Follow the evidence.

A useful listing tells you what the sources establish, where the limits are, and how to check for yourself.

Scope: EU-27Latest source review: 10 October 2026

What belongs here

Tools for incident response, threat intelligence, detection, malware analysis, exposure discovery, response coordination and digital forensics. Each published record needs primary evidence connecting its development or lead stewardship to an entity in an EU member state.

A sales office, an EU hosting option, a domain suffix or an individual’s name is insufficient. The index includes international projects with documented EU origins or stewardship; it does not claim that every contributor or owner is in the EU.

We count independently usable tools and platforms. Renamed products, editions, SDKs, connectors and bundled modules do not become extra listings. Archived, discontinued and insufficiently evidenced candidates remain outside the published catalog.

Each tool has one primary browsing workflow. These are editorial groupings, not an official EU taxonomy. Response coordination includes case handling, reporting and trusted contact management.

Three origin labels

CSIRT-led

Primary project or institutional sources identify an EU CSIRT as a developer or lead. The origin note distinguishes historical development from current stewardship when needed.

Institution-led

An EU public agency, university or research institution is documented as a developer or project lead.

EU-developed

The record identifies an EU developer or development origin. This can include commercial products and independent projects with international contributors or owners. Direct confirmations supplied by the project owner are identified separately from public sources in the evidence record.

These labels describe provenance. They are not ratings, accreditations or security certifications.

Index order is an editorial choice.

IntelFusions appears first at the site owner’s request. Position is not a quality score or recommendation. Name sorting remains alphabetical.

Country answers one question.

The country field identifies the documented developer, originating team or project lead. It does not establish exclusive engineering location, ultimate ownership or data residency.

Origin
Who created or leads the tool, with the basis for the country label.
Control
Current ownership where primary sources establish it, including material acquisitions or non-EU parents.
Engineering
Documented development locations. A headquarters address alone does not establish this.
Hosting
Supported delivery models. A cloud option does not promise a particular data region.

Unknown details remain unknown. A source review is not an independent corporate-ownership audit.

How a record is researched

  1. Find the upstream product.Check the official repository, documentation or product page. Resolve renamed products and distinguish current editions.
  2. Establish the EU connection.Read development, project-lead and institutional evidence. Preserve relevant ownership and contributor qualifications.
  3. Check individual claims.Record supported capabilities, documented deployment options and software license terms. If a commercial contract is not public, record the gap. Search-result snippets are discovery aids, not proof.
  4. Record limits and dates.Keep a dated observation for each evidence source. Each profile exposes the research notes and links behind its claims.

The current catalog contains 97 reviewed profiles. A review date marks when sources were examined, not a live verification signal. Candidate discovery and source review were assisted by automated research; the records were checked against the linked primary material.

Download the complete catalog and evidence records to inspect the data.

Read the license and status together.

Open source requires an identifiable open-source software license. Open core combines an open-source base with separately licensed features. Commercial denotes a sold product or subscription offering. It can include a package combining open-source components with separately licensed feeds. Source available means the code is readable, but the reviewed terms do not support a standard open-source classification. Free service identifies a publicly accessible offering whose reviewed terms explicitly say access is free; it makes no claim that its software or datasets are open source. A free tier alone establishes neither open-source category.

The license field describes the reviewed product or component, not every dependency, dataset or commercial add-on. Where those differ, the scope note explains the distinction. Some commercial contracts are not public: those records explicitly say the full terms were not publicly verified. Commercial availability alone does not establish reuse or redistribution rights.

Active
Recent upstream development, releases or an explicit current maintainer statement was found. For commercial products, current official product and support material establishes availability. For public services, dated published updates establish observed activity. This does not measure maintenance quality or promise support.
Experimental
The upstream project describes itself as beta, experimental or incomplete. It may also have frequent development activity.
Maintenance unconfirmed
The tool and its provenance are documented, but current maintenance could not be established from the reviewed material.

Self-hosted means the software can be operated in your environment. Desktop/CLI identifies local utilities. SaaS is a documented hosted product. Public service is an upstream public instance or API with its own usage conditions; it does not imply a service-level agreement.

How EU funding is documented

The funding filter includes a tool only when a primary source connects its development, a named component or a tool-specific improvement to an EU programme. Each record names the programme and project, provides the grant identifier where established, and links to the source.

Funding through a documented intermediary can qualify. National funding alone, a vendor’s EU address or participation in an unrelated consortium does not. Historical funding stays explicitly scoped; the label is not an EU endorsement, certification or claim of current support. Missing funding evidence means unknown in this pass.

Inspect the documented EU-funded collection.

How capabilities and integrations are tagged

A tag needs explicit upstream documentation of the operation: for example importing STIX, serving TAXII, storing YARA rules, executing detections or connecting through a separate component. Each tag carries a source, a review date and a support note. Versions, editions and connector requirements are retained where the source states them.

A name in a marketing list is not a tested integration. We do not transfer a feature from one product to every product from that vendor. No tag means the capability has not been established here, not that it is absent. Both capability and integration filters must match when used together.

Explore the documented support collections or send a primary source for review.

What this research does not establish

Capabilities are documented project or vendor claims. We have not installed or security-tested every tool, benchmarked performance, or performed procurement or legal due diligence. Product details and sources can change.

The catalog is selective, not an exhaustive market census. A missing product has not necessarily been rejected. There are no paid listings or sponsored ranking in this build.

CSIRTS.eu is independent of ENISA, CERT-EU, the EU CSIRTs Network and listed vendors. It is not an incident-reporting channel.

Inspect the source behind a claim.

Open a profile to read its origin note, license, limitations and dated evidence.

Explore the index