerability intelligence",
        "Client-specific risk scoring and reports",
        "Portal knowledge base and API access"
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Mercury is an account-based intelligence platform and analyst service, not an open-data or downloadable software license. Public portal terms describe hosted access but do not expose the full current subscription or software-license agreement. The company has EU entities beyond Germany; German lead does not mean all engineering is German. Karla is a Mercury-powered feature, not a separate catalog entry.",
      "sources": [
        {
          "label": "Mercury product",
          "url": "https://quointelligence.eu/mercury/"
        },
        {
          "label": "Company and developer account",
          "url": "https://quointelligence.eu/about/"
        },
        {
          "label": "Mercury portal terms",
          "url": "https://quointelligence.eu/terms-conditions/"
        },
        {
          "label": "Customer portal",
          "url": "https://mercury.quointelligence.eu/"
        },
        {
          "label": "2026 company and product update",
          "url": "https://quointelligence.eu/2026/04/quointelligence-closes-eur-7-3-million-series-a-to-scale-unified-risk-intelligence-across-europe/"
        },
        {
          "label": "Current threat-intelligence updates",
          "url": "https://quointelligence.eu/weekly-intelligence-snapshots/"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://quointelligence.eu/mercury/",
          "checkedAt": "2026-10-10",
          "observation": "Current product page describes intelligence tickets, vulnerability alerts, tailored relevance scoring, analyst knowledge-base access, validated indicators and API integration."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://quointelligence.eu/about/",
          "checkedAt": "2026-10-10",
          "observation": "Company says it was founded in Frankfurt in February 2020 and supplies intelligence through Mercury; it lists Germany, Italy and Spain entities and software-engineering expertise."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://quointelligence.eu/",
          "checkedAt": "2026-10-10",
          "observation": "Official company site states its platform is developed and operated within the EU. This is the vendor claim of EU development, paired with German founding rather than inferred from address alone."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://quointelligence.eu/terms-conditions/",
          "checkedAt": "2026-10-10",
          "observation": "Public Mercury portal terms define account-based browser access for business users and say QuoIntelligence hosts the web application. They are portal-use terms and do not publish a complete current software/subscription license; their postal address is older than the current imprint."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://mercury.quointelligence.eu/",
          "checkedAt": "2026-10-10",
          "observation": "The live Mercury login page is a hosted customer portal requiring an account; an accessible login page alone does not imply a free public service."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://quointelligence.eu/2026/04/quointelligence-closes-eur-7-3-million-series-a-to-scale-unified-risk-intelligence-across-europe/",
          "checkedAt": "2026-10-10",
          "observation": "Dated 27 April 2026 company announcement identifies Mercury as its operating AI-powered threat-intelligence platform and plans further product development."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://quointelligence.eu/weekly-intelligence-snapshots/",
          "checkedAt": "2026-10-10",
          "observation": "Official weekly intelligence page lists current 2026 updates hosted in Mercury, evidencing ongoing service activity, not a guaranteed update interval."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "miasm",
      "name": "Miasm",
      "maker": "CEA IT Security",
      "country": "France",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Python reverse-engineering framework for disassembly, binary rewriting, intermediate representation, emulation, unpacking and expression simplification during binary analysis.",
      "origin": "Hosted and maintained by CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group.",
      "originClass": "Institution-led",
      "facts": [
        "Parses and modifies PE and ELF binaries.",
        "Disassembles multiple CPU architectures and models instructions in an intermediate language.",
        "Supports JIT emulation and de-obfuscation."
      ],
      "sources": [
        {
          "label": "Upstream Miasm README",
          "url": "https://github.com/cea-sec/miasm"
        },
        {
          "label": "CEA IT Security project portfolio",
          "url": "https://github.com/cea-sec"
        },
        {
          "label": "Upstream license",
          "url": "https://github.com/cea-sec/miasm/blob/master/LICENSE"
        }
      ],
      "license": "GPL-2.0",
      "maintenance": "Active",
      "scopeNote": "A developer framework, not a turnkey malware verdict service; analysts need scripts and reverse-engineering expertise.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "license",
            "deployment"
          ],
          "url": "https://github.com/cea-sec/miasm",
          "checkedAt": "2026-10-10",
          "observation": "Upstream README calls Miasm a GPLv2 Python reverse-engineering framework and lists PE/ELF, disassembly, IR, emulation and de-obfuscation features."
        },
        {
          "claims": [
            "origin",
            "country",
            "maintenance"
          ],
          "url": "https://github.com/cea-sec",
          "checkedAt": "2026-10-10",
          "observation": "CEA IT Security identifies itself as a group of the French national commission and lists Miasm as a maintained project updated in September 2026."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "mquery",
      "name": "mquery",
      "maker": "CERT Polska",
      "country": "Poland",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Indexes local malware collections with UrsaDB and provides a web interface for analysts to search those samples using YARA rules.",
      "origin": "CERT Polska publishes and maintains the mquery malware search interface; UrsaDB is its separate indexing dependency.",
      "originClass": "CSIRT-led",
      "facts": [
        "YARA queries over sample collections",
        "UrsaDB index acceleration",
        "Docker Compose deployment"
      ],
      "sources": [
        {
          "label": "Upstream README",
          "url": "https://github.com/CERT-Polska/mquery"
        },
        {
          "label": "Actual license",
          "url": "https://github.com/CERT-Polska/mquery/blob/master/LICENSE"
        },
        {
          "label": "Repository activity",
          "url": "https://api.github.com/repos/CERT-Polska/mquery"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Requires a separately configured UrsaDB index; README says a public instance is planned, not currently available.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CERT-Polska/mquery",
          "checkedAt": "2026-10-10",
          "observation": "README credits CERT Polska contact and documents Docker Compose, local sample indexing through UrsaDB, and YARA searching in the web interface."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CERT-Polska/mquery/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE text is GNU Affero General Public License version 3."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/CERT-Polska/mquery",
          "checkedAt": "2026-10-10",
          "observation": "Upstream GitHub API reports a nonarchived repository with code pushed 3 February 2026; this is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/CERT-Polska",
          "checkedAt": "2026-10-10",
          "observation": "Verified CERT Polska organization identifies the Warsaw-based Polish team."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Advanced Threat Monitoring and Cooperation on the European and National Levels (AMCE)",
          "grantId": "2018-PL-IA-0168",
          "scope": "NASK identifies mquery as a tool developed under AMCE, which ran from June 2019 to December 2021. The funding record is historical.",
          "sources": [
            {
              "label": "NASK AMCE project results and dates",
              "url": "https://archiwum.nask.pl/pl/dzialalnosc/nauka-i-biznes/projekty-badawcze/4333,Advance-threat-Monitoring-and-Cooperation-on-the-European-and-national-levels-AM.html"
            },
            {
              "label": "CERT Polska 2020 report, AMCE and Hfinger sections (printed pages 59 and 73)",
              "url": "https://cert.pl/en/uploads/docs/Report_CP_2020.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": [
        {
          "id": "yara",
          "note": "Searches an indexed file collection using analyst-supplied YARA rules, with UrsaDB accelerating candidate selection.",
          "sources": [
            {
              "label": "mquery README and query example",
              "url": "https://github.com/CERT-Polska/mquery"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "nemea",
      "name": "NEMEA",
      "maker": "CESNET",
      "country": "Czechia",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Analyzes network flows through modular detectors for malicious traffic such as scans, denial-of-service activity and DNS tunneling.",
      "origin": "Upstream repository belongs to the Czech CESNET association and its license credits CESNET.",
      "originClass": "Institution-led",
      "facts": [
        "Flow-based analysis",
        "Modular detectors",
        "Supervisor orchestration"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CESNET/Nemea"
        },
        {
          "label": "License",
          "url": "https://github.com/CESNET/Nemea/blob/master/COPYING"
        },
        {
          "label": "CESNET institutional origin",
          "url": "https://www.cesnet.cz/en/about-us"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Dual: CESNET three-clause permissive terms or GPL-2.0-or-later",
      "maintenance": "Unknown",
      "scopeNote": "Meta-repository assembles framework, detectors, modules and supervisor; do not count submodules separately. License covers repository notice; components may vary. Maintenance is Unknown because a dated recent release or update was not established for the combined system.",
      "evidence": [
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/CESNET/Nemea",
          "checkedAt": "2026-10-10",
          "observation": "The reviewed meta-repository documents components and installation but did not establish a dated recent release or update for the combined system; component submodules may have separate activity. Maintenance is marked Unknown pending a component-level check."
        },
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CESNET/Nemea",
          "checkedAt": "2026-10-10",
          "observation": "README describes NEMEA's flow-based detectors, supervisor, packages and source installation."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CESNET/Nemea/blob/master/COPYING",
          "checkedAt": "2026-10-10",
          "observation": "COPYING grants three-clause permissive terms with alternative GPL version 2 or later option."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.cesnet.cz/en/about-us",
          "checkedAt": "2026-10-10",
          "observation": "CESNET describes itself as a Czech Republic academic association."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "nerd",
      "name": "NERD",
      "maker": "CESNET",
      "country": "Czechia",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Aggregates data about known malicious network entities, chiefly IP addresses, and presents the combined context to investigators.",
      "origin": "CESNET publishes NERD and names its Czech security research programme as development context.",
      "originClass": "Institution-led",
      "facts": [
        "Malicious IP context",
        "Data aggregation",
        "Web and daemon components"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/CESNET/NERD"
        },
        {
          "label": "CESNET public service and deployment guidance",
          "url": "https://nerd.cesnet.cz/"
        },
        {
          "label": "License",
          "url": "https://github.com/CESNET/NERD/blob/master/LICENSE"
        },
        {
          "label": "CESNET institutional origin",
          "url": "https://www.cesnet.cz/en/about-us"
        },
        {
          "label": "Upstream activity metadata",
          "url": "https://api.github.com/repos/CESNET/NERD"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Dual: CESNET three-clause permissive terms or GPL-2.0-or-later",
      "maintenance": "Active",
      "scopeNote": "CESNET's public web/API service exposes most data without registration, while full access is limited to trusted partners. Independent self-deployment is possible with assistance but upstream says installation scripts are incompletely tested and documented and some features depend on Warden access. Upstream root license uses alternative terms.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://nerd.cesnet.cz/",
          "checkedAt": "2026-10-10",
          "observation": "CESNET operates a public web interface and API with basic access to most data; full access requires trusted-partner approval. The site recommends its hosted instance because self-installation scripts are incomplete and parts require Warden data, though operators can request deployment help."
        },
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/CESNET/NERD",
          "checkedAt": "2026-10-10",
          "observation": "README identifies source software and hosted service, malicious entity data aggregation, and Czech-funded development."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/CESNET/NERD/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE offers CESNET three-clause permissive terms or GPL version 2 or later."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.cesnet.cz/en/about-us",
          "checkedAt": "2026-10-10",
          "observation": "CESNET describes its Czech Republic association and services."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/CESNET/NERD",
          "checkedAt": "2026-10-10",
          "observation": "Upstream GitHub API reports nonarchived repository with code pushed 2026-09-28; an activity signal, not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "networkminer",
      "name": "NetworkMiner",
      "maker": "NETRESEC AB",
      "country": "Sweden",
      "workflow": "Digital forensics",
      "format": "Open core",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Parses PCAP traffic to reconstruct transferred files, credentials and host context for network forensic investigation and incident response.",
      "origin": "Netresec identifies itself as the developer of network forensic software and lists a Swedish legal address; founder Erik Hjelmvik identifies himself as NetworkMiner creator.",
      "originClass": "EU-developed",
      "facts": [
        "PCAP-based artifact reconstruction",
        "Passive host inventory and live capture",
        "Free GPL edition plus paid Professional features"
      ],
      "license": "Mixed: GPL-2.0 free edition; commercial Professional license (full terms not publicly verified)",
      "maintenance": "Active",
      "scopeNote": "The free edition is GPLv2 and runs locally; paid Professional adds PCAPNG support, enhanced identification and other features under separate commercial licensing. The public product matrix and specifications do not publish full Professional contract terms. Do not treat Professional code as GPL because the free edition is GPL.",
      "sources": [
        {
          "label": "Official product and edition matrix",
          "url": "https://www.netresec.com/?page=NetworkMiner"
        },
        {
          "label": "Vendor source-code license declaration",
          "url": "https://www.netresec.com/?page=NetworkMinerSourceCode"
        },
        {
          "label": "Full GPL version 2 text linked by vendor",
          "url": "https://www.gnu.org/licenses/gpl-2.0.txt"
        },
        {
          "label": "Swedish developer",
          "url": "https://www.netresec.com/?page=AboutNetresec"
        },
        {
          "label": "7 October 2026 release",
          "url": "https://www.netresec.com/?page=blog&tag=networkminer"
        },
        {
          "label": "Professional license options",
          "url": "https://www.netresec.com/files/NetworkMiner-Professional_Product-Specifications.pdf"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.netresec.com/?page=NetworkMiner",
          "checkedAt": "2026-10-10",
          "observation": "Vendor calls NetworkMiner an open-source network-forensics tool for local Windows/Linux use, reconstructing files, emails and credentials from PCAPs; its edition matrix separates free and Professional functions."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.netresec.com/?page=NetworkMinerSourceCode",
          "checkedAt": "2026-10-10",
          "observation": "Vendor explicitly applies GNU General Public License version 2 to the free source code and links the full GPLv2 text; the linked text was inspected. This declaration does not cover Professional-only features."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.gnu.org/licenses/gpl-2.0.txt",
          "checkedAt": "2026-10-10",
          "observation": "The full GNU General Public License version 2 text gives copy, modify and distribution rights subject to its stated conditions; vendor applies it to free NetworkMiner source."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.netresec.com/?page=AboutNetresec",
          "checkedAt": "2026-10-10",
          "observation": "NETRESEC AB says it develops software for traffic capture/PCAP analysis and lists its Swedish registered address in Örsundsbro."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.netresec.com/?page=blog&tag=networkminer",
          "checkedAt": "2026-10-10",
          "observation": "The vendor published NetworkMiner 3.2 on 7 October 2026 with parser and file-reassembly fixes; the source and free download are linked from its official product page."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.netresec.com/files/NetworkMiner-Professional_Product-Specifications.pdf",
          "checkedAt": "2026-10-10",
          "observation": "Vendor specifications distinguish paid named-user and corporate Professional licenses and update entitlements; full commercial end-user terms were not publicly verified."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "onekey-platform",
      "name": "ONEKEY Platform",
      "maker": "ONEKEY GmbH",
      "country": "Germany",
      "workflow": "Exposure discovery",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Analyzes embedded firmware binaries to inventory components, generate SBOMs, identify known vulnerabilities and monitor product risk over subsequent releases.",
      "origin": "ONEKEY says it launched in 2020 as IoT-Inspector, a SEC Consult spin-off, and built its firmware platform with a team across Germany, Hungary, Austria and Belgium. The contracting company is in Düsseldorf.",
      "originClass": "EU-developed",
      "facts": [
        "Binary firmware component analysis",
        "SBOM generation and CVE matching",
        "Ongoing product vulnerability monitoring"
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "The reviewed platform is a business-customer hosted service requiring registration and a license key. Its bundled public terms reserve service intellectual-property rights but are dated July 2020; current negotiated customer terms and any private deployment option were not verified. Its separate MIT-licensed unblob extractor does not make the entire platform open source.",
      "sources": [
        {
          "label": "Platform overview",
          "url": "https://www.onekey.com/platform-overview"
        },
        {
          "label": "Company product history",
          "url": "https://www.onekey.com/about-us"
        },
        {
          "label": "German imprint",
          "url": "https://www.onekey.com/de/imprint"
        },
        {
          "label": "Public terms embedded in current app bundle",
          "url": "https://app.eu.onekey.com/_next/static/chunks/pages/tos-1612795941.js"
        },
        {
          "label": "Analysis documentation",
          "url": "https://docs.onekey.com/platform-guide/how-analyze/"
        },
        {
          "label": "Current documentation",
          "url": "https://docs.onekey.com/"
        },
        {
          "label": "Unblob relationship",
          "url": "https://docs.onekey.com/platform-guide/how-analyze/firmware-extraction/"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://www.onekey.com/platform-overview",
          "checkedAt": "2026-10-10",
          "observation": "Vendor describes a centralized firmware-product security platform with binary component inventory, SBOM import/generation, vulnerability detection and lifecycle monitoring."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.onekey.com/about-us",
          "checkedAt": "2026-10-10",
          "observation": "Vendor says the IoT-Inspector platform launched in 2020 as a SEC Consult spin-off, rebranded to ONEKEY in 2022, and its growing team in Germany, Hungary, Austria and Belgium developed the Compliance Wizard."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.onekey.com/de/imprint",
          "checkedAt": "2026-10-10",
          "observation": "ONEKEY GmbH lists its registered seat and street address in Düsseldorf, Germany. Combined with the company development account, this supports a German lead, not German-only engineering."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://app.eu.onekey.com/_next/static/chunks/pages/tos-1612795941.js",
          "checkedAt": "2026-10-10",
          "observation": "The /tos page loads this first-party JavaScript bundle, which embeds terms describing ONEKEY-hosted Services, corporate-customer license keys and reserved IP rights. The embedded terms are dated July 2020; current complete commercial terms were not verified."
        },
        {
          "claims": [
            "capabilities"
          ],
          "url": "https://docs.onekey.com/platform-guide/how-analyze/",
          "checkedAt": "2026-10-10",
          "observation": "Official guide covers firmware extraction, software-component identification, CVE matching and binary analysis. It describes how the platform works rather than promising exhaustive detection."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://docs.onekey.com/",
          "checkedAt": "2026-10-10",
          "observation": "Official documentation front page was updated 16 September 2026 and continues to link live platform/API guides; an update is not an assurance of support or scan accuracy."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://docs.onekey.com/platform-guide/how-analyze/firmware-extraction/",
          "checkedAt": "2026-10-10",
          "observation": "Documentation distinguishes the open-source unblob firmware extractor from the ONEKEY platform that invokes it."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "openaev",
      "name": "OpenAEV",
      "maker": "Filigran",
      "country": "France",
      "workflow": "Exposure discovery",
      "format": "Open core",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Adversarial exposure validation platform for planning and running attack simulations, measuring defensive coverage, and tracking remediation against tested scenarios.",
      "origin": "Designed and developed by French company Filigran; formerly named OpenBAS.",
      "originClass": "EU-developed",
      "facts": [
        "Runs simulation campaigns and individual tests against selected targets.",
        "Reports validation results to help prioritize remediation.",
        "Community Edition is Apache-2.0; Enterprise Edition has a separate license."
      ],
      "sources": [
        {
          "label": "Upstream repository and README",
          "url": "https://github.com/OpenAEV-Platform/openaev"
        },
        {
          "label": "Upstream license",
          "url": "https://github.com/OpenAEV-Platform/openaev/blob/main/LICENSE"
        },
        {
          "label": "Official OpenBAS rebrand announcement",
          "url": "https://filigran.io/press-releases/filigran-redefines-proactive-security-openbas-rebrands-to-openaev-with-an-ai-powered-enterprise-edition"
        },
        {
          "label": "Filigran product and deployment",
          "url": "https://filigran.io/products/openaev"
        },
        {
          "label": "Current edition license agreements",
          "url": "https://filigran.io/licenses"
        },
        {
          "label": "Filigran France legal identity",
          "url": "https://filigran.io/privacy-policy"
        },
        {
          "label": "Releases",
          "url": "https://github.com/OpenAEV-Platform/openaev/releases"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Mixed: Apache-2.0 Community Edition; OpenAEV Enterprise Edition License",
      "maintenance": "Active",
      "scopeNote": "OpenBAS is the previous name, not a separate product. Adversary validation is an imperfect fit for the current Exposure discovery workflow label.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment",
            "maintenance"
          ],
          "url": "https://github.com/OpenAEV-Platform/openaev",
          "checkedAt": "2026-10-10",
          "observation": "The upstream README describes simulation and validation functions, names Filigran as designer/developer, documents Docker/manual installation, and says development is ongoing."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://filigran.io/privacy-policy",
          "checkedAt": "2026-10-10",
          "observation": "Filigran's current privacy policy identifies Filigran SAS as its French group entity at 66 avenue des Champs Élysées, Paris."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/OpenAEV-Platform/openaev/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The license identifies Apache-2.0 for Community Edition and a distinct proprietary Enterprise Edition license."
        },
        {
          "claims": [
            "identity"
          ],
          "url": "https://filigran.io/press-releases/filigran-redefines-proactive-security-openbas-rebrands-to-openaev-with-an-ai-powered-enterprise-edition",
          "checkedAt": "2026-10-10",
          "observation": "Filigran explicitly says OpenBAS was renamed OpenAEV; it is not an additional independent product."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://filigran.io/products/openaev",
          "checkedAt": "2026-10-10",
          "observation": "Filigran offers self-hosted Community and Enterprise editions plus a fully managed OpenAEV Enterprise Edition SaaS service, separate from its trial."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://filigran.io/licenses",
          "checkedAt": "2026-10-10",
          "observation": "Filigran's current license page links a separate OpenAEV Enterprise Edition agreement and says Community Edition remains Apache-2.0."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "opencve",
      "name": "OpenCVE",
      "maker": "Amber Security / OpenCVE project",
      "country": "France",
      "workflow": "Exposure discovery",
      "format": "Source available",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Tracks published vulnerabilities for selected vendors and products, with CVE filtering, subscriptions, notifications and shared remediation tracking for security teams.",
      "origin": "OpenCVE identifies Amber Security SAS as its publisher; the French company describes OpenCVE as its own vulnerability-monitoring solution and lists its registered office in Lille.",
      "originClass": "EU-developed",
      "facts": [
        "Vendor and product CVE subscriptions",
        "Risk filtering and notification workflows",
        "Docker deployment or hosted Cloud service"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/opencve/opencve"
        },
        {
          "label": "Current software license",
          "url": "https://github.com/opencve/opencve/blob/master/LICENSE"
        },
        {
          "label": "Deployment documentation",
          "url": "https://docs.opencve.io/deployment/"
        },
        {
          "label": "Project creators and publisher",
          "url": "https://www.opencve.io/about"
        },
        {
          "label": "Publisher and French legal identity",
          "url": "https://ambersecurity.solutions/"
        },
        {
          "label": "Hosted service terms",
          "url": "https://www.opencve.io/terms"
        },
        {
          "label": "Upstream changelog",
          "url": "https://github.com/opencve/opencve/blob/master/CHANGELOG.md"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "BUSL-1.1",
      "maintenance": "Active",
      "scopeNote": "The current Community code uses Business Source License 1.1, not an open-source license. Its additional grant restricts commercial security monitoring and alerting services for third parties; separate commercial terms may be needed. The inspected license names a 2030-08-14 change date to Apache-2.0 for that version. The hosted Cloud service has separate commercial terms; Cloud-only features are not assumed to be included in Community. This tracks disclosed CVEs and does not scan assets for vulnerabilities.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://github.com/opencve/opencve",
          "checkedAt": "2026-10-10",
          "observation": "The upstream README describes a vulnerability-intelligence application with vendor/product subscriptions, CVE filters, notifications and team workflows; it separates Community from Cloud features."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.opencve.io/about",
          "checkedAt": "2026-10-10",
          "observation": "OpenCVE names its two creators and identifies the publisher as Amber Security SAS."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://ambersecurity.solutions/",
          "checkedAt": "2026-10-10",
          "observation": "Amber Security describes creating its OpenCVE solution and gives its French SAS registration and Lille office. This establishes the French publisher/steward, not every contributor location."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/opencve/opencve/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE text is Business Source License 1.1 with an additional-use restriction on providing commercial security monitoring and alerting services to third parties. It explicitly is not an open-source license; the inspected version changes to Apache-2.0 on 2030-08-14."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://docs.opencve.io/deployment/",
          "checkedAt": "2026-10-10",
          "observation": "Current installation documentation describes a complete Docker stack and directs users to OpenCVE Cloud as the hosted option."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://www.opencve.io/terms",
          "checkedAt": "2026-10-10",
          "observation": "The official service agreement governs subscription-based SaaS access and limits customer rights; the hosted service is not covered by a blanket open-source grant."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/opencve/opencve/blob/master/CHANGELOG.md",
          "checkedAt": "2026-10-10",
          "observation": "The upstream changelog records version 3.1.0 on 2026-08-14 with API and access-control changes. Release activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "openvas-scan",
      "name": "OPENVAS SCAN",
      "maker": "Greenbone",
      "country": "Germany",
      "workflow": "Exposure discovery",
      "format": "Commercial",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Vulnerability scanner for networks, endpoints, and containers with authenticated checks, risk prioritization, remediation guidance, and virtual-appliance deployment.",
      "origin": "Greenbone explicitly says OPENVAS SCAN was developed in Germany and remains its German product stewardship; upstream open-source components and paid feed differ in license.",
      "originClass": "EU-developed",
      "facts": [
        "Scans network services, endpoints, and container images.",
        "Runs as customer-hosted virtual or hardware appliance.",
        "Enterprise Feed is subscription controlled despite open-licensed individual tests."
      ],
      "sources": [
        {
          "label": "OPENVAS SCAN product",
          "url": "https://www.greenbone.net/en/openvas-scan/"
        },
        {
          "label": "Greenbone license details",
          "url": "https://www.greenbone.net/en/license-information/"
        },
        {
          "label": "Rename and lifecycle",
          "url": "https://www.greenbone.net/en/roadmap-lifecycle/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Mixed: open-source software packages and tests; subscription-controlled OPENVAS ENTERPRISE FEED database and access key",
      "maintenance": "Active",
      "scopeNote": "The previous Greenbone Enterprise Appliance name now maps to OPENVAS SCAN. The Enterprise Feed as a whole has subscription restrictions; no blanket proprietary or fully open-source label is accurate.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.greenbone.net/en/openvas-scan/",
          "checkedAt": "2026-10-10",
          "observation": "Greenbone says OPENVAS SCAN was developed in Germany, describes scanning features and shows hardware and virtual deployment."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.greenbone.net/en/license-information/",
          "checkedAt": "2026-10-10",
          "observation": "Greenbone's license page distinguishes open-licensed component packages and individual vulnerability tests from subscription restrictions on the Enterprise Feed database and access key."
        },
        {
          "claims": [
            "identity",
            "maintenance"
          ],
          "url": "https://www.greenbone.net/en/roadmap-lifecycle/",
          "checkedAt": "2026-10-10",
          "observation": "The official lifecycle page maps the former Greenbone Enterprise Appliance to OPENVAS SCAN as its current product name."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "openwec",
      "name": "OpenWEC",
      "maker": "CEA IT Security",
      "country": "France",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Desktop/CLI"
      ],
      "description": "Linux-based Windows Event Collector server that receives source-initiated event forwarding without installing an additional Windows agent.",
      "origin": "Published and maintained by CEA IT Security within the French national commission.",
      "originClass": "Institution-led",
      "facts": [
        "Receives Windows event logs using the built-in Windows Event Forwarding protocol.",
        "Runs a Linux server with a CLI for subscription management.",
        "Supports source-initiated push mode."
      ],
      "sources": [
        {
          "label": "Upstream OpenWEC README",
          "url": "https://github.com/cea-sec/openwec"
        },
        {
          "label": "CEA IT Security portfolio",
          "url": "https://github.com/cea-sec"
        },
        {
          "label": "Upstream license",
          "url": "https://github.com/cea-sec/openwec/blob/main/LICENSE"
        }
      ],
      "license": "GPL-3.0-or-later",
      "maintenance": "Active",
      "scopeNote": "Log collection infrastructure, not a detector or SIEM by itself; source-initiated push is the only WEF mode documented as supported.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment",
            "license"
          ],
          "url": "https://github.com/cea-sec/openwec",
          "checkedAt": "2026-10-10",
          "observation": "README describes a GPLv3-or-later Linux WEC server and management CLI, agentless Windows collection, and the source-initiated push limitation."
        },
        {
          "claims": [
            "origin",
            "country",
            "maintenance"
          ],
          "url": "https://github.com/cea-sec",
          "checkedAt": "2026-10-10",
          "observation": "CEA IT Security identifies its French commission affiliation and lists OpenWEC with September 2026 repository activity."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "oradad",
      "name": "ORADAD",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Exposure discovery",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Windows command-line utility that exports Active Directory data through LDAP, including multi-domain forests, to support directory security audits and investigations.",
      "origin": "Published in ANSSI’s official project organization by the French national cybersecurity agency.",
      "originClass": "Institution-led",
      "facts": [
        "Exports Active Directory data via LDAP.",
        "Supports multi-domain forests.",
        "Provides configurable x86 and x64 executable releases."
      ],
      "sources": [
        {
          "label": "Upstream repository",
          "url": "https://github.com/ANSSI-FR/ORADAD"
        },
        {
          "label": "Official release list",
          "url": "https://github.com/ANSSI-FR/ORADAD/releases"
        },
        {
          "label": "ANSSI portfolio",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        }
      ],
      "license": "GPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Primarily documented as an audit data collector rather than a complete vulnerability scanner or incident response platform.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment",
            "license"
          ],
          "url": "https://github.com/ANSSI-FR/ORADAD",
          "checkedAt": "2026-10-10",
          "observation": "README says ORADAD dumps LDAP data for security audits, supports multi-domain forests and is invoked as a Windows executable; repository carries GPL-3.0."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI organization profile states its repositories are projects developed by the French agency."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/ORADAD/releases",
          "checkedAt": "2026-10-10",
          "observation": "Official releases list v3.6.220b in July 2026, primarily extending executable validity dates."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "oradaz",
      "name": "ORADAZ",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Exposure discovery",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Beta command-line utility that dumps Azure configuration data through REST APIs to support security audits and manual exposure review.",
      "origin": "Published by ANSSI, the French national cybersecurity agency, in its official project organization.",
      "originClass": "Institution-led",
      "facts": [
        "Collects Azure configuration through REST APIs.",
        "Runs as an executable using an adjacent XML configuration file.",
        "Upstream explicitly marks the project beta."
      ],
      "sources": [
        {
          "label": "Upstream ORADAZ README",
          "url": "https://github.com/ANSSI-FR/ORADAZ"
        },
        {
          "label": "Upstream GPL-3.0 license",
          "url": "https://github.com/ANSSI-FR/ORADAZ/blob/main/LICENSE.md"
        },
        {
          "label": "ANSSI open-source portfolio",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        }
      ],
      "license": "GPL-3.0",
      "maintenance": "Experimental",
      "scopeNote": "Upstream says beta and positions it for Azure security audits, not automated incident response or a general cloud posture platform.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment",
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/ORADAZ",
          "checkedAt": "2026-10-10",
          "observation": "README labels ORADAZ beta and says it dumps Azure data through REST APIs for security audits; usage invokes oradaz.exe with an adjacent XML configuration."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/ANSSI-FR/ORADAZ/blob/main/LICENSE.md",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license is GNU General Public License version 3."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI states its official repositories contain projects developed by the French national cybersecurity agency."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "orc2timeline",
      "name": "orc2timeline",
      "maker": "ANSSI",
      "country": "France",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Local command-line utility that processes one or more DFIR ORC forensic archives and creates a per-host timeline for incident analysis.",
      "origin": "Published in ANSSI’s official GitHub organization as a standalone forensic parser.",
      "originClass": "Institution-led",
      "facts": [
        "Accepts one or more ORC archives.",
        "Groups archives by host and writes compressed CSV timelines.",
        "Installs as a Python package with pip."
      ],
      "sources": [
        {
          "label": "Upstream README",
          "url": "https://github.com/ANSSI-FR/orc2timeline"
        },
        {
          "label": "ANSSI portfolio",
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md"
        },
        {
          "label": "Upstream license",
          "url": "https://github.com/ANSSI-FR/orc2timeline/blob/main/LICENSE"
        }
      ],
      "license": "LGPL-3.0",
      "maintenance": "Unknown",
      "scopeNote": "Narrow parser dependent on DFIR ORC archives; current maintenance cadence was not verified. Distinct timeline output from DFIR-OGRE’s general structured extraction.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment",
            "license"
          ],
          "url": "https://github.com/ANSSI-FR/orc2timeline",
          "checkedAt": "2026-10-10",
          "observation": "README documents pip installation, processing ORC archive directories, host grouping and compressed CSV timelines; repository labels the license LGPL-3.0."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/ANSSI-FR/.github/blob/main/profile/README.en.md",
          "checkedAt": "2026-10-10",
          "observation": "ANSSI profile says repositories in its organization are projects developed by the French agency."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/ANSSI-FR/orc2timeline",
          "checkedAt": "2026-10-10",
          "observation": "Upstream page does not establish a current release or maintenance schedule, so status remains unknown."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "outpost24-compassdrp",
      "name": "Outpost24 CompassDRP",
      "maker": "Outpost24",
      "country": "Sweden",
      "workflow": "Threat intelligence",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Cloud digital-risk product that combines external asset discovery with threat intelligence and monitors exposed credentials, leaked data, and phishing domains.",
      "origin": "Outpost24 began product development in Sweden and still has a development team at its Karlskrona headquarters; it also operates outside the EU. The exact engineering allocation for this product is not public.",
      "originClass": "EU-developed",
      "facts": [
        "Combines attack-surface discovery, digital risk monitoring, and threat intelligence.",
        "Monitors stolen credentials, leaked data, and phishing domains.",
        "Vendor calls it a cloud-based solution."
      ],
      "sources": [
        {
          "label": "CompassDRP product",
          "url": "https://outpost24.com/products/compass-drp/"
        },
        {
          "label": "Outpost24 company origin",
          "url": "https://outpost24.com/company/"
        },
        {
          "label": "Blueliv acquisition",
          "url": "https://outpost24.com/blog/outpost24-acquires-threat-intelligence-solution-blueliv/"
        },
        {
          "label": "Outpost24 AB master agreement",
          "url": "https://outpost24.com/wp-content/uploads/2026/06/Outpost24-AB-Master-Agreement-June-2026.pdf"
        },
        {
          "label": "Karlskrona development team",
          "url": "https://careers.outpost24.com/locations/karlskrona-se"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "CompassDRP combines Outpost24’s Swedish line with acquired Spanish Blueliv technology. Engineering spans locations, and ultimate control and hosting region are unverified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://outpost24.com/products/compass-drp/",
          "checkedAt": "2026-10-10",
          "observation": "The current commercial page calls CompassDRP a cloud solution combining asset discovery and threat intelligence with digital-risk monitoring."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://outpost24.com/company/",
          "checkedAt": "2026-10-10",
          "observation": "Outpost24 describes its Swedish founding and continuing security product development, while indicating its present international footprint."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://outpost24.com/blog/outpost24-acquires-threat-intelligence-solution-blueliv/",
          "checkedAt": "2026-10-10",
          "observation": "Outpost24's announcement records acquisition of Barcelona-based threat-intelligence developer Blueliv, a predecessor line for current digital-risk functionality."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://outpost24.com/wp-content/uploads/2026/06/Outpost24-AB-Master-Agreement-June-2026.pdf",
          "checkedAt": "2026-10-10",
          "observation": "The June 2026 Outpost24 AB agreement grants a limited customer license, ties use to the paid agreement, and reserves product intellectual-property rights."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://outpost24.com/products/compass-drp/",
          "checkedAt": "2026-10-10",
          "observation": "At review on 10 October 2026 the vendor actively offered CompassDRP through a current product page; no release cadence was inferred."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://careers.outpost24.com/locations/karlskrona-se",
          "checkedAt": "2026-10-10",
          "observation": "Outpost24’s current Karlskrona location page says a development team shares its Swedish headquarters; it also lists an IT Development opening there. This confirms current EU engineering presence, not EU-only development or product-specific team allocation."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "outpost24-outscannx",
      "name": "Outpost24 OutscanNX",
      "maker": "Outpost24",
      "country": "Sweden",
      "workflow": "Exposure discovery",
      "format": "Commercial",
      "deployment": [
        "SaaS",
        "Self-hosted"
      ],
      "description": "Vulnerability management product that scans network and cloud assets, prioritizes findings with exploit context, and tracks remediation through reports and workflows.",
      "origin": "Outpost24 began product development in Sweden and still has a development team at its Karlskrona headquarters; it also operates outside the EU. The exact engineering allocation for this product is not public.",
      "originClass": "EU-developed",
      "facts": [
        "Continuously identifies vulnerabilities across network and cloud assets.",
        "Prioritizes with exploit intelligence, asset context, CVSS, EPSS, and KEV.",
        "Vendor offers SaaS, hybrid, and on-premises delivery."
      ],
      "sources": [
        {
          "label": "OutscanNX product",
          "url": "https://outpost24.com/products/risk-based-vulnerability-management/"
        },
        {
          "label": "Outpost24 company history",
          "url": "https://outpost24.com/company/"
        },
        {
          "label": "Outpost24 AB master agreement",
          "url": "https://outpost24.com/wp-content/uploads/2026/06/Outpost24-AB-Master-Agreement-June-2026.pdf"
        },
        {
          "label": "Outscan NX service terms",
          "url": "https://outpost24.com/wp-content/uploads/2025/05/Service-Specific-Terms-Outpost24-Outscan-NX.pdf"
        },
        {
          "label": "Karlskrona development team",
          "url": "https://careers.outpost24.com/locations/karlskrona-se"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "Outpost24’s own history mentions a Vietnam software park. Swedish product origin and a current Karlskrona development team do not establish EU-only engineering or hosting.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://outpost24.com/products/risk-based-vulnerability-management/",
          "checkedAt": "2026-10-10",
          "observation": "The current commercial product page names OutscanNX, explains vulnerability assessment and risk prioritization, and lists SaaS, hybrid, and on-premises deployment."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://outpost24.com/company/",
          "checkedAt": "2026-10-10",
          "observation": "Company history says the original Swedish team automated ethical-hacker vulnerability scanning, pioneered scanning as a service, and later opened a Vietnam software park."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://outpost24.com/wp-content/uploads/2026/06/Outpost24-AB-Master-Agreement-June-2026.pdf",
          "checkedAt": "2026-10-10",
          "observation": "The June 2026 Outpost24 AB agreement grants a limited customer license, ties use to the paid agreement, and reserves product intellectual-property rights."
        },
        {
          "claims": [
            "license",
            "maintenance"
          ],
          "url": "https://outpost24.com/wp-content/uploads/2025/05/Service-Specific-Terms-Outpost24-Outscan-NX.pdf",
          "checkedAt": "2026-10-10",
          "observation": "The vendor’s May 2025 product-specific terms name Outscan NX and its annual asset-based subscription; the current 2026 product page continues to offer it."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://outpost24.com/products/risk-based-vulnerability-management/",
          "checkedAt": "2026-10-10",
          "observation": "At review on 10 October 2026 the vendor actively offered OutscanNX through its product page; this is offer visibility, not a claim of release quality."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://careers.outpost24.com/locations/karlskrona-se",
          "checkedAt": "2026-10-10",
          "observation": "Outpost24’s current Karlskrona location page says a development team shares its Swedish headquarters; it also lists an IT Development opening there. This confirms current EU engineering presence, not EU-only development or product-specific team allocation."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "pandora",
      "name": "Pandora",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports.",
      "origin": "The README credits CIRCL and Raphaël Vinot in Luxembourg, alongside CERT-AG, for Pandora’s development.",
      "originClass": "CSIRT-led",
      "facts": [
        "Combines file checks including YARA and configured external analysis workers.",
        "Offers file previews and shareable analysis results."
      ],
      "sources": [
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/pandora-analysis/pandora"
        },
        {
          "label": "Software license",
          "url": "https://github.com/pandora-analysis/pandora/blob/main/LICENSE"
        },
        {
          "label": "CIRCL service description",
          "url": "https://www.circl.lu/services/pandora-document-analysis/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0-or-later",
      "maintenance": "Active",
      "scopeNote": "This is static file analysis. Configured external workers may receive files or metadata; CIRCL’s public instance has its own documented sharing policy.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/pandora-analysis/pandora",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/pandora-analysis/pandora",
          "checkedAt": "2026-10-10",
          "observation": "The README credits CIRCL and Raphaël Vinot in Luxembourg, alongside CERT-AG, for Pandora’s development."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/pandora-analysis/pandora/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0-or-later."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/pandora-analysis/pandora",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "identity",
            "origin",
            "country"
          ],
          "url": "https://www.circl.lu/services/pandora-document-analysis/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL operates Pandora as its document and file analysis service."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/pandora-analysis/pandora",
          "checkedAt": "2026-10-10",
          "observation": "The README applies version 3 or any later version to this software."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://www.circl.lu/services/pandora-document-analysis/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL’s current service page explicitly offers public access and documents running a private instance."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "yara",
          "note": "A YARA worker compiles local .yar rules and scans submitted file content. The worker disables itself when no usable rules are available.",
          "sources": [
            {
              "label": "Pandora YARA worker implementation",
              "url": "https://github.com/pandora-analysis/pandora/blob/main/pandora/workers/yara.py"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "originClass": "EU-developed",
      "format": "Commercial",
      "maintenance": "Active",
      "reviewedAt": "2026-10-10",
      "slug": "pentest-tools-platform",
      "name": "Pentest-Tools.com",
      "maker": "PentestTools S.A.",
      "country": "Romania",
      "workflow": "Exposure discovery",
      "deployment": [
        "SaaS"
      ],
      "description": "Hosted security testing platform for scanning and validating vulnerabilities in web applications, networks and cloud infrastructure, with findings and reporting workflows.",
      "origin": "Built by the Bucharest-based Pentest-Tools.com team; Romanian company and platform licensor are identified in its public terms.",
      "facts": [
        "Scans web applications, networks and cloud infrastructure.",
        "Provides continuous vulnerability scanning and validation, findings management and reports.",
        "Customers access the hosted platform or API under a restricted internal-use license."
      ],
      "sources": [
        {
          "label": "Company and platform",
          "url": "https://pentest-tools.com/about"
        },
        {
          "label": "Platform terms and license",
          "url": "https://pentest-tools.com/legal/terms-of-service"
        },
        {
          "label": "2026 product update",
          "url": "https://pentest-tools.com/blog/new-website-brand-update"
        }
      ],
      "license": "Proprietary",
      "scopeNote": "The public terms require authorization for tested targets; hosted data location and any separately contracted service scope need buyer review.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities"
          ],
          "url": "https://pentest-tools.com/about",
          "checkedAt": "2026-10-10",
          "observation": "The company says its Bucharest team has built detection, validation and exploitation capabilities since 2017; it distinguishes software platform testing from human-led offensive services and lists web, network and cloud scans."
        },
        {
          "claims": [
            "country",
            "deployment",
            "license"
          ],
          "url": "https://pentest-tools.com/legal/terms-of-service",
          "checkedAt": "2026-10-10",
          "observation": "Terms identify PentestTools S.A. as a Romanian company; platform is at app.pentest-tools.com or API. Intellectual-property section grants limited, nonexclusive, nontransferable internal testing use and prohibits copying, redistribution and reverse engineering."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://pentest-tools.com/blog/new-website-brand-update",
          "checkedAt": "2026-10-10",
          "observation": "The vendor's 2026 website/product update is dated September 2026 and describes the continuing hosted product and its new platform presentation."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "plum-island",
      "name": "Plum Island",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Exposure discovery",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Schedule distributed perimeter scans, retain observations over time and search changes in exposed services and technical metadata.",
      "origin": "The CIRCL-led D4 project describes Plum as its project for monitoring Luxembourg’s perimeter and explains its development within FETTA.",
      "originClass": "CSIRT-led",
      "facts": [
        "Orchestrates scan jobs across agents and target profiles.",
        "Searches retained observations and exports reports or CSV/JSON results."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/D4-project/Plum-Island"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://www.d4-project.org/2026/04/29/Plum-knowing-and-monitoring-your-perimeter.html"
        },
        {
          "label": "Software license",
          "url": "https://github.com/D4-project/Plum-Island/blob/main/LICENSE"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Experimental",
      "scopeNote": "The upstream README labels it beta. It orchestrates discovery and exposure monitoring; it is not a standalone vulnerability-verdict engine.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/D4-project/Plum-Island",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes schedule distributed perimeter scans, retain observations over time and search changes in exposed services and technical metadata. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.d4-project.org/2026/04/29/Plum-knowing-and-monitoring-your-perimeter.html",
          "checkedAt": "2026-10-10",
          "observation": "The CIRCL-led D4 project describes Plum as its project for monitoring Luxembourg’s perimeter and explains its development within FETTA."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/D4-project/Plum-Island/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/D4-project/Plum-Island",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-10-08. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/D4-project/Plum-Island",
          "checkedAt": "2026-10-10",
          "observation": "The upstream README explicitly describes the software as beta or experimental."
        }
      ],
      "funding": [
        {
          "programme": "Digital Europe Programme (DEP)",
          "project": "FETTA",
          "grantId": "101128030",
          "scope": "The April 2026 Plum announcement attributes development support to FETTA. This applies to the perimeter monitoring project and does not assign it the older D4 grant.",
          "sources": [
            {
              "label": "D4 project announcement: Plum and FETTA funding",
              "url": "https://www.d4-project.org/2026/04/29/Plum-knowing-and-monitoring-your-perimeter.html"
            },
            {
              "label": "CIRCL FETTA project announcement",
              "url": "https://circl.lu/pub/press/20240131/"
            },
            {
              "label": "CERT Polska 2024 report, JTAN and FETTA sections (printed pages 75–82)",
              "url": "https://cert.pl/uploads/docs/Report_CP_2024.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "secvisogram",
      "name": "Secvisogram",
      "maker": "German Federal Office for Information Security (BSI)",
      "country": "Germany",
      "workflow": "Response coordination",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Creates and edits machine-readable CSAF security advisories in a web interface for coordinated publication and exchange of vulnerability information.",
      "origin": "BSI's official repository identifies Secvisogram as its CSAF web editor; BSI is a German federal institution based in Bonn.",
      "originClass": "Institution-led",
      "facts": [
        "CSAF 2.0 and 2.1 advisory editor",
        "Web-based validation and editing",
        "Self-deployment documentation"
      ],
      "sources": [
        {
          "label": "Upstream editor",
          "url": "https://github.com/BSI-Bund/secvisogram"
        },
        {
          "label": "Actual MIT license",
          "url": "https://github.com/BSI-Bund/secvisogram/blob/main/LICENSE"
        },
        {
          "label": "BSI project organization",
          "url": "https://github.com/BSI-Bund"
        },
        {
          "label": "Upstream branch activity",
          "url": "https://github.com/BSI-Bund/secvisogram/commits/main.atom"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "MIT",
      "maintenance": "Active",
      "scopeNote": "This is an advisory authoring and validation editor, not a vulnerability scanner or managed disclosure service. A demo URL alone is not treated as generally available hosted service.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/BSI-Bund/secvisogram",
          "checkedAt": "2026-10-10",
          "observation": "README identifies BSI Secvisogram as a CSAF 2.0/2.1 web editor, with documentation to run the application in a self-hosted environment."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/BSI-Bund",
          "checkedAt": "2026-10-10",
          "observation": "Repository belongs to official BSI project organization, whose page lists the German federal office in Bonn."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/BSI-Bund/secvisogram/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual root license is MIT, with BSI copyright."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/BSI-Bund/secvisogram/commits/main.atom",
          "checkedAt": "2026-10-10",
          "observation": "Upstream default-branch Atom feed records a commit on 2026-06-23; branch activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "sekoia-defend",
      "name": "Sekoia Defend",
      "maker": "Sekoia",
      "country": "France",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Cloud security operations product that ingests telemetry, applies detection rules, supports alert and case investigation, and runs automated playbooks.",
      "origin": "Built by Sekoia.io SAS, a French security software company with its registered office in Rennes.",
      "originClass": "EU-developed",
      "facts": [
        "Collects logs from endpoints, cloud services, networks and applications.",
        "Applies detection rules and provides alert triage and case management.",
        "Runs playbooks for enrichment and response."
      ],
      "sources": [
        {
          "label": "Sekoia product overview",
          "url": "https://docs.sekoia.com/getting_started/what_is_sekoia/"
        },
        {
          "label": "Sekoia Defend product",
          "url": "https://www.sekoia.com/platform/defend"
        },
        {
          "label": "Subscription model",
          "url": "https://docs.sekoia.com/getting_started/understand_your_subscription/"
        },
        {
          "label": "Sekoia company origin",
          "url": "https://www.sekoia.com/about"
        },
        {
          "label": "French legal notice",
          "url": "https://www.sekoia.com/legal-notice"
        }
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Sekoia hosts the core platform; on-premises playbook runners do not imply an on-premises Defend product. Reveal and Elevate are dependent add-ons. Full product license terms were not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://docs.sekoia.com/getting_started/what_is_sekoia/",
          "checkedAt": "2026-10-10",
          "observation": "Sekoia documentation identifies Defend as a core XDR product with log collection, detection, triage, case investigation and playbooks."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.sekoia.com/about",
          "checkedAt": "2026-10-10",
          "observation": "The company describes its founding team and says they built a European cybersecurity software company and platform."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.sekoia.com/legal-notice",
          "checkedAt": "2026-10-10",
          "observation": "The legal notice identifies Sekoia.io SAS and its registered office in Rennes, France."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://docs.sekoia.com/getting_started/understand_your_subscription/",
          "checkedAt": "2026-10-10",
          "observation": "Official subscription documentation says Defend is licensed as a distinct paid product and identifies subscription tiers. It does not publish customer software rights or full product terms."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://docs.sekoia.com/getting_started/what_is_sekoia/",
          "checkedAt": "2026-10-10",
          "observation": "Current documentation describes the active Defend product and current platform features; no ceased-support notice appears."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": [
        {
          "id": "sigma",
          "note": "Applies Sigma detections and correlation rules to normalized event streams. The documented syntax includes Sekoia-specific time modifiers, so rules may need adjustment when moved to another engine.",
          "sources": [
            {
              "label": "Sekoia Sigma rule documentation",
              "url": "https://docs.sekoia.com/xdr/features/detect/sigma/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "sekoia-intelligence",
      "name": "Sekoia Intelligence",
      "maker": "Sekoia",
      "country": "France",
      "workflow": "Threat intelligence",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Threat intelligence product with searchable actor, campaign, malware and indicator records, analyst reports, feeds, and APIs for dissemination to security systems.",
      "origin": "Built by Sekoia.io SAS and its threat research team in France; separately licensed from Sekoia Defend.",
      "originClass": "EU-developed",
      "facts": [
        "Searchable CTI records connect actors, malware, campaigns, infrastructure and indicators.",
        "Feeds, TAXII, MISP connectors and APIs distribute intelligence.",
        "Can be purchased independently of Defend as an API-delivered CTI product."
      ],
      "sources": [
        {
          "label": "Sekoia CTI documentation",
          "url": "https://docs.sekoia.com/cti/"
        },
        {
          "label": "Sekoia Intelligence product",
          "url": "https://www.sekoia.com/platform/intelligence"
        },
        {
          "label": "Independent subscription evidence",
          "url": "https://docs.sekoia.com/getting_started/understand_your_subscription/"
        },
        {
          "label": "French legal notice",
          "url": "https://www.sekoia.com/legal-notice"
        },
        {
          "label": "Sekoia company origin",
          "url": "https://www.sekoia.com/about"
        }
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Standalone Intelligence is API-delivered; platform UI availability and Defend integration depend on subscription. This is an independently licensable product, not a duplicate platform module. Full product license terms were not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://docs.sekoia.com/cti/",
          "checkedAt": "2026-10-10",
          "observation": "Official CTI docs describe searchable intelligence and explicitly state standalone API delivery, in addition to Defend-integrated availability."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://docs.sekoia.com/getting_started/understand_your_subscription/",
          "checkedAt": "2026-10-10",
          "observation": "Official subscription documentation says Intelligence is separately licensed and can be bought without Defend. It does not publish customer software rights or full product terms."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.sekoia.com/about",
          "checkedAt": "2026-10-10",
          "observation": "Sekoia attributes its software and threat research platform to its own French-founded team."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://www.sekoia.com/legal-notice",
          "checkedAt": "2026-10-10",
          "observation": "The legal notice gives Sekoia.io SAS registered office in Rennes, France."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.sekoia.com/platform/intelligence",
          "checkedAt": "2026-10-10",
          "observation": "Current official product page offers Intelligence and describes analyst-maintained records and integrations."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": [
        {
          "id": "taxii",
          "note": "Exposes intelligence collections through TAXII 2.1. Access requires an Intelligence Center API key and the corresponding service access.",
          "sources": [
            {
              "label": "Sekoia TAXII integration guide",
              "url": "https://docs.sekoia.com/cti/features/integrations/taxii/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "stix",
          "note": "Uses STIX 2.1 for intelligence objects and exports contextualized indicators through its CTI feed. The documented CTI feed exports indicators rather than raw observables.",
          "sources": [
            {
              "label": "Sekoia Intelligence data model",
              "url": "https://docs.sekoia.com/cti/features/data_model/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "originClass": "EU-developed",
      "format": "Commercial",
      "maintenance": "Active",
      "reviewedAt": "2026-10-10",
      "slug": "stormshield-endpoint-security-evolution",
      "name": "Stormshield Endpoint Security Evolution",
      "maker": "Stormshield",
      "country": "France",
      "workflow": "Detection and monitoring",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Endpoint detection and response software for workstations and servers, with behavioral detection, YARA-based hunting and predefined or custom remediation actions.",
      "origin": "Stormshield states that all of its R&D teams and product development are in France; it identifies Airbus Defence and Space Cyber Programmes as owner.",
      "facts": [
        "Detects and blocks suspicious endpoint activity with a local agent.",
        "Supports YARA hunting, IOC searches and incident-remediation actions.",
        "Available as on-premises software or SaaS."
      ],
      "sources": [
        {
          "label": "Endpoint Security Evolution product",
          "url": "https://www.stormshield.com/products-services/products/endpoint-protection/stormshield-endpoint-security/"
        },
        {
          "label": "French development and ownership",
          "url": "https://www.stormshield.com/fr/produits-certifies-et-qualifies/"
        },
        {
          "label": "Sales and software IP terms",
          "url": "https://www.stormshield.com/fr/conditions-generales-de-vente-et-de-service/"
        },
        {
          "label": "2026 product lifecycle",
          "url": "https://documentation.stormshield.com/PLC/SES/Evolution/fr/Content/PDF/ses-fr-ses_evolution-guide_cycle_de_vie_produits.pdf"
        }
      ],
      "license": "Commercial license; full terms not publicly verified",
      "scopeNote": "Stormshield's general sales terms reserve rights in its software but defer product-specific grants to separate contracts; SES Evolution's full customer license was not publicly verified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.stormshield.com/products-services/products/endpoint-protection/stormshield-endpoint-security/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor product page names SES Evolution, describes behavioral detection, YARA/IoC search and remediation, and offers on-premises and SaaS deployments."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.stormshield.com/fr/produits-certifies-et-qualifies/",
          "checkedAt": "2026-10-10",
          "observation": "Stormshield says all its R&D and development are carried out in France, lists Endpoint Security Evolution, and identifies its Airbus Defence and Space Cyber Programmes parent."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.stormshield.com/fr/conditions-generales-de-vente-et-de-service/",
          "checkedAt": "2026-10-10",
          "observation": "General product terms state Stormshield retains IP in its software and customer rights are defined by a separate license contract; SES Evolution's complete grant was not published on this page."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://documentation.stormshield.com/PLC/SES/Evolution/fr/Content/PDF/ses-fr-ses_evolution-guide_cycle_de_vie_produits.pdf",
          "checkedAt": "2026-10-10",
          "observation": "Stormshield publishes a 2026 lifecycle guide for the current SES Evolution product line, evidencing ongoing version support."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "suspicious",
      "name": "Suspicious",
      "maker": "Thales Group CERT",
      "country": "France",
      "workflow": "Malware analysis",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Triages suspicious emails, files, URLs and indicators through configurable analyzers, then presents investigation reports in a self-hosted web interface.",
      "origin": "The upstream project says Thales Group CERT built and maintains Suspicious; its lead contributor's profile lists Thales CERT in France.",
      "originClass": "CSIRT-led",
      "facts": [
        "Email and file triage",
        "Configurable indicator analyzers",
        "Web reports and optional mailbox intake"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/thalesgroup-cert/suspicious"
        },
        {
          "label": "Actual Apache license",
          "url": "https://github.com/thalesgroup-cert/suspicious/blob/main/LICENSE"
        },
        {
          "label": "Lead contributor profile",
          "url": "https://github.com/TheoBhang"
        },
        {
          "label": "Current project release",
          "url": "https://github.com/thalesgroup-cert/suspicious/releases/tag/v1.5.3"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Apache-2.0",
      "maintenance": "Active",
      "scopeNote": "Some analyzers depend on separately configured third-party services or credentials. Its verdicts and classifier outputs are triage aids, not verified determinations.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/thalesgroup-cert/suspicious",
          "checkedAt": "2026-10-10",
          "observation": "README says Suspicious is built and maintained by Thales Group CERT, analyzes emails, files, URLs and indicators, and documents Docker Compose self-hosting plus optional IMAP intake."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/TheoBhang",
          "checkedAt": "2026-10-10",
          "observation": "Lead contributor's self-reported profile identifies Thales CERT and France; this supports the lead location, not every contributor."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/thalesgroup-cert/suspicious/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual LICENSE contains Apache License version 2.0 text."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/thalesgroup-cert/suspicious/releases/tag/v1.5.3",
          "checkedAt": "2026-10-10",
          "observation": "Upstream v1.5.3 release was published 2026-10-08; release activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "cortex",
          "note": "Dispatches analysis jobs to a configured Cortex instance and processes returned reports. Analyzer identifiers must match installed Cortex analyzers; the documented configuration requires a shared webhook secret.",
          "sources": [
            {
              "label": "Suspicious integration configuration",
              "url": "https://github.com/thalesgroup-cert/suspicious/blob/master/CONFIG.md"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "yara",
          "note": "Runs the configured Yara_Boosted analyzer through Cortex during submission analysis. Requires that analyzer to be installed and configured in the connected Cortex instance.",
          "sources": [
            {
              "label": "Suspicious analyzer configuration",
              "url": "https://github.com/thalesgroup-cert/suspicious/blob/master/CONFIG.md"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "thehive",
          "note": "Optional connector creates TheHive cases or alerts from Suspicious verdicts after enabling and configuring TheHive API access.",
          "sources": [
            {
              "label": "Suspicious TheHive configuration",
              "url": "https://github.com/thalesgroup-cert/suspicious/blob/master/CONFIG.md"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "misp",
          "note": "Optional integration pushes indicators to one or more configured MISP instances, with configurable classification tags and API credentials per instance.",
          "sources": [
            {
              "label": "Suspicious MISP configuration",
              "url": "https://github.com/thalesgroup-cert/suspicious/blob/master/CONFIG.md"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "t-pot",
      "name": "T-Pot",
      "maker": "Deutsche Telekom Security",
      "country": "Germany",
      "workflow": "Detection and monitoring",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Combines multiple honeypots and a local analysis stack to collect, search and visualize attempted attacks against decoy network services.",
      "origin": "The upstream project is maintained by Deutsche Telekom Security GmbH, whose official GitHub organization identifies Bonn, Germany as its location.",
      "originClass": "EU-developed",
      "facts": [
        "Multiple integrated honeypots",
        "Attack event search and visualization",
        "Standalone or distributed deployment"
      ],
      "sources": [
        {
          "label": "Upstream project and deployment",
          "url": "https://github.com/telekom-security/tpotce"
        },
        {
          "label": "Actual project license",
          "url": "https://github.com/telekom-security/tpotce/blob/master/LICENSE"
        },
        {
          "label": "Deutsche Telekom Security organization",
          "url": "https://github.com/telekom-security"
        },
        {
          "label": "Upstream branch activity",
          "url": "https://github.com/telekom-security/tpotce/commits/master.atom"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Mixed: GPL-3.0 for T-Pot code; integrated components retain separate licenses",
      "maintenance": "Active",
      "scopeNote": "T-Pot packages third-party honeypots and an Elastic-based analysis stack under their own licenses, so the project GPL does not apply to every component. Honeypots are decoys and require deliberate network isolation and deployment planning.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/telekom-security/tpotce",
          "checkedAt": "2026-10-10",
          "observation": "README calls T-Pot an all-in-one multi-honeypot platform with more than 20 decoys and attack visualization; installation documents self-hosted standalone and distributed setups."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/telekom-security",
          "checkedAt": "2026-10-10",
          "observation": "Official upstream organization identifies Deutsche Telekom Security GmbH and its Bonn, Germany location; this establishes the project organization's country, not every contributor's location."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/telekom-security/tpotce/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Root LICENSE contains GNU GPL version 3 text."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/telekom-security/tpotce",
          "checkedAt": "2026-10-10",
          "observation": "README licenses section names different terms for bundled components, including Elastic-licensed software."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/telekom-security/tpotce/commits/master.atom",
          "checkedAt": "2026-10-10",
          "observation": "Upstream default-branch Atom feed records a commit on 2026-10-06; branch activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "elastic",
          "note": "Bundles an Elastic Stack pipeline for collecting and visualizing honeypot events. This documents the supplied T-Pot stack; compatibility with an independently managed Elastic deployment is not established here.",
          "sources": [
            {
              "label": "T-Pot technical concept",
              "url": "https://github.com/telekom-security/tpotce#technical-concept"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "suricata",
          "note": "Provides a Suricata container alongside honeypots for network security monitoring. Availability depends on the selected deployment configuration.",
          "sources": [
            {
              "label": "T-Pot bundled tools",
              "url": "https://github.com/telekom-security/tpotce#honeypots-and-tools"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "tehtris-edr",
      "name": "Tehtris EDR",
      "maker": "Tehtris",
      "country": "France",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Endpoint detection and response product that monitors execution and privilege activity, investigates suspicious behavior, and can block processes or isolate hosts.",
      "origin": "Tehtris identifies itself as a French company and says its EDR is designed, developed and operated in Europe.",
      "originClass": "EU-developed",
      "facts": [
        "Endpoint agent monitors workstations and servers for suspicious activity.",
        "Console supports fleet search, alert triage and configurable response.",
        "Can stop processes or isolate hosts according to policy."
      ],
      "sources": [
        {
          "label": "Current EDR product",
          "url": "https://tehtris.com/edr"
        },
        {
          "label": "About and European development",
          "url": "https://tehtris.com/a-propos"
        },
        {
          "label": "French head office",
          "url": "https://tehtris.com/contact"
        },
        {
          "label": "TEHTRIS XDR Platform SaaS terms",
          "url": "https://cdn.prod.website-files.com/6a79819d7fd2beeb1069ac7a/6abf7c50fce84cdd90d2d126_TEHTRIS%20%28REAK-T%29%20XDR%20CGU_2025%20FR.pdf"
        }
      ],
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "Current site promotes Tehtris EDR; older XDR AI Platform pages are stale or unavailable. The public product page describes managed European OVHcloud hosting; self-hosted deployment was not reverified.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://tehtris.com/edr",
          "checkedAt": "2026-10-10",
          "observation": "Current product page describes commercial Tehtris EDR, agent telemetry, investigation console, stopping processes and isolating hosts; it describes OVHcloud hosting and an optional SecNumCloud configuration."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://tehtris.com/a-propos",
          "checkedAt": "2026-10-10",
          "observation": "Tehtris says its EDR is designed, developed and operated in Europe and discusses its French cybersecurity company history."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://tehtris.com/contact",
          "checkedAt": "2026-10-10",
          "observation": "Official contact page labels its Paris address as the French headquarters."
        },
        {
          "claims": [
            "license",
            "deployment"
          ],
          "url": "https://cdn.prod.website-files.com/6a79819d7fd2beeb1069ac7a/6abf7c50fce84cdd90d2d126_TEHTRIS%20%28REAK-T%29%20XDR%20CGU_2025%20FR.pdf",
          "checkedAt": "2026-10-10",
          "observation": "TEHTRIS's linked XDR Platform terms grant a limited non-transferable SaaS use right, retain exclusive vendor ownership of service software, and explicitly list EDR, EPP and SIEM in the service scope."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://tehtris.com/edr",
          "checkedAt": "2026-10-10",
          "observation": "Current 2026 site actively offers Tehtris EDR, with current platform specifications and sales contact."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "tenzir",
      "name": "Tenzir",
      "maker": "Tenzir GmbH",
      "country": "Germany",
      "workflow": "Feed automation",
      "format": "Open core",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Collects, parses, transforms, enriches and routes security telemetry through programmable pipelines for detection, investigation and downstream security tools.",
      "origin": "Tenzir GmbH says it developed the current software and operates from Hamburg. Its preceding VAST research began at UC Berkeley; the German claim concerns the current company-led Tenzir product, not every historical contributor.",
      "originClass": "EU-developed",
      "facts": [
        "Programmable security-data pipelines",
        "Self-hosted nodes with CLI/container deployment",
        "Hosted control plane for Community and Enterprise editions"
      ],
      "license": "Mixed: BSD-3-Clause Open-Source Edition and Node code; proprietary App, Platform and Node extensions",
      "maintenance": "Active",
      "scopeNote": "The fully open-source Node can run locally; the Community and Enterprise App/Platform are proprietary and vendor-hosted, while their nodes also include closed-source parts. The free Community edition has a 1 TB/day ingress limit. Do not infer all prebuilt binaries are solely BSD-licensed; documentation says they may contain proprietary plugins.",
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/tenzir/tenzir"
        },
        {
          "label": "Actual repository license",
          "url": "https://github.com/tenzir/tenzir/blob/main/LICENSE"
        },
        {
          "label": "Edition terms and rights",
          "url": "https://tenzir.com/legal/terms-and-conditions/"
        },
        {
          "label": "German legal entity",
          "url": "https://tenzir.com/legal/notice/"
        },
        {
          "label": "Company and project origin",
          "url": "https://tenzir.com/company/founding-story/"
        },
        {
          "label": "Node deployment",
          "url": "https://tenzir.com/docs/guides/node-setup/deploy-a-node/"
        },
        {
          "label": "Open-source installation",
          "url": "https://tenzir.com/docs/guides/installation/"
        },
        {
          "label": "Current upstream releases",
          "url": "https://github.com/tenzir/tenzir/releases"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://github.com/tenzir/tenzir",
          "checkedAt": "2026-10-10",
          "observation": "Upstream describes a security-data pipeline engine for collecting, parsing, normalizing, aggregating, storing, querying and routing telemetry, including in-stream detections."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/tenzir/tenzir/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The actual root license grants redistribution in source and binary forms with the three BSD conditions and disclaims warranties."
        },
        {
          "claims": [
            "origin",
            "license",
            "deployment"
          ],
          "url": "https://tenzir.com/legal/terms-and-conditions/",
          "checkedAt": "2026-10-10",
          "observation": "June 2026 terms identify Tenzir GmbH as developer, define an exclusively BSD-3-Clause Open-Source Edition, and separate proprietary hosted App/Platform and closed-source Node components. Community access is free under terms, with a 1 TB/day ingress limit."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://tenzir.com/legal/notice/",
          "checkedAt": "2026-10-10",
          "observation": "Tenzir GmbH is registered in Hamburg and lists a Hamburg, Germany address."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://tenzir.com/company/founding-story/",
          "checkedAt": "2026-10-10",
          "observation": "The vendor traces VAST to research at UC Berkeley, shows its team in Hamburg in 2022, and says VAST was later renamed to Tenzir; this limits any claim of wholly German historical origin."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://tenzir.com/docs/guides/node-setup/deploy-a-node/",
          "checkedAt": "2026-10-10",
          "observation": "Official documentation supports Docker or a native static binary for a persistent node. Installation documentation separately offers CLI container and source builds, warning prebuilt packages can include proprietary plugins."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/tenzir/tenzir/releases",
          "checkedAt": "2026-10-10",
          "observation": "Official upstream release list includes Tenzir Node v6.8.1 dated 24 July 2026; this is release activity, not an uptime or support guarantee."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": [
        {
          "id": "sigma",
          "note": "Its sigma operator evaluates Sigma v2.1 detection rules and global filters over structured events. Correlation rules are explicitly unsupported.",
          "sources": [
            {
              "label": "Tenzir Sigma operator reference",
              "url": "https://tenzir.com/docs/reference/operators/sigma/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "yara",
          "note": "Its yara operator runs YARA-X rules over finite byte input. It compiles source rules, does not accept precompiled rules, and documents module and input-size limits.",
          "sources": [
            {
              "label": "Tenzir YARA operator reference",
              "url": "https://tenzir.com/docs/reference/operators/yara/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "splunk",
          "note": "The to_splunk operator sends JSON or raw events to a configured Splunk HTTP Event Collector using a HEC token.",
          "sources": [
            {
              "label": "Tenzir Splunk HEC output reference",
              "url": "https://tenzir.com/docs/reference/operators/to_splunk/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "elastic",
          "note": "The to_opensearch operator, also exposed as to_elasticsearch, sends batched events to an Elasticsearch-compatible Bulk API.",
          "sources": [
            {
              "label": "Tenzir Bulk API output reference",
              "url": "https://tenzir.com/docs/reference/operators/to_opensearch/"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "suricata",
          "note": "The read_suricata operator parses Suricata EVE JSON from files or streams into structured events. This is log ingestion, not execution of Suricata detection rules.",
          "sources": [
            {
              "label": "Tenzir Suricata input reference",
              "url": "https://tenzir.com/docs/reference/operators/read_suricata/"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "nextron-thor",
      "name": "THOR APT Scanner",
      "maker": "Nextron Systems",
      "country": "Germany",
      "workflow": "Malware analysis",
      "format": "Commercial",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Portable compromise-assessment scanner that searches live hosts or forensic images using YARA, Sigma, indicators, and anomaly checks without installation.",
      "origin": "Nextron describes THOR as originating in German security engineering work and remains its named German developer and commercial steward.",
      "originClass": "EU-developed",
      "facts": [
        "Scans live systems, images, registry data, and event logs.",
        "Runs as a portable binary on Windows, Linux, and macOS.",
        "Accepts custom YARA rules and indicators."
      ],
      "sources": [
        {
          "label": "THOR product",
          "url": "https://www.nextron-systems.com/thor/"
        },
        {
          "label": "Nextron history",
          "url": "https://www.nextron-systems.com/about/"
        },
        {
          "label": "Scanner comparison",
          "url": "https://www.nextron-systems.com/compare-our-scanners/"
        },
        {
          "label": "THOR licensed download guide",
          "url": "https://thor-microsoft-defender-guide.nextron-systems.com/en/latest/usage/thor-seed.html"
        },
        {
          "label": "THOR support index",
          "url": "https://knowledge.nextron-systems.com/thor"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "THOR is a portable local scanner. Vendor manuals require host licenses and EULA acceptance; the full current EULA was not publicly readable. THOR Lite is a separate free edition, not proof of an open-source license.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.nextron-systems.com/thor/",
          "checkedAt": "2026-10-10",
          "observation": "The vendor's product page describes portable installation-free host and image scanning with YARA/Sigma/IOCs and reports; the page presents THOR as a commercial product."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.nextron-systems.com/about/",
          "checkedAt": "2026-10-10",
          "observation": "Nextron's history identifies the German origins of THOR and its current German company stewardship."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.nextron-systems.com/compare-our-scanners/",
          "checkedAt": "2026-10-10",
          "observation": "The vendor distinguishes commercial THOR from free THOR Lite; it does not call either edition open source."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://thor-microsoft-defender-guide.nextron-systems.com/en/latest/usage/thor-seed.html",
          "checkedAt": "2026-10-10",
          "observation": "Official THOR deployment documentation says voucher/customer downloads require EULA acceptance and a valid host license; the EULA text itself was not found on the public site."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://knowledge.nextron-systems.com/thor",
          "checkedAt": "2026-10-10",
          "observation": "Nextron’s support index dates THOR Scanner 10.7.32 to 10 September 2026."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "sigma",
          "note": "Applies Sigma rules to Windows Eventlogs, disk log files and selected internal objects. Releases before THOR 10.7 require Sigma scanning to be explicitly enabled.",
          "sources": [
            {
              "label": "THOR custom signature manual",
              "url": "https://thor-manual.nextron-systems.com/en/latest/usage/custom-signatures.html#sigma-rules"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "yara",
          "note": "Applies bundled and custom YARA rules to files, process memory and other documented scan targets. Custom rules and scan-size limits are configurable.",
          "sources": [
            {
              "label": "THOR custom YARA manual",
              "url": "https://thor-manual.nextron-systems.com/en/latest/usage/custom-signatures.html#yara-rules"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "stix",
          "note": "Reads IOCs from STIX v2 JSON files and applies the observable types and operators listed in the manual. This is a supported subset, not full STIX model ingestion.",
          "sources": [
            {
              "label": "THOR STIX IOC manual",
              "url": "https://thor-manual.nextron-systems.com/en/latest/usage/custom-signatures.html#stix-iocs"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "tuency",
      "name": "Tuency",
      "maker": "CERT.at / Intevation",
      "country": "Austria",
      "workflow": "Response coordination",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Lets a CERT constituency manage organization contacts and network objects so IntelMQ can route security notifications to the appropriate recipients.",
      "origin": "CERT.at/nic.at leads and holds copyright; software engineering is explicitly credited to Intevation in Germany.",
      "originClass": "CSIRT-led",
      "facts": [
        "Self-service contact management",
        "Network object and notification rules",
        "IntelMQ contact lookup"
      ],
      "sources": [
        {
          "label": "Upstream README",
          "url": "https://gitlab.com/intevation/tuency/tuency/-/raw/master/README.md"
        },
        {
          "label": "Actual license",
          "url": "https://gitlab.com/intevation/tuency/tuency/-/raw/master/LICENSES/AGPL-3.0-or-later.txt"
        },
        {
          "label": "Release notes",
          "url": "https://gitlab.com/intevation/tuency/tuency/-/raw/master/NEWS.md"
        },
        {
          "label": "CERT.at instance documentation",
          "url": "https://tuency.cert.at/docs/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0-or-later",
      "maintenance": "Active",
      "scopeNote": "Austrian CERT lead and copyright, German Intevation engineering; the contact-management feature is stable while CERT.at calls IPv4 notification management experimental. Successor to archived DO Portal.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "capabilities",
            "deployment",
            "license"
          ],
          "url": "https://gitlab.com/intevation/tuency/tuency/-/raw/master/README.md",
          "checkedAt": "2026-10-10",
          "observation": "Upstream credits CERT.at and nic.at copyrights, Intevation software engineering, AGPL-3.0-or-later, IntelMQ use, contact management and sample Docker production deployment."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://gitlab.com/intevation/tuency/tuency/-/raw/master/LICENSES/AGPL-3.0-or-later.txt",
          "checkedAt": "2026-10-10",
          "observation": "Actual bundled license text is GNU Affero General Public License version 3."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://gitlab.com/intevation/tuency/tuency/-/raw/master/NEWS.md",
          "checkedAt": "2026-10-10",
          "observation": "Upstream NEWS records version 2.7.8 on 17 September 2026."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://tuency.cert.at/docs/",
          "checkedAt": "2026-10-10",
          "observation": "CERT.at instance docs identify the Austrian national CERT, its constituency portal, stable contacts management and experimental IPv4 notification management."
        }
      ],
      "funding": [
        {
          "programme": "Connecting Europe Facility (CEF)",
          "project": "Enhancing Cybersecurity in Austria",
          "grantId": "2018-AT-IA-0111",
          "scope": "CERT.at explicitly identifies partial CEF funding for the tuency constituency portal under this 2019–2021 action. The action has closed.",
          "sources": [
            {
              "label": "CERT.at project register: tuency funding",
              "url": "https://www.cert.at/en/about-us/projects/"
            },
            {
              "label": "HaDEA CEF cybersecurity action register (December 2021 status)",
              "url": "https://hadea.ec.europa.eu/system/files/2022-06/DSI%20fiche%20Cybersecurity_final_version.pdf"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "typosquatting-finder",
      "name": "Typosquatting Finder",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Exposure discovery",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Generate and resolve look-alike domain names, inspect results and export findings for follow-up threat intelligence analysis.",
      "origin": "CIRCL lists Typosquatter among its own project organisations and provides the tool’s public project page in Luxembourg.",
      "originClass": "CSIRT-led",
      "facts": [
        "Offers selectable domain-permutation algorithms and DNS results.",
        "Exports results as JSON and MISP events."
      ],
      "sources": [
        {
          "label": "Project documentation",
          "url": "https://github.com/typosquatter/ail-typo-website"
        },
        {
          "label": "Origin and stewardship",
          "url": "https://www.circl.lu/projects/typosquatting-finder/"
        },
        {
          "label": "Software license",
          "url": "https://github.com/typosquatter/ail-typo-website/blob/main/LICENCE"
        },
        {
          "label": "Project affiliation",
          "url": "https://www.circl.lu/projects/"
        },
        {
          "label": "Permutation engine license",
          "url": "https://github.com/typosquatter/ail-typo-squatting/blob/main/LICENSE"
        },
        {
          "label": "CIRCL public service",
          "url": "https://typosquatting-finder.circl.lu/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Apache-2.0 (web application)",
      "maintenance": "Active",
      "scopeNote": "The underlying permutation library uses a separate BSD-2-Clause license. A similar or registered domain is not evidence of malicious use.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/typosquatter/ail-typo-website",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes generate and resolve look-alike domain names, inspect results and export findings for follow-up threat intelligence analysis. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.circl.lu/projects/typosquatting-finder/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL lists Typosquatter among its own project organisations and provides the tool’s public project page in Luxembourg."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/typosquatter/ail-typo-website/blob/main/LICENCE",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies Apache-2.0 (web application)."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/typosquatter/ail-typo-website",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-02-25. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.circl.lu/projects/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL’s inventory connects the Typosquatter organisation and this tool to CIRCL."
        },
        {
          "claims": [
            "license",
            "origin",
            "country"
          ],
          "url": "https://github.com/typosquatter/ail-typo-squatting/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "The underlying permutation library is BSD-2-Clause and credits CIRCL, Luxembourg, the AIL project and David Cruciani."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://typosquatting-finder.circl.lu/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL operates a free public search service for potentially typosquatted domains; the live form and project link are available."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "unblob",
      "name": "unblob",
      "maker": "ONEKEY GmbH / unblob project",
      "country": "Germany",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Recursively extracts firmware and other binary containers, carves unknown chunks and produces structured reports for analysts examining embedded-device images.",
      "origin": "ONEKEY announced its standalone unblob extraction suite from Düsseldorf in 2022, and the current project license names ONEKEY GmbH as copyright holder.",
      "originClass": "EU-developed",
      "facts": [
        "Recursive firmware/container extraction",
        "Unknown-region carving and entropy analysis",
        "CLI and container deployment"
      ],
      "license": "MIT",
      "maintenance": "Active",
      "scopeNote": "unblob is a standalone extraction utility released from the commercial ONEKEY platform and does not itself provide a vulnerability verdict. Some optional external extractors have their own licenses and system requirements; the MIT grant applies to the upstream unblob repository.",
      "sources": [
        {
          "label": "Upstream standalone project",
          "url": "https://github.com/onekey-sec/unblob"
        },
        {
          "label": "Actual MIT license",
          "url": "https://github.com/onekey-sec/unblob/blob/main/LICENSE"
        },
        {
          "label": "ONEKEY release and German origin",
          "url": "https://www.onekey.com/press-release/onekey-redefines-iot-security-with-unblob"
        },
        {
          "label": "Standalone installation",
          "url": "https://unblob.org/installation/"
        },
        {
          "label": "Official project releases",
          "url": "https://github.com/onekey-sec/unblob/releases"
        },
        {
          "label": "ONEKEY German imprint",
          "url": "https://www.onekey.com/de/imprint"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/onekey-sec/unblob",
          "checkedAt": "2026-10-10",
          "observation": "Upstream describes a standalone extraction suite with recursive parsing, unknown-chunk carving, entropy and JSON reports; README gives pip, Docker, CLI and source installation."
        },
        {
          "claims": [
            "license",
            "origin"
          ],
          "url": "https://github.com/onekey-sec/unblob/blob/main/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual root LICENSE is the MIT grant with 2022 ONEKEY GmbH copyright."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.onekey.com/press-release/onekey-redefines-iot-security-with-unblob",
          "checkedAt": "2026-10-10",
          "observation": "Düsseldorf-dated July 2022 ONEKEY announcement explicitly releases unblob as an open-source extraction suite and core platform component for independent security researchers."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://unblob.org/installation/",
          "checkedAt": "2026-10-10",
          "observation": "Official unblob documentation gives local installation and an OCI container command, separate from access to the commercial ONEKEY SaaS."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/onekey-sec/unblob/releases",
          "checkedAt": "2026-10-10",
          "observation": "Upstream release list includes version 26.6.4 dated 4 June 2026 with new extractors and fixes; release activity is not a support guarantee."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "usbsas",
      "name": "usbsas",
      "maker": "CEA IT Security",
      "country": "France",
      "workflow": "Digital forensics",
      "format": "Open source",
      "deployment": [
        "Desktop/CLI"
      ],
      "description": "Linux tool for forensic examination of untrusted USB devices, with read-only mounting, disk imaging and controlled file transfer.",
      "origin": "Developed in CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group.",
      "originClass": "Institution-led",
      "facts": [
        "Supports forensic analysis of untrusted USB mass-storage devices.",
        "Can mount a device read-only and create a device image.",
        "Separates parsing tasks into restricted user-space processes."
      ],
      "sources": [
        {
          "label": "Upstream usbsas README and license statement",
          "url": "https://github.com/cea-sec/usbsas"
        },
        {
          "label": "CEA IT Security organization",
          "url": "https://github.com/cea-sec"
        },
        {
          "label": "Upstream GPL license",
          "url": "https://github.com/cea-sec/usbsas/blob/main/LICENSE"
        }
      ],
      "license": "GPL-3.0-or-later",
      "maintenance": "Active",
      "scopeNote": "Requires physical access to the USB medium and a compatible GNU/Linux host; a focused evidence-intake tool, not an end-to-end DFIR platform.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment",
            "license"
          ],
          "url": "https://github.com/cea-sec/usbsas",
          "checkedAt": "2026-10-10",
          "observation": "README says GNU/Linux Rust software for secure reading of untrusted USB devices, expressly includes forensic analysis as a use case, lists read-only mount and imaging, and grants GPL version 3 or any later version."
        },
        {
          "claims": [
            "origin",
            "country",
            "maintenance"
          ],
          "url": "https://github.com/cea-sec",
          "checkedAt": "2026-10-10",
          "observation": "CEA IT Security identifies its affiliation with the French national commission; its repository list shows usbsas updated 8 October 2026."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "vmray-platform",
      "name": "VMRay Platform",
      "maker": "VMRay GmbH",
      "country": "Germany",
      "workflow": "Malware analysis",
      "format": "Commercial",
      "deployment": [
        "Self-hosted",
        "SaaS"
      ],
      "description": "Analyzes suspicious files, URLs and emails with layered sandbox techniques, returning behavioral findings, verdict context and extracted indicators for responders.",
      "origin": "VMRay says its founders developed pioneering sandbox technology during doctoral work in Bochum and founded VMRay GmbH there in 2013; the present platform has global staff and customers.",
      "originClass": "EU-developed",
      "facts": [
        "Malware and phishing sandbox analysis",
        "Behavioral findings and extracted IOCs",
        "Cloud or on-premises product plans"
      ],
      "license": "Commercial license; full terms not publicly verified",
      "maintenance": "Active",
      "scopeNote": "Current VMRay Platform is offered through DeepResponse, FinalVerdict and TotalInsight plans; VMRay Analyzer is a discontinued legacy plan and is not a separate current entry. Product pricing/trial pages establish commercial delivery, but no full platform end-user license was publicly verified. Cloud region or sovereignty claims should not be assumed for every plan.",
      "sources": [
        {
          "label": "Current platform",
          "url": "https://www.vmray.com/"
        },
        {
          "label": "Product trial and deployment FAQ",
          "url": "https://www.vmray.com/try-vmray/"
        },
        {
          "label": "Founding milestones",
          "url": "https://www.vmray.com/why-vmray/milestone/"
        },
        {
          "label": "Commercial pricing request",
          "url": "https://www.vmray.com/vmray-pricing/"
        },
        {
          "label": "Current release",
          "url": "https://www.vmray.com/release-highlights-vmray-platform-2026-2-multi-stage-malware-analysis/"
        },
        {
          "label": "Legacy product status",
          "url": "https://www.vmray.com/vmray-analyzer/"
        }
      ],
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities"
          ],
          "url": "https://www.vmray.com/",
          "checkedAt": "2026-10-10",
          "observation": "Official platform site describes sandbox-based malware and phishing analysis for SOC, CERT and CTI teams, with integrations and API access."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://www.vmray.com/try-vmray/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor FAQ explicitly offers VMRay Cloud and On-Premises, and documents manual WebUI, mailbox, REST API and connector submission paths."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.vmray.com/why-vmray/milestone/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor history says the founders completed doctoral work at Ruhr University Bochum on sandbox technology and founded VMRay GmbH in 2013; the company lists Bochum and Boston offices."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.vmray.com/vmray-pricing/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor pricing page solicits commercial product and pricing requests; reviewed public pages did not provide complete end-user license text for the current platform."
        },
        {
          "claims": [
            "maintenance",
            "capabilities"
          ],
          "url": "https://www.vmray.com/release-highlights-vmray-platform-2026-2-multi-stage-malware-analysis/",
          "checkedAt": "2026-10-10",
          "observation": "Dated 9 April 2026 Platform 2026.2.0 release describes recursive malware analysis, improved reporting and new Cloud controls; vendor release claims are not independent effectiveness evidence."
        },
        {
          "claims": [
            "identity"
          ],
          "url": "https://www.vmray.com/vmray-analyzer/",
          "checkedAt": "2026-10-10",
          "observation": "Vendor says legacy Analyzer was discontinued and replaced by current plans built on the shared VMRay Platform."
        }
      ],
      "reviewedAt": "2026-10-10",
      "funding": [],
      "capabilities": [
        {
          "id": "misp",
          "note": "VMRay's separately deployed vmray-misp-feed script periodically converts platform analysis results to MISP events. Requires VMRay API access and MISP access to the generated feed; report attachments, tags and IOC-only export are configurable.",
          "sources": [
            {
              "label": "VMRay MISP feed configuration",
              "url": "https://github.com/vmray/vmray-misp-feed/blob/main/docs/vmray-misp-feed.md"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "vulnerability-lookup",
      "name": "Vulnerability-Lookup",
      "maker": "CIRCL and project contributors",
      "country": "Luxembourg",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted",
        "Public service"
      ],
      "description": "Correlate vulnerability records across sources, track sightings and support advisory publication and coordinated vulnerability disclosure.",
      "origin": "The upstream README identifies CIRCL, Computer Incident Response Center Luxembourg, and named project contributors as copyright holders.",
      "originClass": "CSIRT-led",
      "facts": [
        "Combines vulnerability feeds with comments, bundles and sightings.",
        "Provides a lookup API and coordinated-disclosure workflows."
      ],
      "sources": [
        {
          "label": "Origin and stewardship",
          "url": "https://github.com/vulnerability-lookup/vulnerability-lookup"
        },
        {
          "label": "Software license",
          "url": "https://github.com/vulnerability-lookup/vulnerability-lookup/blob/main/LICENSE.md"
        },
        {
          "label": "Public service",
          "url": "https://www.circl.lu/services/cve-search/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "A vulnerability intelligence and disclosure platform; it does not scan assets to establish whether they are vulnerable.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/vulnerability-lookup/vulnerability-lookup",
          "checkedAt": "2026-10-10",
          "observation": "Upstream documentation describes correlate vulnerability records across sources, track sightings and support advisory publication and coordinated vulnerability disclosure. It documents local installation."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/vulnerability-lookup/vulnerability-lookup",
          "checkedAt": "2026-10-10",
          "observation": "The upstream README identifies CIRCL, Computer Incident Response Center Luxembourg, and named project contributors as copyright holders."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/vulnerability-lookup/vulnerability-lookup/blob/main/LICENSE.md",
          "checkedAt": "2026-10-10",
          "observation": "The upstream license file specifies AGPL-3.0."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://api.github.com/repos/vulnerability-lookup/vulnerability-lookup",
          "checkedAt": "2026-10-10",
          "observation": "Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://www.circl.lu/services/cve-search/",
          "checkedAt": "2026-10-10",
          "observation": "CIRCL offers the public vulnerability lookup instance; the README also documents local installation."
        }
      ],
      "funding": [
        {
          "programme": "Digital Europe Programme (DEP)",
          "project": "Next Generation Security Operator Training Infrastructure (NGSOTI)",
          "grantId": "101127921",
          "scope": "Vulnerability-Lookup acknowledges NGSOTI co-funding. The action runs from January 2024 to December 2026; the acknowledgement does not specify an amount for this tool.",
          "sources": [
            {
              "label": "Vulnerability-Lookup project funding statement",
              "url": "https://www.vulnerability-lookup.org/"
            },
            {
              "label": "Restena NGSOTI project: programme, grant and dates",
              "url": "https://www.restena.lu/en/project/ngsoti"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ],
      "capabilities": []
    },
    {
      "slug": "warden",
      "name": "Warden",
      "maker": "CESNET-CERTS / CESNET",
      "country": "Czechia",
      "workflow": "Feed automation",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Shares structured security-event reports between authenticated CSIRT participants through a server, sending clients and receiving clients using the IDEA format.",
      "origin": "CESNET-CERTS developed Warden for the Czech research network and publishes the server/client source.",
      "originClass": "CSIRT-led",
      "facts": [
        "IDEA event exchange",
        "Authenticated server and clients",
        "Self-hostable server"
      ],
      "sources": [
        {
          "label": "Project and CSIRT origin",
          "url": "https://warden.cesnet.cz/en/about_project"
        },
        {
          "label": "Architecture",
          "url": "https://warden.cesnet.cz/en/architecture"
        },
        {
          "label": "Server README",
          "url": "https://gitlab.cesnet.cz/api/v4/projects/1392/repository/files/warden_server%2FREADME/raw?ref=master"
        },
        {
          "label": "Server license",
          "url": "https://gitlab.cesnet.cz/api/v4/projects/1392/repository/files/warden_server%2FLICENSE/raw?ref=master"
        },
        {
          "label": "Downloads",
          "url": "https://warden.cesnet.cz/en/downloads"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "BSD-3-Clause (core server/client)",
      "maintenance": "Active",
      "scopeNote": "The CESNET-hosted exchange requires participant registration; official FAQ says operators can run their own server. Core server/client READMEs use older Python/Apache examples and 3.0-beta3 naming. Contrib licenses may differ.",
      "evidence": [
        {
          "claims": [
            "identity",
            "origin",
            "country",
            "capabilities"
          ],
          "url": "https://warden.cesnet.cz/en/about_project",
          "checkedAt": "2026-10-10",
          "observation": "Official project history says Warden arose from CESNET-CERTS and CSIRT-MU needs to exchange detected events."
        },
        {
          "claims": [
            "capabilities"
          ],
          "url": "https://warden.cesnet.cz/en/architecture",
          "checkedAt": "2026-10-10",
          "observation": "Official architecture describes sender, receiver and server exchange of IDEA security-event records with authentication."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://gitlab.cesnet.cz/api/v4/projects/1392/repository/files/warden_server%2FREADME/raw?ref=master",
          "checkedAt": "2026-10-10",
          "observation": "Actual server README documents local Python/WSGI, Apache and database installation."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://gitlab.cesnet.cz/api/v4/projects/1392/repository/files/warden_server%2FLICENSE/raw?ref=master",
          "checkedAt": "2026-10-10",
          "observation": "Actual server license contains three-clause BSD conditions and CESNET copyright; client LICENSE matches."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://gitlab.cesnet.cz/api/v4/projects/1392/repository/commits?per_page=1",
          "checkedAt": "2026-10-10",
          "observation": "Upstream repository latest commit on 19 January 2026; this shows code activity, not supported operational compatibility."
        },
        {
          "claims": [
            "deployment"
          ],
          "url": "https://warden.cesnet.cz/en/faq",
          "checkedAt": "2026-10-10",
          "observation": "Official FAQ says users can install their own server; joining CESNET-hosted exchange has participation rules."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "watcher",
      "name": "Watcher",
      "maker": "Thales Group CERT",
      "country": "France",
      "workflow": "Threat intelligence",
      "format": "Open source",
      "deployment": [
        "Self-hosted"
      ],
      "description": "Monitors vulnerability, ransomware and news sources against watch terms, collecting results and sending alerts through a self-hosted analyst interface.",
      "origin": "Thales Group CERT calls itself the developer; prominent project contributors publicly identify with Thales CERT in France.",
      "originClass": "CSIRT-led",
      "facts": [
        "CVE and ransomware source monitoring",
        "Keyword watch rules and alerts",
        "Docker-hosted analyst interface"
      ],
      "sources": [
        {
          "label": "Upstream project",
          "url": "https://github.com/thalesgroup-cert/Watcher"
        },
        {
          "label": "Official project documentation",
          "url": "https://thalesgroup-cert.github.io/Watcher/README.html"
        },
        {
          "label": "Actual AGPL license",
          "url": "https://github.com/thalesgroup-cert/Watcher/blob/master/LICENSE"
        },
        {
          "label": "Creator profile",
          "url": "https://github.com/Felix83000"
        },
        {
          "label": "Co-developer profile",
          "url": "https://github.com/ygalnezri"
        },
        {
          "label": "Upstream branch activity",
          "url": "https://github.com/thalesgroup-cert/Watcher/commits/master.atom"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "AGPL-3.0",
      "maintenance": "Active",
      "scopeNote": "Coverage depends on configured external sources, credentials and feeds; this does not establish completeness or quality of alerts. French country label refers to the evidenced project team.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://github.com/thalesgroup-cert/Watcher",
          "checkedAt": "2026-10-10",
          "observation": "README describes Django/React threat-intelligence monitoring of CVE, ransomware and RSS sources with keyword alerts and Docker deployment."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://thalesgroup-cert.github.io/Watcher/README.html",
          "checkedAt": "2026-10-10",
          "observation": "Official documentation explicitly says Watcher was developed by Thales Group CERT."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://github.com/Felix83000",
          "checkedAt": "2026-10-10",
          "observation": "Creator's self-reported profile identifies Félix Herrenschmidt, Thales CERT, France, and names Watcher."
        },
        {
          "claims": [
            "country"
          ],
          "url": "https://github.com/ygalnezri",
          "checkedAt": "2026-10-10",
          "observation": "Another major contributor's profile identifies Thales CERT, France and Watcher development."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://github.com/thalesgroup-cert/Watcher/blob/master/LICENSE",
          "checkedAt": "2026-10-10",
          "observation": "Actual root LICENSE contains GNU Affero General Public License version 3 text."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://github.com/thalesgroup-cert/Watcher/commits/master.atom",
          "checkedAt": "2026-10-10",
          "observation": "Upstream default-branch Atom feed records a commit on 2026-10-02; branch activity is not a support guarantee."
        }
      ],
      "funding": [],
      "capabilities": [
        {
          "id": "misp",
          "note": "Exports monitored domains from Website Monitoring and DNS Threats Monitored to MISP. Requires a configured MISP instance and API key; the UI tracks whether a domain has already been exported.",
          "sources": [
            {
              "label": "Watcher MISP export guide",
              "url": "https://thalesgroup-cert.github.io/Watcher/README.html#misp-export"
            }
          ],
          "checkedAt": "2026-10-11"
        },
        {
          "id": "thehive",
          "note": "Creates TheHive alerts from Watcher notifications and manual exports. Requires TheHive API credentials and the configured Watcher custom field to exist in TheHive.",
          "sources": [
            {
              "label": "Watcher TheHive configuration",
              "url": "https://thalesgroup-cert.github.io/Watcher/README.html#configure-your-thehive-notifications"
            }
          ],
          "checkedAt": "2026-10-11"
        }
      ]
    },
    {
      "slug": "withsecure-elements-xm",
      "name": "WithSecure Elements Exposure Management",
      "maker": "WithSecure",
      "country": "Finland",
      "workflow": "Exposure discovery",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Cloud exposure management offering that discovers assets and vulnerabilities across devices, identities, cloud, and external surfaces, then ranks remediation work.",
      "origin": "WithSecure is the Finnish business-security successor to F-Secure; its current European product-development statement covers Elements generally, not a published XM engineering roster.",
      "originClass": "EU-developed",
      "facts": [
        "Discovers devices, identities, cloud assets, and external exposure.",
        "Visualizes possible attack paths and prioritizes remediation.",
        "Delivered through the Elements cloud platform."
      ],
      "sources": [
        {
          "label": "Exposure Management product",
          "url": "https://www.withsecure.com/en/for-business/platform/xm/"
        },
        {
          "label": "Elements platform",
          "url": "https://www.withsecure.com/en/for-business/platform/"
        },
        {
          "label": "WithSecure European product-development statement",
          "url": "https://www.withsecure.com/en/resources-hub/press-releases/european-way/"
        },
        {
          "label": "WithSecure terms of use",
          "url": "https://www.withsecure.com/en/terms/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "XM and XDR share one Elements platform but are named distinct purchasable capabilities. No EU-only hosting or ultimate-control claim is made.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.withsecure.com/en/for-business/platform/xm/",
          "checkedAt": "2026-10-10",
          "observation": "WithSecure's current XM page describes asset/exposure discovery, attack paths, prioritized remediation and access through Elements cloud."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.withsecure.com/en/resources-hub/press-releases/european-way/",
          "checkedAt": "2026-10-10",
          "observation": "WithSecure's company statement says product development and service delivery are based in Europe after its Malaysian divestment; company history documents Finnish origin."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.withsecure.com/en/terms/",
          "checkedAt": "2026-10-10",
          "observation": "WithSecure business terms grant a fee-based limited right to use its solutions and reserve software intellectual-property rights."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.withsecure.com/en/for-business/platform/xm/",
          "checkedAt": "2026-10-10",
          "observation": "At review on 10 October 2026 the vendor maintained a current XM product and demo page; this establishes offer visibility, not a release cadence."
        }
      ],
      "funding": [],
      "capabilities": []
    },
    {
      "slug": "withsecure-elements-xdr",
      "name": "WithSecure Elements XDR",
      "maker": "WithSecure",
      "country": "Finland",
      "workflow": "Detection and monitoring",
      "format": "Commercial",
      "deployment": [
        "SaaS"
      ],
      "description": "Cloud extended detection and response offering that correlates endpoint, identity, email, and cloud telemetry to investigate and contain multistage attacks.",
      "origin": "WithSecure is the Finnish business-security successor to F-Secure and says current Elements XDR product development and delivery are based in Europe.",
      "originClass": "EU-developed",
      "facts": [
        "Correlates endpoint, identity, email, and cloud signals.",
        "Uses the cloud Elements Security Center.",
        "WithSecure reports European development, delivery, and support for Elements XDR."
      ],
      "sources": [
        {
          "label": "Elements product",
          "url": "https://www.withsecure.com/en/for-business/platform/"
        },
        {
          "label": "About WithSecure",
          "url": "https://www.withsecure.com/en/about-us/"
        },
        {
          "label": "European development statement",
          "url": "https://www.withsecure.com/fi/resurssit/medialle/withsecure-elements-xdr-certified-leader-in-av-comparatives/"
        },
        {
          "label": "2026 ownership update",
          "url": "https://www.withsecure.com/en/recommended-cash-tender-offer/diana-bidco-oy-has-gained-title-to-the-minority-shares-in-withsecure-corporation/"
        },
        {
          "label": "WithSecure terms of use",
          "url": "https://www.withsecure.com/en/terms/"
        }
      ],
      "reviewedAt": "2026-10-10",
      "license": "Proprietary",
      "maintenance": "Active",
      "scopeNote": "WithSecure was taken private by Diana BidCo in 2026; European development does not prove EU-only ownership, infrastructure, or data residency. Elements XDR modules are one offering.",
      "evidence": [
        {
          "claims": [
            "identity",
            "capabilities",
            "deployment"
          ],
          "url": "https://www.withsecure.com/en/for-business/platform/",
          "checkedAt": "2026-10-10",
          "observation": "The platform page calls Elements a cloud platform, sells XDR as a capability, and describes multi-surface detection and response."
        },
        {
          "claims": [
            "origin",
            "country"
          ],
          "url": "https://www.withsecure.com/fi/resurssit/medialle/withsecure-elements-xdr-certified-leader-in-av-comparatives/",
          "checkedAt": "2026-10-10",
          "observation": "In its 2026 announcement WithSecure says Elements XDR is developed, delivered and supported in Europe; its company history places the business in Finland after the F-Secure split."
        },
        {
          "claims": [
            "origin"
          ],
          "url": "https://www.withsecure.com/en/recommended-cash-tender-offer/diana-bidco-oy-has-gained-title-to-the-minority-shares-in-withsecure-corporation/",
          "checkedAt": "2026-10-10",
          "observation": "The company's tender-offer notice records Diana BidCo taking title to remaining minority shares and the 2026 delisting, so independent public-company status would be stale."
        },
        {
          "claims": [
            "license"
          ],
          "url": "https://www.withsecure.com/en/terms/",
          "checkedAt": "2026-10-10",
          "observation": "WithSecure business terms grant a fee-based limited right to use its solutions and reserve software intellectual-property rights."
        },
        {
          "claims": [
            "maintenance"
          ],
          "url": "https://www.withsecure.com/fi/resurssit/medialle/withsecure-elements-xdr-certified-leader-in-av-comparatives/",
          "checkedAt": "2026-10-10",
          "observation": "The vendor published a September 2026 notice explicitly naming the currently delivered Elements XDR offering."
        }
      ],
      "funding": [],
      "capabilities": []
    }
  ]
}