YARA Capability
Uses YARA trackers on collected content and supports retrospective YARA hunts over historical data.
An independent tool index
for incident response teams
Threat intelligence CSIRT-led
Collect and analyse unstructured web, chat and file data to investigate information leaks and extract threat intelligence.
By CIRCL and project contributors · Luxembourg
Primary sources connect this project to an EU CSIRT as developer or lead.
The upstream README explicitly states that AIL was originally developed at CIRCL, the Computer Incident Response Center Luxembourg.
Crawlers, feeds and optional analysis services require separate configuration.
identity / capabilities / deployment
Upstream documentation describes collect and analyse unstructured web, chat and file data to investigate information leaks and extract threat intelligence. It documents local installation.
Read sourceorigin / country
The upstream README explicitly states that AIL was originally developed at CIRCL, the Computer Incident Response Center Luxembourg.
Read sourcelicense
The upstream license file specifies AGPL-3.0-or-later.
Read sourcemaintenance
Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee.
Read sourceorigin / country
CIRCL lists AIL among its open-source projects in Luxembourg.
Read sourcelicense
The README applies version 3 or any later version to this software.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Reference: 2020-EU-IA-0260
AIL identifies its instance synchronisation protocol, released in version 4.0 in December 2021, as JTAN-funded development. JTAN finished in June 2024.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs