Detection and monitoring CSIRT-led

D4

Build a distributed sensor network that collects security telemetry and dispatches it to configured decoders and analysers.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The D4 project identifies CIRCL, Luxembourg House of Cybersecurity, Luxembourg, as its project contact and organisation.

Reported capabilities

  • Registers and manages sensors through a central server.
  • Carries telemetry streams to downstream decoders and analysis queues.

Scope and limits

This entry groups the core server and sensor transport. Detection depends on the sensors and analysers deployed.

Inspect the research evidence 4 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes build a distributed sensor network that collects security telemetry and dispatches it to configured decoders and analysers. It documents local installation.

    Read source
  2. origin / country

    The D4 project identifies CIRCL, Luxembourg House of Cybersecurity, Luxembourg, as its project contact and organisation.

    Read source
  3. license

    The upstream license file specifies AGPL-3.0.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-07-14. This is an activity signal, not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection