Back to the catalog
Your working shortlist
Compare the details.
Put up to three tools side by side. Follow the sources before making a decision.
A useful comparison starts with two tools.
Add tools from the catalog to compare their purpose, deployment, and origin evidence. Your shortlist is saved in this browser.
Explore toolsScroll across to compare all selected tools.
| At a glance | IntelFusions | MISP | IntelMQ | n6 | Artemis | Taranis NG | MWDB Core | OpenCTI | TheHive | Guardsix SIEM | Bitdefender GravityZone XDR | Acquire | ADTimeline | AIL Framework | ASGARD Management Center | BGP Ranking | CapLoader | Cerebrate | Convey | Cortex | CounterCraft The Platform | CrowdSec Security Engine | CVE Search | Cyberwatch Vulnerability Manager | Cyscale Cloud Platform | D4 | DCSO Threat Intelligence Engine | DECODE | DFIR ORC | DFIR-IRIS | DFIR-O365RC | DFIR-OGRE | DFIRTrack | Dissect | DRAKVUF Sandbox | droid | EclecticIQ Intelligence Center | ESET Inspect On-Prem | Exein Runtime | Flowintel | G DATA XDR | Gatewatcher NDR | GLIMPS Audit | GLIMPS Malware Expert | Guardsix NDR | HarfangLab EDR | Hashlookup | Hfinger | Holm Security VMP | IntelOwl | ipfixprobe | Karton | Kunai | Kunai Sandbox | Loki-RS | Lookyloo | MADCAT | Mailgoose | Mentat | Mercury | Miasm | mquery | NEMEA | NERD | NetworkMiner | ONEKEY Platform | OpenAEV | OpenCVE | OPENVAS SCAN | OpenWEC | ORADAD | ORADAZ | orc2timeline | Outpost24 CompassDRP | Outpost24 OutscanNX | Pandora | Pentest-Tools.com | Plum Island | Secvisogram | Sekoia Defend | Sekoia Intelligence | Stormshield Endpoint Security Evolution | Suspicious | T-Pot | Tehtris EDR | Tenzir | THOR APT Scanner | Tuency | Typosquatting Finder | unblob | usbsas | VMRay Platform | Vulnerability-Lookup | Warden | Watcher | WithSecure Elements Exposure Management | WithSecure Elements XDR |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Response workflow | Threat intelligence | Threat intelligence | Feed automation | Feed automation | Exposure discovery | Threat intelligence | Malware analysis | Threat intelligence | Response coordination | Detection and monitoring | Detection and monitoring | Digital forensics | Digital forensics | Threat intelligence | Detection and monitoring | Threat intelligence | Digital forensics | Response coordination | Response coordination | Feed automation | Detection and monitoring | Detection and monitoring | Threat intelligence | Exposure discovery | Exposure discovery | Detection and monitoring | Threat intelligence | Malware analysis | Digital forensics | Response coordination | Digital forensics | Digital forensics | Response coordination | Digital forensics | Malware analysis | Detection and monitoring | Threat intelligence | Detection and monitoring | Detection and monitoring | Response coordination | Detection and monitoring | Detection and monitoring | Malware analysis | Malware analysis | Detection and monitoring | Detection and monitoring | Digital forensics | Malware analysis | Exposure discovery | Threat intelligence | Detection and monitoring | Malware analysis | Detection and monitoring | Malware analysis | Detection and monitoring | Threat intelligence | Detection and monitoring | Exposure discovery | Detection and monitoring | Threat intelligence | Malware analysis | Malware analysis | Detection and monitoring | Threat intelligence | Digital forensics | Exposure discovery | Exposure discovery | Exposure discovery | Exposure discovery | Detection and monitoring | Exposure discovery | Exposure discovery | Digital forensics | Threat intelligence | Exposure discovery | Malware analysis | Exposure discovery | Exposure discovery | Response coordination | Detection and monitoring | Threat intelligence | Detection and monitoring | Malware analysis | Detection and monitoring | Detection and monitoring | Feed automation | Malware analysis | Response coordination | Exposure discovery | Digital forensics | Digital forensics | Malware analysis | Threat intelligence | Feed automation | Threat intelligence | Exposure discovery | Detection and monitoring |
| Developer / lead | IntelFusions | CIRCL and project contributors | CERT.at / IntelMQ community | CERT Polska | CERT Polska | SK-CERT | CERT Polska | Filigran | StrangeBee | Guardsix | Bitdefender | Fox-IT | ANSSI | CIRCL and project contributors | Nextron Systems | CIRCL and project contributors | NETRESEC AB | CIRCL and project contributors | CSIRT.cz / CZ.NIC | StrangeBee | CounterCraft | CrowdSec | CIRCL and project contributors | Cyberwatch | Cyscale Limited | CIRCL and project contributors | DCSO Deutsche Cyber-Sicherheitsorganisation GmbH | ANSSI | ANSSI | DFIR-IRIS community | ANSSI | ANSSI | Mathias Stuhlmacher / DFIRTrack project | Fox-IT | CERT Polska | CERT-EU | EclecticIQ | ESET | Exein S.p.A. | CIRCL and project contributors | G DATA CyberDefense | Gatewatcher | GLIMPS | GLIMPS | Guardsix | HarfangLab | CIRCL and project contributors | CERT Polska | Holm Security | Certego / IntelOwl project | CESNET | CERT Polska | CIRCL / Kunai Project | Kunai Project / CIRCL | Florian Roth | CIRCL and project contributors | German Federal Office for Information Security (BSI) | CERT Polska | CESNET | QuoIntelligence GmbH | CEA IT Security | CERT Polska | CESNET | CESNET | NETRESEC AB | ONEKEY GmbH | Filigran | Amber Security / OpenCVE project | Greenbone | CEA IT Security | ANSSI | ANSSI | ANSSI | Outpost24 | Outpost24 | CIRCL and project contributors | PentestTools S.A. | CIRCL and project contributors | German Federal Office for Information Security (BSI) | Sekoia | Sekoia | Stormshield | Thales Group CERT | Deutsche Telekom Security | Tehtris | Tenzir GmbH | Nextron Systems | CERT.at / Intevation | CIRCL and project contributors | ONEKEY GmbH / unblob project | CEA IT Security | VMRay GmbH | CIRCL and project contributors | CESNET-CERTS / CESNET | Thales Group CERT | WithSecure | WithSecure |
| Country | Romania | Luxembourg | Austria | Poland | Poland | Slovakia | Poland | France | France | Denmark | Romania | Netherlands | France | Luxembourg | Germany | Luxembourg | Sweden | Luxembourg | Czechia | France | Spain | France | Luxembourg | France | Romania | Luxembourg | Germany | France | France | France | France | France | Germany | Netherlands | Poland | Belgium | Netherlands | Slovakia | Italy | Luxembourg | Germany | France | France | France | Denmark | France | Luxembourg | Poland | Sweden | Italy | Czechia | Poland | Luxembourg | Luxembourg | Germany | Luxembourg | Germany | Poland | Czechia | Germany | France | Poland | Czechia | Czechia | Sweden | Germany | France | France | Germany | France | France | France | France | Sweden | Sweden | Luxembourg | Romania | Luxembourg | Germany | France | France | France | France | Germany | France | Germany | Germany | Austria | Luxembourg | Germany | France | Germany | Luxembourg | Czechia | France | Finland | Finland |
| Product model | Free service | Open source | Open source | Open source | Open source | Open source | Open source | Open core | Commercial | Commercial | Commercial | Open source | Open source | Open source | Commercial | Open source | Commercial | Open source | Open source | Open source | Commercial | Open source | Open source | Commercial | Commercial | Open source | Commercial | Open source | Open source | Open source | Open source | Open source | Open source | Open source | Source available | Open source | Commercial | Commercial | Commercial | Open source | Commercial | Commercial | Commercial | Commercial | Commercial | Commercial | Open source | Open source | Commercial | Open source | Open source | Open source | Open source | Open source | Open source | Open source | Open source | Open source | Open source | Commercial | Open source | Open source | Open source | Open source | Open core | Commercial | Open core | Source available | Commercial | Open source | Open source | Open source | Open source | Commercial | Commercial | Open source | Commercial | Open source | Open source | Commercial | Commercial | Commercial | Open source | Open source | Commercial | Open core | Commercial | Open source | Open source | Open source | Open source | Commercial | Open source | Open source | Open source | Commercial | Commercial |
| Deployment | Public service | Self-hosted | Self-hosted | Self-hosted | Self-hosted | Self-hosted | Self-hosted | Self-hosted · SaaS | Self-hosted · SaaS | Self-hosted | SaaS | Desktop/CLI | Desktop/CLI | Self-hosted | Self-hosted | Self-hosted · Public service | Desktop/CLI | Self-hosted | Desktop/CLI · Self-hosted | Self-hosted | Self-hosted | Self-hosted | Self-hosted | Self-hosted | SaaS | Self-hosted | SaaS | Desktop/CLI | Desktop/CLI | Self-hosted | Desktop/CLI | Desktop/CLI | Self-hosted | Desktop/CLI | Self-hosted | Desktop/CLI | Self-hosted | Self-hosted | SaaS | Self-hosted | SaaS | Self-hosted · SaaS | Self-hosted · SaaS | Self-hosted · SaaS | Self-hosted | Self-hosted · SaaS | Self-hosted · Public service | Desktop/CLI | SaaS · Self-hosted | Self-hosted | Self-hosted | Self-hosted | Desktop/CLI | Self-hosted · Public service | Desktop/CLI | Self-hosted · Public service | Self-hosted | Self-hosted · Public service | Self-hosted | SaaS | Desktop/CLI | Self-hosted | Self-hosted | Self-hosted · Public service | Desktop/CLI | SaaS | Self-hosted · SaaS | Self-hosted · SaaS | Self-hosted | Self-hosted · Desktop/CLI | Desktop/CLI | Desktop/CLI | Desktop/CLI | SaaS | SaaS · Self-hosted | Self-hosted · Public service | SaaS | Self-hosted | Self-hosted | SaaS | SaaS | Self-hosted · SaaS | Self-hosted | Self-hosted | SaaS | Self-hosted · SaaS | Desktop/CLI | Self-hosted | Self-hosted · Public service | Desktop/CLI | Desktop/CLI | Self-hosted · SaaS | Self-hosted · Public service | Self-hosted | Self-hosted | SaaS | SaaS |
| Software license | Website terms; third-party datasets retain separate licenses | AGPL-3.0 | AGPL-3.0 | AGPL-3.0 | BSD-3-Clause | EUPL-1.2 | AGPL-3.0-or-later with plugin exception | Mixed: Apache-2.0 Community Edition; OpenCTI Enterprise Edition License | Proprietary | Proprietary | Proprietary | AGPL-3.0 | GPL-3.0 | AGPL-3.0-or-later | Commercial license; full terms not publicly verified | AGPL-3.0 | Commercial license; full terms not publicly verified | AGPL-3.0 | GPL-3.0 | AGPL-3.0 | Proprietary | MIT | AGPL-3.0 | Commercial license; full terms not publicly verified | Proprietary | AGPL-3.0 | Commercial license; full terms not publicly verified | BSD-3-Clause | LGPL-2.1 | LGPL-3.0 | GPL-3.0 | Apache-2.0 | MIT | AGPL-3.0 | Custom: GPL-2.0 with DRAKVUF Sandbox clarifications and exceptions | EUPL-1.2 | Commercial license; full terms not publicly verified | Proprietary | Proprietary | AGPL-3.0 | Proprietary | Commercial license; full terms not publicly verified | License terms not publicly verified | Commercial license; full terms not publicly verified | Proprietary | Commercial license; full terms not publicly verified | AGPL-3.0 | GPL-3.0 | Proprietary | AGPL-3.0 | BSD-3-Clause | BSD-3-Clause | GPL-3.0 | GPL-3.0 (sandbox engine) | GPL-3.0 | BSD-3-Clause | GPL-3.0 | BSD-3-Clause | MIT | Commercial license; full terms not publicly verified | GPL-2.0 | AGPL-3.0 | Dual: CESNET three-clause permissive terms or GPL-2.0-or-later | Dual: CESNET three-clause permissive terms or GPL-2.0-or-later | Mixed: GPL-2.0 free edition; commercial Professional license (full terms not publicly verified) | Commercial license; full terms not publicly verified | Mixed: Apache-2.0 Community Edition; OpenAEV Enterprise Edition License | BUSL-1.1 | Mixed: open-source software packages and tests; subscription-controlled OPENVAS ENTERPRISE FEED database and access key | GPL-3.0-or-later | GPL-3.0 | GPL-3.0 | LGPL-3.0 | Proprietary | Proprietary | AGPL-3.0-or-later | Proprietary | AGPL-3.0 | MIT | Commercial license; full terms not publicly verified | Commercial license; full terms not publicly verified | Commercial license; full terms not publicly verified | Apache-2.0 | Mixed: GPL-3.0 for T-Pot code; integrated components retain separate licenses | Proprietary | Mixed: BSD-3-Clause Open-Source Edition and Node code; proprietary App, Platform and Node extensions | Commercial license; full terms not publicly verified | AGPL-3.0-or-later | Apache-2.0 (web application) | MIT | GPL-3.0-or-later | Commercial license; full terms not publicly verified | AGPL-3.0 | BSD-3-Clause (core server/client) | AGPL-3.0 | Proprietary | Proprietary |
| Upstream status | Active | Active | Active | Active | Experimental | Active | Active | Active | Active | Active | Active | Active | Maintenance unconfirmed | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Maintenance unconfirmed | Active | Active | Maintenance unconfirmed | Experimental | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Maintenance unconfirmed | Active | Active | Active | Experimental | Experimental | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Maintenance unconfirmed | Active | Active | Active | Active | Active | Active | Active | Active | Experimental | Maintenance unconfirmed | Active | Active | Active | Active | Experimental | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active | Active |
| Scope and limits | The terms describe an informational research resource, exclude alerting or monitoring services, and promise no SLA. Incident claims require independent verification. No public open-source software license or self-hosted release was verified. Public access does not permit substantial database reuse. | This profile covers the upstream software. Hosting providers and their terms require separate review. | Multi-CSIRT project; Austria identifies the directory-listed lead, not every contributor or all engineering. | The CERT.PL web portal is a deployment, not evidence of a generally offered SaaS product. | README explicitly says experimental; some additional modules have different licenses and are omitted. | Distinct from discontinued Dutch Taranis3; follow current Docker guide for operational warnings. | Core license includes a plugin exception; plugin code may carry other terms. | The freely accessible demonstration instance is not the SaaS offer; edition-specific capabilities and hosting location need individual checking. | Current TheHive 5 is proprietary despite older TheHive 4 AGPL releases. Cloud placement is not guaranteed in France; a trial becomes read-only without an activated license. | Vendor sovereignty statements are marketing claims, not independently verified ownership or legal conclusions. Command Centre is an umbrella name. | Cloud only applies to XDR, not every GravityZone product. Cloud hosting geography and ultimate ownership are not established by the cited pages. | Part of the Dissect ecosystem but independently installable and usable for artifact collection; Fox-IT has UK group ownership. | Replication metadata yields only a partial timeline; suspicious-change dashboards require analyst review. No recent upstream release or support guarantee was verified. | Crawlers, feeds and optional analysis services require separate configuration. | ASGARD is separately deployable and integrates THOR scanning. Vendor installer documentation requires a product-matched license; full current end-user rights were not publicly readable. | Rankings describe observations in the contributing datasets; they are not a complete assessment of an operator’s security. | CapLoader is a separate Windows desktop product with a 30-day restricted trial and commercial licenses; it is not the GPL NetworkMiner edition. The vendor publishes license options and feature limits, but not the complete current end-user contract. .NET Framework 4.8 is required. | Supports response coordination and contact management; it is not an incident case-management system. | Primarily a Python CLI with an optional web-service mode; it processes reports but is not a full case-management platform. | Cortex itself remains open source; that does not make current TheHive 5 open source. External analyzers can have separate terms. | The public product page says cloud and hybrid environments are supported, but it does not establish that the management console is vendor-hosted SaaS. US and UK group entities exist; ultimate control and data residency require review. | The self-hosted Security Engine is MIT-licensed; CrowdSec-supplied community blocklist and other vendor threat data have separate terms restricting redistribution, and the optional hosted Console is a distinct service. Blocking requires a configured remediation component; the engine alone detects and makes local decisions. The France label reflects documented French R&D and the French SAS legal notice, not every current contributor, data host or ultimate owner. | CIRCL’s former public CVE Search service has been superseded by Vulnerability-Lookup. This record covers the separately maintained self-hosted project. | Commercial on-premises product; the vendor’s compliance and patch modules are not counted as independent tools. Customer-controlled cloud installation is not vendor SaaS. The documented license file controls access to the vulnerability database; application-code rights were not publicly verified. | Romania is the evidenced product-development location, not the licensor's country: Cyscale Limited is registered in England and Wales, its EULA selects Israeli law, and EU ownership or exclusive EU hosting is not established. | This entry groups the core server and sensor transport. Detection depends on the sensors and analysers deployed. | TIE is a provider-operated, contracted API/feed service, not downloadable open-source software or a free public endpoint. DCSO may combine its own, public, commercial and customer-licensed intelligence, so access to underlying data has source-specific conditions. Public TIE documentation does not publish a complete customer license or promise customer-hosted deployment. | Requires DFIR ORC collection output; anomaly ranks are triage leads, not confirmed malicious verdicts. No recent release or explicit maintenance policy was verified. | Windows-only collection tool. Its release notes concern forensic acquisition; no claim of evidentiary integrity certification is implied. | The current v3 branch is beta and the README advises using stable v2.4.29 for production; the preview deployment is only a demonstration. | Requires appropriate tenant permissions and Microsoft licensing; the upstream warns its optional Purview retrieval path remains beta/unusable and this is not a live SIEM. | Beta software with potentially breaking changes and unstabilized parsers; requires DFIR ORC archive input and a separate Windows parser plugin repository. | The upstream README explicitly warns against exposing DFIRTrack on a publicly available server. The German country label is tied to its evidenced lead maintainer. | Fox-IT is part of UK-based NCC Group; Dutch development does not imply EU ownership or hosting. Count the suite once, not its parser modules. | The custom GPL-2.0-derived license has additional clarifications and exceptions, so standard open-source compatibility is unverified. Requires Intel VT-x/EPT and supported Linux/Windows guests; upstream says cloud VM support is unavailable and maintenance is difficult. | The README marks Atomic Red Team testing as work in progress. Country denotes CERT-EU's Brussels base, not a claim that every contributor works in Belgium. | The Dutch product/R&D origin is documented, but EU-only engineering and ownership are not. A vendor license key and paid upgrade do not establish proprietary rights; full core terms need review. | Inspect On-Prem requires compatible ESET endpoint/management components. Do not equate it with the consolidated cloud console. | Runtime runs an agent inside customer devices while the current EULA describes connected SaaS resources; offline behavior, tenancy and hosting region need contract-level verification. This is industrial/embedded detection rather than a general SOC EDR. | Deployment and integration setup remain the operator’s responsibility. | German development and data-center location are vendor statements. They do not establish every subcontractor, legal exposure, or independently verified security status. | Gatewatcher NDR is one platform; Decision Center, AIonIQ, sensors, and TAPs are not split as standalone CSIRT software here. Full product license terms were not publicly verified. | Primarily software auditing and reverse engineering, with vendor-listed incident response use; current release cadence was not verified. Distinct binary-code recognition function from Malware Expert. Audit-specific license terms were not publicly verified. | Only Expert is counted; Malware Detect and Kiosk are linked ingestion/user-facing offerings in the same analysis ecosystem. Vendor efficacy figures are not represented as verified results. Full Malware Expert EULA terms were not publicly verified. | Guardsix promotes SIEM integration; the public pages do not establish whether NDR can operate without any other Guardsix license. | Other HarfangLab ASM, EPP and ITDR capabilities are integrated offerings and are not split here. Vendor hosting claims are not independently audited by this index. Full product license terms were not publicly verified. | A matching hash is context, not a benign or malicious verdict. The server README labels the implementation beta; CIRCL’s public service is best-effort. | README calls this a working prototype/PoC and recommends isolated execution; repository API shows latest code push in May 2023, so ongoing maintenance is unverified. | System/network/web scanning are capabilities of one VMP, not separate catalog products; Swedish hosting is vendor-stated for its SaaS offer. | Certego is the Italian project steward, with international community contributors; this does not establish Italian origin for every analyzer. Self-hosting uses Docker Compose and is supported/tested chiefly on Ubuntu; bundled third-party analyzers and external services have separate terms or credentials. The hosted Honeynet demo requires an invitation and is not listed as a public service. The v6.8.0 release warns that its Docker build lacks ARM support. | A telemetry producer, not an alerting engine by itself; optional hardware acceleration does not mean hardware is required. | Count the framework once; individual Karton workers and plugins are not separate entries. | Linux support depends on the documented kernel compatibility. Running eBPF probes requires elevated privileges. | Linux sample analysis; CIRCL notes limits against evasive malware. The engine is GPL-3.0. The separate web UI has conflicting notices: its LICENSE contains AGPL-3.0, while its README says MIT; confirm the UI terms with upstream before reuse. | The README calls Loki-RS a side project for practical triage and experimentation and points professional support to THOR. The separate Python LOKI predecessor is officially deprecated. | Public-instance submissions follow CIRCL’s service conditions. Results support investigation and do not establish that a file or URL is safe. | The README describes higher-interaction response, DPI routing proxy and Docker appliance as planned or in progress. Bundled libraries retain their respective licenses; no production fitness claim is made. | Email-domain protection assessment rather than incident handling. CERT Polska's Polish instance offers public domain and test-email checks; Lithuania NCSC also operates an instance. These are public institutional services, not a general commercial SaaS offering. | The CESNET-hosted Mentat service and the self-installable software are one system; setup uses several components and can require advanced administration. | Mercury is an account-based intelligence platform and analyst service, not an open-data or downloadable software license. Public portal terms describe hosted access but do not expose the full current subscription or software-license agreement. The company has EU entities beyond Germany; German lead does not mean all engineering is German. Karla is a Mercury-powered feature, not a separate catalog entry. | A developer framework, not a turnkey malware verdict service; analysts need scripts and reverse-engineering expertise. | Requires a separately configured UrsaDB index; README says a public instance is planned, not currently available. | Meta-repository assembles framework, detectors, modules and supervisor; do not count submodules separately. License covers repository notice; components may vary. Maintenance is Unknown because a dated recent release or update was not established for the combined system. | CESNET's public web/API service exposes most data without registration, while full access is limited to trusted partners. Independent self-deployment is possible with assistance but upstream says installation scripts are incompletely tested and documented and some features depend on Warden access. Upstream root license uses alternative terms. | The free edition is GPLv2 and runs locally; paid Professional adds PCAPNG support, enhanced identification and other features under separate commercial licensing. The public product matrix and specifications do not publish full Professional contract terms. Do not treat Professional code as GPL because the free edition is GPL. | The reviewed platform is a business-customer hosted service requiring registration and a license key. Its bundled public terms reserve service intellectual-property rights but are dated July 2020; current negotiated customer terms and any private deployment option were not verified. Its separate MIT-licensed unblob extractor does not make the entire platform open source. | OpenBAS is the previous name, not a separate product. Adversary validation is an imperfect fit for the current Exposure discovery workflow label. | The current Community code uses Business Source License 1.1, not an open-source license. Its additional grant restricts commercial security monitoring and alerting services for third parties; separate commercial terms may be needed. The inspected license names a 2030-08-14 change date to Apache-2.0 for that version. The hosted Cloud service has separate commercial terms; Cloud-only features are not assumed to be included in Community. This tracks disclosed CVEs and does not scan assets for vulnerabilities. | The previous Greenbone Enterprise Appliance name now maps to OPENVAS SCAN. The Enterprise Feed as a whole has subscription restrictions; no blanket proprietary or fully open-source label is accurate. | Log collection infrastructure, not a detector or SIEM by itself; source-initiated push is the only WEF mode documented as supported. | Primarily documented as an audit data collector rather than a complete vulnerability scanner or incident response platform. | Upstream says beta and positions it for Azure security audits, not automated incident response or a general cloud posture platform. | Narrow parser dependent on DFIR ORC archives; current maintenance cadence was not verified. Distinct timeline output from DFIR-OGRE’s general structured extraction. | CompassDRP combines Outpost24’s Swedish line with acquired Spanish Blueliv technology. Engineering spans locations, and ultimate control and hosting region are unverified. | Outpost24’s own history mentions a Vietnam software park. Swedish product origin and a current Karlskrona development team do not establish EU-only engineering or hosting. | This is static file analysis. Configured external workers may receive files or metadata; CIRCL’s public instance has its own documented sharing policy. | The public terms require authorization for tested targets; hosted data location and any separately contracted service scope need buyer review. | The upstream README labels it beta. It orchestrates discovery and exposure monitoring; it is not a standalone vulnerability-verdict engine. | This is an advisory authoring and validation editor, not a vulnerability scanner or managed disclosure service. A demo URL alone is not treated as generally available hosted service. | Sekoia hosts the core platform; on-premises playbook runners do not imply an on-premises Defend product. Reveal and Elevate are dependent add-ons. Full product license terms were not publicly verified. | Standalone Intelligence is API-delivered; platform UI availability and Defend integration depend on subscription. This is an independently licensable product, not a duplicate platform module. Full product license terms were not publicly verified. | Stormshield's general sales terms reserve rights in its software but defer product-specific grants to separate contracts; SES Evolution's full customer license was not publicly verified. | Some analyzers depend on separately configured third-party services or credentials. Its verdicts and classifier outputs are triage aids, not verified determinations. | T-Pot packages third-party honeypots and an Elastic-based analysis stack under their own licenses, so the project GPL does not apply to every component. Honeypots are decoys and require deliberate network isolation and deployment planning. | Current site promotes Tehtris EDR; older XDR AI Platform pages are stale or unavailable. The public product page describes managed European OVHcloud hosting; self-hosted deployment was not reverified. | The fully open-source Node can run locally; the Community and Enterprise App/Platform are proprietary and vendor-hosted, while their nodes also include closed-source parts. The free Community edition has a 1 TB/day ingress limit. Do not infer all prebuilt binaries are solely BSD-licensed; documentation says they may contain proprietary plugins. | THOR is a portable local scanner. Vendor manuals require host licenses and EULA acceptance; the full current EULA was not publicly readable. THOR Lite is a separate free edition, not proof of an open-source license. | Austrian CERT lead and copyright, German Intevation engineering; the contact-management feature is stable while CERT.at calls IPv4 notification management experimental. Successor to archived DO Portal. | The underlying permutation library uses a separate BSD-2-Clause license. A similar or registered domain is not evidence of malicious use. | unblob is a standalone extraction utility released from the commercial ONEKEY platform and does not itself provide a vulnerability verdict. Some optional external extractors have their own licenses and system requirements; the MIT grant applies to the upstream unblob repository. | Requires physical access to the USB medium and a compatible GNU/Linux host; a focused evidence-intake tool, not an end-to-end DFIR platform. | Current VMRay Platform is offered through DeepResponse, FinalVerdict and TotalInsight plans; VMRay Analyzer is a discontinued legacy plan and is not a separate current entry. Product pricing/trial pages establish commercial delivery, but no full platform end-user license was publicly verified. Cloud region or sovereignty claims should not be assumed for every plan. | A vulnerability intelligence and disclosure platform; it does not scan assets to establish whether they are vulnerable. | The CESNET-hosted exchange requires participant registration; official FAQ says operators can run their own server. Core server/client READMEs use older Python/Apache examples and 3.0-beta3 naming. Contrib licenses may differ. | Coverage depends on configured external sources, credentials and feeds; this does not establish completeness or quality of alerts. French country label refers to the evidenced project team. | XM and XDR share one Elements platform but are named distinct purchasable capabilities. No EU-only hosting or ultimate-control claim is made. | WithSecure was taken private by Diana BidCo in 2026; European development does not prove EU-only ownership, infrastructure, or data residency. Elements XDR modules are one offering. |
| Origin evidence | EU-developed | CSIRT-led | CSIRT-led | CSIRT-led | CSIRT-led | CSIRT-led | CSIRT-led | EU-developed | EU-developed | EU-developed | EU-developed | EU-developed | Institution-led | CSIRT-led | EU-developed | CSIRT-led | EU-developed | CSIRT-led | CSIRT-led | EU-developed | EU-developed | EU-developed | CSIRT-led | EU-developed | EU-developed | CSIRT-led | EU-developed | Institution-led | Institution-led | CSIRT-led | Institution-led | Institution-led | EU-developed | EU-developed | CSIRT-led | CSIRT-led | EU-developed | EU-developed | EU-developed | CSIRT-led | EU-developed | EU-developed | EU-developed | EU-developed | EU-developed | EU-developed | CSIRT-led | CSIRT-led | EU-developed | EU-developed | Institution-led | CSIRT-led | CSIRT-led | CSIRT-led | EU-developed | CSIRT-led | Institution-led | CSIRT-led | Institution-led | EU-developed | Institution-led | CSIRT-led | Institution-led | Institution-led | EU-developed | EU-developed | EU-developed | EU-developed | EU-developed | Institution-led | Institution-led | Institution-led | Institution-led | EU-developed | EU-developed | CSIRT-led | EU-developed | CSIRT-led | Institution-led | EU-developed | EU-developed | EU-developed | CSIRT-led | EU-developed | EU-developed | EU-developed | EU-developed | CSIRT-led | CSIRT-led | EU-developed | Institution-led | EU-developed | CSIRT-led | CSIRT-led | CSIRT-led | EU-developed | EU-developed |
| What it does | Public threat-intelligence research platform linking adversary profiles, malware, incident claims, detection-rule references and contextual briefings for analyst investigation. | Collect, correlate and exchange structured threat intelligence, with sharing groups, event synchronisation and exports for detection tools. | Collects and processes security feeds through message-queued bots to automate incident handling, notifications and exchange with other systems. | Collects, manages and distributes security incident and threat feeds to authorized users through a REST API and web interface. | Scans websites for security issues through modular checks and generates readable notices for administrators from the resulting findings. | Collects open-source intelligence, supports analyst reporting and controlled team collaboration, and publishes outputs from a self-hosted Docker deployment. | Stores malware samples and extracted configurations, letting analysts search relationships, share collections and integrate through its REST API. | Threat intelligence platform that structures observables and context with STIX 2, links assertions to sources, and exchanges data through APIs and connectors. | Incident response platform for triaging alerts, opening cases, coordinating investigation tasks, and analyzing observables through connected Cortex services. | Security information and event management product that correlates logs from hybrid infrastructure and provides detections, investigation context, and audit evidence. | Extended detection and response product that correlates endpoint, identity, network, and cloud signals to investigate incidents and coordinate response actions. | Collects forensic artifacts from live systems or disk images into lightweight containers for triage and subsequent independent investigation. | PowerShell utility that reconstructs partial timelines of Active Directory object changes from replication metadata for incident investigation and threat hunting. | Collect and analyse unstructured web, chat and file data to investigate information leaks and extract threat intelligence. | Incident-response console that deploys agents, schedules compromise scans, manages indicators, collects evidence, and executes response playbooks across endpoints. | Aggregate malicious-activity observations by autonomous system number and inspect comparative rankings and historical changes. | Indexes large PCAP collections, identifies network protocols, filters suspicious flows and exports selected packets for deeper forensic analysis. | Maintain trusted contacts, organisational affiliations and public keys, and connect security tools across collaborating response teams. | Transforms incident logs and tables into enriched, filtered or split reports that CSIRTs can send to responsible contacts through SMTP or OTRS. | Observable analysis and response engine that runs analyzers and responders through a shared API, commonly connected to TheHive investigations. | Deception platform that deploys realistic decoy assets, records adversary interaction, and enriches resulting alerts with indicators and attack-technique context. | Parses system and application logs to detect hostile behavior, generate local decisions and feed remediation components for blocking or challenging attackers. | Import vulnerability and platform-enumeration data into a local database, then search it through command-line, web and API interfaces. | Vulnerability management software that discovers assets, scans for affected technologies, prioritizes findings using context, and supports patch decisions and remediation. | Cloud security platform linking vulnerable software, exposed workloads, identities and ownership so teams can prioritize and route remediation. | Build a distributed sensor network that collects security telemetry and dispatches it to configured decoders and analysers. | Aggregates selected intelligence feeds, normalizes and contextualizes indicators, then exposes tailored IoC collections through an authenticated API. | Standalone analysis tool that ranks anomalous Windows PE files from DFIR ORC metadata and exports triage results as CSV or PDF. | Windows forensic acquisition utility for collecting incident response artefacts from hosts into structured archives for later analysis and evidence handling. | Collaborative incident response workspace for sharing technical investigation details, organizing cases, and tracking evidence and timelines across responders. | PowerShell forensic collection module that retrieves Microsoft 365 audit events and Entra sign-in logs for post-incident investigations. | Command-line parser that extracts Windows artefacts from DFIR ORC archives into structured records for analysis in search and analytics systems. | Tracks affected systems, incidents and investigative tasks in larger digital forensics and incident response cases through a shared web interface. | Opens forensic images and file collections for cross-platform artifact analysis through a modular Python framework and command-line investigation tools. | Runs automated agentless malware analysis in virtualized guests and exposes a web interface for submissions and examination of results. | Validates and transforms Sigma detection rules, then searches or deploys them across compatible SIEM and EDR environments through a command-line workflow. | Threat intelligence platform for ingesting, structuring, analyzing, and sharing indicators and adversary context through analyst workflows, APIs, and integrations. | Endpoint detection and response console that collects endpoint events, investigates anomalies and indicators, and provides response actions through an on-premises server. | Embedded runtime security platform with on-device agents that monitor and block malicious behavior and send fleet telemetry for investigation. | Organise investigation cases, tasks and analyst notes, with templates, assignments and integrations for threat intelligence workflows. | Endpoint detection and response offering that correlates signals across devices, prioritizes incidents, and supports process termination or file quarantine. | Network detection and response platform that analyses traffic and metadata, prioritizes suspicious activity, and supports threat hunting and incident investigation. | Binary analysis product that recognizes libraries and known code across architectures, supports software reverse engineering, and exports symbols to analyst tools. | File analysis workspace that combines static and dynamic engines, extracts indicators and malware context, and supports investigation and threat hunting. | Network detection and response product that analyzes network telemetry, groups related activity into attack chains, and supports investigation in on-premises environments. | Endpoint detection and response software that monitors workstation and server activity, raises investigation alerts, and supports blocking and response actions. | Look up file hashes in known-file datasets to add context during incident investigation and forensic triage. | Fingerprints malware HTTP requests from packet captures so analysts can compare traffic patterns and group activity associated with malware families. | Vulnerability management platform that scans systems, networks, and applications, tracks exposure over time, and supports risk-based remediation across an organization. | Enriches files and indicators such as IP addresses, domains and hashes through configurable analyzers, with a shared REST API and investigative interface. | Exports bidirectional network flow records with protocol metadata and telemetry for downstream monitoring and investigation systems. | Runs distributed malware processing tasks using Python workers, Redis messaging and S3 storage, with independent analysis services around the core framework. | Monitor Linux host and container events with eBPF instrumentation and on-host event enrichment for detection and threat hunting. | Run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering. | Scans files, process memory and archives for YARA rules and indicators of compromise during endpoint triage and threat hunting. | Capture websites and inspect the domains and requests involved in loading a page during web and phishing investigations. | Runs a low-interaction network sensor that records connection attempts across services to help analysts observe mass scanning and attack patterns. | Checks a domain's SPF and DMARC records and validates DKIM through a test email, with a self-hosted portal reusable by other CSIRTs. | Processes structured security events in a modular SIEM, providing a web interface, searchable event records and periodic notifications to affected networks. | Delivers analyst-reviewed threat intelligence, vulnerability alerts, contextual risk scoring, IOC access and tailored reports through a customer web portal. | Python reverse-engineering framework for disassembly, binary rewriting, intermediate representation, emulation, unpacking and expression simplification during binary analysis. | Indexes local malware collections with UrsaDB and provides a web interface for analysts to search those samples using YARA rules. | Analyzes network flows through modular detectors for malicious traffic such as scans, denial-of-service activity and DNS tunneling. | Aggregates data about known malicious network entities, chiefly IP addresses, and presents the combined context to investigators. | Parses PCAP traffic to reconstruct transferred files, credentials and host context for network forensic investigation and incident response. | Analyzes embedded firmware binaries to inventory components, generate SBOMs, identify known vulnerabilities and monitor product risk over subsequent releases. | Adversarial exposure validation platform for planning and running attack simulations, measuring defensive coverage, and tracking remediation against tested scenarios. | Tracks published vulnerabilities for selected vendors and products, with CVE filtering, subscriptions, notifications and shared remediation tracking for security teams. | Vulnerability scanner for networks, endpoints, and containers with authenticated checks, risk prioritization, remediation guidance, and virtual-appliance deployment. | Linux-based Windows Event Collector server that receives source-initiated event forwarding without installing an additional Windows agent. | Windows command-line utility that exports Active Directory data through LDAP, including multi-domain forests, to support directory security audits and investigations. | Beta command-line utility that dumps Azure configuration data through REST APIs to support security audits and manual exposure review. | Local command-line utility that processes one or more DFIR ORC forensic archives and creates a per-host timeline for incident analysis. | Cloud digital-risk product that combines external asset discovery with threat intelligence and monitors exposed credentials, leaked data, and phishing domains. | Vulnerability management product that scans network and cloud assets, prioritizes findings with exploit context, and tracks remediation through reports and workflows. | Inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports. | Hosted security testing platform for scanning and validating vulnerabilities in web applications, networks and cloud infrastructure, with findings and reporting workflows. | Schedule distributed perimeter scans, retain observations over time and search changes in exposed services and technical metadata. | Creates and edits machine-readable CSAF security advisories in a web interface for coordinated publication and exchange of vulnerability information. | Cloud security operations product that ingests telemetry, applies detection rules, supports alert and case investigation, and runs automated playbooks. | Threat intelligence product with searchable actor, campaign, malware and indicator records, analyst reports, feeds, and APIs for dissemination to security systems. | Endpoint detection and response software for workstations and servers, with behavioral detection, YARA-based hunting and predefined or custom remediation actions. | Triages suspicious emails, files, URLs and indicators through configurable analyzers, then presents investigation reports in a self-hosted web interface. | Combines multiple honeypots and a local analysis stack to collect, search and visualize attempted attacks against decoy network services. | Endpoint detection and response product that monitors execution and privilege activity, investigates suspicious behavior, and can block processes or isolate hosts. | Collects, parses, transforms, enriches and routes security telemetry through programmable pipelines for detection, investigation and downstream security tools. | Portable compromise-assessment scanner that searches live hosts or forensic images using YARA, Sigma, indicators, and anomaly checks without installation. | Lets a CERT constituency manage organization contacts and network objects so IntelMQ can route security notifications to the appropriate recipients. | Generate and resolve look-alike domain names, inspect results and export findings for follow-up threat intelligence analysis. | Recursively extracts firmware and other binary containers, carves unknown chunks and produces structured reports for analysts examining embedded-device images. | Linux tool for forensic examination of untrusted USB devices, with read-only mounting, disk imaging and controlled file transfer. | Analyzes suspicious files, URLs and emails with layered sandbox techniques, returning behavioral findings, verdict context and extracted indicators for responders. | Correlate vulnerability records across sources, track sightings and support advisory publication and coordinated vulnerability disclosure. | Shares structured security-event reports between authenticated CSIRT participants through a server, sending clients and receiving clients using the IDEA format. | Monitors vulnerability, ransomware and news sources against watch terms, collecting results and sending alerts through a self-hosted analyst interface. | Cloud exposure management offering that discovers assets and vulnerabilities across devices, identities, cloud, and external surfaces, then ranks remediation work. | Cloud extended detection and response offering that correlates endpoint, identity, email, and cloud telemetry to investigate and contain multistage attacks. |
| Origin notes | IntelFusions is a Romanian threat-intelligence research platform. Its About page identifies Antonio Radu as the founder who built it. The country was confirmed directly by the index owner on 10 October 2026. | The EU CSIRTs Network tooling directory identifies CIRCL as the CSIRT lead. The project also credits Belgian Defence and international contributors; Luxembourg records CIRCL stewardship, not exclusive authorship. | EU CSIRTs Network Tooling WG names CERT.at as lead; upstream credits a wider European CERT community. | Upstream README explicitly attributes development to CERT Polska. | Maintained under CERT Polska's verified upstream organization. | README explicitly credits SK-CERT and the wider CSIRT community. | Maintained in CERT Polska's upstream organization. | Designed and developed by French company Filigran; the repository does not establish that every contributor or hosting region is French. | Began in an unnamed European financial institution CSIRT; current developer and licensor is French company StrangeBee. The original CSIRT country was not established. | Guardsix traces its SIEM to Danish Logpoint; its published history records a Danish startup acquisition behind the first SIEM. Current shareholders and all engineering locations are not established here. | Bitdefender identifies its Bucharest research and innovation hub and Romanian product R&D centers; the exact engineering split for GravityZone XDR is not public. | Dissect Team at Fox-IT publishes Acquire as a separate installable tool. | Published by ANSSI with French agency presentations of the method in 2019. | The upstream README explicitly states that AIL was originally developed at CIRCL, the Computer Incident Response Center Luxembourg. | Nextron's German engineering team created the THOR/ASGARD product line and remains the named steward; exact locations of all current contributors are unpublished. | The project history describes CIRCL support from its 2010 origin and a rewrite within the CIRCL-led D4 project. | Netresec says it develops its network forensic products in Sweden, and its official CapLoader page identifies this product as one of those tools. | The upstream README credits CIRCL in Luxembourg and contributors; the CSIRTs Network tooling directory identifies CIRCL as project lead. | Upstream README explicitly says Convey is brought by CSIRT.cz within the Czech CZ.NIC organization. | Fully developed and maintained by French company StrangeBee since 2018, according to its official documentation. | CounterCraft's founders identify San Sebastián, Spain, as their research-and-development headquarters; group entities also operate in the US and UK. | CrowdSec's own account says French Grand Défi Cyber funding supported development of its open-source software and expansion of its R&D team; the publisher is registered in Montrouge, France. | CIRCL’s published tooling document identifies CIRCL as the CSIRT lead for CVE Search. Its current inventory still includes the project, which also has independent contributors. | Built by Cyberwatch’s product team in France; the company identifies itself as a Framatome Cybersecurity subsidiary since 2022. | Cyscale advertises Romanian engineering and product roles that build the platform, while the contracting company is registered in England and Wales. | The D4 project identifies CIRCL, Luxembourg House of Cybersecurity, Luxembourg, as its project contact and organisation. | DCSO describes TIE as its own platform and operates the threat-intelligence service from its Berlin-based GmbH; its team performs research and feed integration. | Developed and managed by ANSSI, the French national cybersecurity agency, for analysis of DFIR ORC collection output. | Managed by ANSSI, the French cybersecurity agency, with the repository explicitly naming ANSSI stewardship. | Originated inside the Airbus Cybersecurity commercial CSIRT in France in 2019; now maintained by the independent DFIR-IRIS project. | Published under ANSSI’s official repository and described as an incident-response forensic tool. | Managed by ANSSI and announced in its official open-source portfolio in May 2026. | The lead contributor and copyright holder Mathias Stuhlmacher publicly lists Germany as his location; this does not establish every contributor's country. | Upstream identifies Dutch Fox-IT's Dissect Team as developer. | Upstream maintainers use CERT.PL contact and credit CERT Polska among creators. | The project is published by CERT-EU, the EU institutions' computer emergency response team based in Brussels, Belgium. | EclecticIQ began its Intelligence Center platform in Amsterdam and received Dutch/EU financing for platform R&D. The vendor also disclosed an India engineering hub; the exact current engineering split is not public. | ESET's Slovak product R&D operation includes its EDR line; public evidence does not isolate every ESET Inspect developer or component location. | Exein's EULA names Rome-based Exein S.p.A. as developer and licensor of Exein Runtime; the company also has non-Italian offices. | Flowintel’s README credits CIRCL in Luxembourg and David Cruciani, and identifies CIRCL and the EU FETTA project as funders. | G DATA explicitly states that this XDR product is developed in Germany; the product page also says the hosted console stores data in German data centers. | Developed by French company Gatewatcher, which identifies its own NDR platform and has headquarters in France. | Offered by French publisher GLIMPS as a distinct reverse-engineering product. | Developed by French publisher GLIMPS; an ANSSI service legal notice independently names GLIMPS as its software publisher in Cesson-Sévigné. | Guardsix NDR continues a product line acquired from Danish Muninn; current engineering distribution and ultimate control require separate verification. | Created by HarfangLab, whose founders built its EDR; HarfangLab describes its engineering and teams as Europe-based and itself as a French company. | The server README credits CIRCL, Computer Incident Response Center Luxembourg, and Alexandre Dulaunoy. | CERT Polska publishes the Python/Tshark prototype as a standalone CLI and library. | Holm Security says its platform is built in Europe and identifies itself as a Swedish company; the exact engineering country and staffing are unpublished. | Certego says it created IntelOwl in 2020; upstream says project management moved fully to Certego with version 6.8.0. Certego is based in Modena, Italy. | CESNET's upstream repository and license identify the Czech association. | CERT Polska publishes and maintains the upstream framework. | CIRCL’s own technical article explicitly describes developing Kunai for Linux security monitoring. CIRCL is based in Luxembourg; the project also accepts wider contributions. | The Kunai Project is based in Luxembourg; CIRCL identifies this as its Linux malware sandbox and links the upstream installation source. | The current Rust successor is developed by Florian Roth, whose upstream profile identifies Frankfurt, Germany; the older Python LOKI is deprecated. | The software license credits CIRCL in Luxembourg alongside the project authors and Viper Framework. CIRCL operates the documented public instance. | The upstream MADCAT v2 project is published by Germany's Federal Office for Information Security, whose project organization lists Bonn, Germany. | CERT Polska published the former Bezpieczna Poczta code as a white-label tool for other national CSIRTs; Lithuania NCSC runs an instance. | CESNET publishes the Mentat SIEM source and attributes the system copyright to the Czech association. | QuoIntelligence says it was founded in Frankfurt in 2020 and its Mercury-backed platform is developed and operated within the EU; its current entities and team span Germany, Italy and Spain. | Hosted and maintained by CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group. | CERT Polska publishes and maintains the mquery malware search interface; UrsaDB is its separate indexing dependency. | Upstream repository belongs to the Czech CESNET association and its license credits CESNET. | CESNET publishes NERD and names its Czech security research programme as development context. | Netresec identifies itself as the developer of network forensic software and lists a Swedish legal address; founder Erik Hjelmvik identifies himself as NetworkMiner creator. | ONEKEY says it launched in 2020 as IoT-Inspector, a SEC Consult spin-off, and built its firmware platform with a team across Germany, Hungary, Austria and Belgium. The contracting company is in Düsseldorf. | Designed and developed by French company Filigran; formerly named OpenBAS. | OpenCVE identifies Amber Security SAS as its publisher; the French company describes OpenCVE as its own vulnerability-monitoring solution and lists its registered office in Lille. | Greenbone explicitly says OPENVAS SCAN was developed in Germany and remains its German product stewardship; upstream open-source components and paid feed differ in license. | Published and maintained by CEA IT Security within the French national commission. | Published in ANSSI’s official project organization by the French national cybersecurity agency. | Published by ANSSI, the French national cybersecurity agency, in its official project organization. | Published in ANSSI’s official GitHub organization as a standalone forensic parser. | Outpost24 began product development in Sweden and still has a development team at its Karlskrona headquarters; it also operates outside the EU. The exact engineering allocation for this product is not public. | Outpost24 began product development in Sweden and still has a development team at its Karlskrona headquarters; it also operates outside the EU. The exact engineering allocation for this product is not public. | The README credits CIRCL and Raphaël Vinot in Luxembourg, alongside CERT-AG, for Pandora’s development. | Built by the Bucharest-based Pentest-Tools.com team; Romanian company and platform licensor are identified in its public terms. | The CIRCL-led D4 project describes Plum as its project for monitoring Luxembourg’s perimeter and explains its development within FETTA. | BSI's official repository identifies Secvisogram as its CSAF web editor; BSI is a German federal institution based in Bonn. | Built by Sekoia.io SAS, a French security software company with its registered office in Rennes. | Built by Sekoia.io SAS and its threat research team in France; separately licensed from Sekoia Defend. | Stormshield states that all of its R&D teams and product development are in France; it identifies Airbus Defence and Space Cyber Programmes as owner. | The upstream project says Thales Group CERT built and maintains Suspicious; its lead contributor's profile lists Thales CERT in France. | The upstream project is maintained by Deutsche Telekom Security GmbH, whose official GitHub organization identifies Bonn, Germany as its location. | Tehtris identifies itself as a French company and says its EDR is designed, developed and operated in Europe. | Tenzir GmbH says it developed the current software and operates from Hamburg. Its preceding VAST research began at UC Berkeley; the German claim concerns the current company-led Tenzir product, not every historical contributor. | Nextron describes THOR as originating in German security engineering work and remains its named German developer and commercial steward. | CERT.at/nic.at leads and holds copyright; software engineering is explicitly credited to Intevation in Germany. | CIRCL lists Typosquatter among its own project organisations and provides the tool’s public project page in Luxembourg. | ONEKEY announced its standalone unblob extraction suite from Düsseldorf in 2022, and the current project license names ONEKEY GmbH as copyright holder. | Developed in CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group. | VMRay says its founders developed pioneering sandbox technology during doctoral work in Bochum and founded VMRay GmbH there in 2013; the present platform has global staff and customers. | The upstream README identifies CIRCL, Computer Incident Response Center Luxembourg, and named project contributors as copyright holders. | CESNET-CERTS developed Warden for the Czech research network and publishes the server/client source. | Thales Group CERT calls itself the developer; prominent project contributors publicly identify with Thales CERT in France. | WithSecure is the Finnish business-security successor to F-Secure; its current European product-development statement covers Elements generally, not a published XM engineering roster. | WithSecure is the Finnish business-security successor to F-Secure and says current Elements XDR product development and delivery are based in Europe. |
| Reported capabilities | Threat actor and malware profiles linked to an intelligence graph · Detection-rule references with ATT&CK mappings and original-source links · Intelligence briefings and country views for research | Correlates indicators and related intelligence objects. · Supports MISP, STIX and detection-rule export workflows. | Feed collection and processing · Automated incident notifications · Message-queue architecture | Feed handling · REST API and web portal · Authorized distribution | Modular web checks · Automatic reports · Experimental upstream | OSINT collection · Analyst reports · Team collaboration | Sample and configuration repository · Search and relationships · REST API | Stores linked technical and nontechnical threat intelligence with source references. · Imports and exports STIX 2 and CSV data and exposes a GraphQL API. · Community Edition uses Apache-2.0; Enterprise Edition has a separate license. | Turns alerts into cases and tracks investigation work. · Community license is free for on-prem use but requires activation; cloud is a paid Platinum option. · TheHive 5 Community license restricts modification and redistribution. | Collects logs across hybrid, on-premises, OT, and cloud environments. · Supports self-hosted and air-gapped deployment. · Formerly named Logpoint SIEM; the current Guardsix name is a rebrand. | Correlates telemetry across multiple security sensors. · Supports investigation and response from the GravityZone console. · The XDR feature matrix labels XDR as GravityZone Cloud only. | Live or image acquisition · Artifact profiles · Lightweight container output | Builds partial timelines of selected Active Directory objects and attribute changes. · Includes a Splunk app with dashboards for suspicious directory changes. · Highlights group, ACL and privileged-account changes for analyst triage. | Keyword, regular-expression and YARA tracking with historical hunts. · Extracts indicators and exports findings to MISP. | Controls endpoint scans and custom indicator checks. · Runs response playbooks for quarantine, collection, and remote commands. · Ships as a hardened virtual appliance. | Ranks ASNs using configured malicious-activity datasets. · Exposes historical ASN information through an API. | Large-PCAP flow indexing and filtering · Protocol identification and suspicious-flow alerts · Packet export and carving from memory or disk images | Synchronises contact information between Cerebrate instances. · Provides APIs and tooling connections for community coordination. | Log/table conversion and enrichment · Split by incident contact · SMTP or OTRS delivery | Automates observable analysis through analyzers. · Runs responders as investigation actions. · Licensed under AGPL-3.0 and deployable with packages, Docker or Kubernetes. | Deploys decoy systems that mirror production assets. · Records interactions and adds indicator, TTP and MITRE ATT&CK context. · Product terms grant a limited license to access, install and deploy where applicable. | Log-based attack detection · Local API decisions · Optional remediation components | Supports local CVE and CPE lookups. · Provides searchable vulnerability records through a web interface and API. | Maps assets and continuously detects relevant published vulnerabilities. · Prioritizes risk using business context and supports remediation. · Runs within customer-controlled local or cloud infrastructure. | Maps vulnerable packages and images to deployed cloud workloads. · Adds internet exposure, reachability and ownership context to triage. · Delivers the platform by SaaS under Cyscale Limited's EULA. | Registers and manages sensors through a central server. · Carries telemetry streams to downstream decoders and analysis queues. | Indicator aggregation and contextualization · Tailored API feeds and STIX/TAXII access · DCSO analyst and sensor enrichment | Ranks Windows PE files by metadata-based anomaly scores. · Accepts DFIR ORC NTFSInfo CSV files or archives. · Exports CSV and PDF views, with an optional Splunk dashboard. | Collects forensic artefacts from Microsoft Windows systems. · Packages collections through a configurable Windows executable. · Current upstream release is v10.4.0. | Multi-user web workspace shares investigation details and cases. · Stable v2.4.29 remains recommended for production while v3 is beta. · The umbrella project is licensed LGPL-3.0. | Collects Microsoft 365 Unified Audit Log and Entra sign-in/audit records as JSON. · Offers Docker and PowerShell installation. · Can optionally retrieve Azure Monitor and Azure DevOps audit logs. | Parses browser, file-system, process and Windows event artefacts in ORC archives. · Outputs structured data for Splunk, ELK or other stores. · Upstream README explicitly labels the project beta. | System-based incident tracking · Shared case and task records · Ubuntu, Docker and Ansible installation routes | Image and filesystem parsing · target-query and target-shell · Modular artifact parsers | Hypervisor-level analysis · Web upload and results · Installer provided | Sigma detection-as-code workflow · Rule validation and transformation · SIEM and EDR query or deployment | Current Intelligence Center 3.9 release documents threat intelligence workflows and integrations. · Official installation guide covers customer-hosted and offline deployment. · The vendor requires an instance-specific license key; full current core rights terms were not publicly readable. | On-premises server, connectors, and web console are documented. · Includes incident investigation, rules, and response features. · Inspect Cloud's separate console was consolidated into ESET PROTECT; On-Prem remains documented. | Kernel-level agents monitor and block suspicious behavior on embedded systems. · Fleet console traces incidents and produces runtime evidence. · Customer devices exchange information with Exein resources under the SaaS model in its EULA. | Case and task templates support repeatable response procedures. · Integrates MISP taxonomies and galaxy data, with export modules. | Correlates endpoint signals in a browser console. · Responds by quarantining files or terminating processes. · Vendor says development and hosting are in Germany. | Analyzes network communications and metadata for behavioral threats. · Aggregates and prioritizes alerts for SOC investigation. · Vendor describes on-premises, SaaS and hybrid deployment options. | Identifies static libraries and known code in binary files. · Supports multiple processor architectures and symbol transfer to IDA and Ghidra. · Can be used on-premises without an internet connection. | Analyzes submitted files with static, dynamic and hybrid engines. · Extracts malware families, malicious functions, indicators and ATT&CK mapping. · Supports YARA rules, retro hunting and MISP/STIX/JSON exports. | Analyzes network telemetry for suspicious behavior. · Presents correlated activity as attack chains. · The vendor describes on-premises and hybrid deployment. | Endpoint agents detect and block threats on workstations and servers. · Analysts can tune alerting, access telemetry and investigate via console and API. · Offers both cloud and on-premises console deployment. | Supports individual and bulk hash lookups through a REST API. · Can import NSRL and other supported file-hash datasets. | HTTP request fingerprints · PCAP file or folder input · JSON output | Scans systems and network exposure through one platform. · Provides both cloud and on-premises platform deployments. · The vendor says its SaaS data center is in Sweden. | File and observable enrichment · REST API and analyst web interface · Docker Compose deployment | Bidirectional IPFIX export · Protocol parsers · High-speed capture options | Distributed processing framework · Redis task routing · S3 sample exchange | Produces chronologically ordered Linux activity events. · Provides container-aware monitoring in a standalone Rust binary. | Supports x86_64 and aarch64 sandbox environments. · Records host activity alongside network captures. | YARA and IOC endpoint scans · File, process memory and archive coverage · Command-line and prebuilt binary use | Visualises relationships between domains involved in a capture. · Provides a REST API for capture workflows. | Low-interaction network sensor · Connection attempt logging · Attack-pattern observation | SPF, DMARC and DKIM checks · Domain and test-email methods · Reusable CSIRT deployment | IDEA event processing · Web interface and API · Per-network event reporting | Curated threat and vulnerability intelligence · Client-specific risk scoring and reports · Portal knowledge base and API access | Parses and modifies PE and ELF binaries. · Disassembles multiple CPU architectures and models instructions in an intermediate language. · Supports JIT emulation and de-obfuscation. | YARA queries over sample collections · UrsaDB index acceleration · Docker Compose deployment | Flow-based analysis · Modular detectors · Supervisor orchestration | Malicious IP context · Data aggregation · Web and daemon components | PCAP-based artifact reconstruction · Passive host inventory and live capture · Free GPL edition plus paid Professional features | Binary firmware component analysis · SBOM generation and CVE matching · Ongoing product vulnerability monitoring | Runs simulation campaigns and individual tests against selected targets. · Reports validation results to help prioritize remediation. · Community Edition is Apache-2.0; Enterprise Edition has a separate license. | Vendor and product CVE subscriptions · Risk filtering and notification workflows · Docker deployment or hosted Cloud service | Scans network services, endpoints, and container images. · Runs as customer-hosted virtual or hardware appliance. · Enterprise Feed is subscription controlled despite open-licensed individual tests. | Receives Windows event logs using the built-in Windows Event Forwarding protocol. · Runs a Linux server with a CLI for subscription management. · Supports source-initiated push mode. | Exports Active Directory data via LDAP. · Supports multi-domain forests. · Provides configurable x86 and x64 executable releases. | Collects Azure configuration through REST APIs. · Runs as an executable using an adjacent XML configuration file. · Upstream explicitly marks the project beta. | Accepts one or more ORC archives. · Groups archives by host and writes compressed CSV timelines. · Installs as a Python package with pip. | Combines attack-surface discovery, digital risk monitoring, and threat intelligence. · Monitors stolen credentials, leaked data, and phishing domains. · Vendor calls it a cloud-based solution. | Continuously identifies vulnerabilities across network and cloud assets. · Prioritizes with exploit intelligence, asset context, CVSS, EPSS, and KEV. · Vendor offers SaaS, hybrid, and on-premises delivery. | Combines file checks including YARA and configured external analysis workers. · Offers file previews and shareable analysis results. | Scans web applications, networks and cloud infrastructure. · Provides continuous vulnerability scanning and validation, findings management and reports. · Customers access the hosted platform or API under a restricted internal-use license. | Orchestrates scan jobs across agents and target profiles. · Searches retained observations and exports reports or CSV/JSON results. | CSAF 2.0 and 2.1 advisory editor · Web-based validation and editing · Self-deployment documentation | Collects logs from endpoints, cloud services, networks and applications. · Applies detection rules and provides alert triage and case management. · Runs playbooks for enrichment and response. | Searchable CTI records connect actors, malware, campaigns, infrastructure and indicators. · Feeds, TAXII, MISP connectors and APIs distribute intelligence. · Can be purchased independently of Defend as an API-delivered CTI product. | Detects and blocks suspicious endpoint activity with a local agent. · Supports YARA hunting, IOC searches and incident-remediation actions. · Available as on-premises software or SaaS. | Email and file triage · Configurable indicator analyzers · Web reports and optional mailbox intake | Multiple integrated honeypots · Attack event search and visualization · Standalone or distributed deployment | Endpoint agent monitors workstations and servers for suspicious activity. · Console supports fleet search, alert triage and configurable response. · Can stop processes or isolate hosts according to policy. | Programmable security-data pipelines · Self-hosted nodes with CLI/container deployment · Hosted control plane for Community and Enterprise editions | Scans live systems, images, registry data, and event logs. · Runs as a portable binary on Windows, Linux, and macOS. · Accepts custom YARA rules and indicators. | Self-service contact management · Network object and notification rules · IntelMQ contact lookup | Offers selectable domain-permutation algorithms and DNS results. · Exports results as JSON and MISP events. | Recursive firmware/container extraction · Unknown-region carving and entropy analysis · CLI and container deployment | Supports forensic analysis of untrusted USB mass-storage devices. · Can mount a device read-only and create a device image. · Separates parsing tasks into restricted user-space processes. | Malware and phishing sandbox analysis · Behavioral findings and extracted IOCs · Cloud or on-premises product plans | Combines vulnerability feeds with comments, bundles and sightings. · Provides a lookup API and coordinated-disclosure workflows. | IDEA event exchange · Authenticated server and clients · Self-hostable server | CVE and ransomware source monitoring · Keyword watch rules and alerts · Docker-hosted analyst interface | Discovers devices, identities, cloud assets, and external exposure. · Visualizes possible attack paths and prioritizes remediation. · Delivered through the Elements cloud platform. | Correlates endpoint, identity, email, and cloud signals. · Uses the cloud Elements Security Center. · WithSecure reports European development, delivery, and support for Elements XDR. |
| Research date | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 | 10 October 2026 |
| Primary sources |
Different workflows solve different problems. This comparison shows documented attributes; it does not score or rank security quality. Read our method.