Threat intelligence CSIRT-led

BGP Ranking

Aggregate malicious-activity observations by autonomous system number and inspect comparative rankings and historical changes.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted / Public service
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The project history describes CIRCL support from its 2010 origin and a rewrite within the CIRCL-led D4 project.

Reported capabilities

  • Ranks ASNs using configured malicious-activity datasets.
  • Exposes historical ASN information through an API.

Scope and limits

Rankings describe observations in the contributing datasets; they are not a complete assessment of an operator’s security.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes aggregate malicious-activity observations by autonomous system number and inspect comparative rankings and historical changes. It documents local installation.

    Read source
  2. origin / country

    The project history describes CIRCL support from its 2010 origin and a rewrite within the CIRCL-led D4 project.

    Read source
  3. license

    The upstream license file specifies AGPL-3.0.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-01-08. This is an activity signal, not a support guarantee.

    Read source
  5. origin / country / deployment

    CIRCL provides the public BGP Ranking service and identifies its Luxembourg role.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs