Threat intelligence EU-developed

DCSO Threat Intelligence Engine

Aggregates selected intelligence feeds, normalizes and contextualizes indicators, then exposes tailored IoC collections through an authenticated API.

By DCSO Deutsche Cyber-Sicherheitsorganisation GmbH · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
DCSO Deutsche Cyber-Sicherheitsorganisation GmbH
Recorded country
Germany
Product model
Commercial
Deployment
SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

DCSO describes TIE as its own platform and operates the threat-intelligence service from its Berlin-based GmbH; its team performs research and feed integration.

Reported capabilities

  • Indicator aggregation and contextualization
  • Tailored API feeds and STIX/TAXII access
  • DCSO analyst and sensor enrichment

Scope and limits

TIE is a provider-operated, contracted API/feed service, not downloadable open-source software or a free public endpoint. DCSO may combine its own, public, commercial and customer-licensed intelligence, so access to underlying data has source-specific conditions. Public TIE documentation does not publish a complete customer license or promise customer-hosted deployment.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    DCSO says its TIE aggregates, normalizes and contextualizes IOCs from chosen sources and makes tailored feeds available through its API as part of its threat-intelligence service.

    Read source
  2. deployment

    DCSO documents a remote TAXII/STIX 2.1 API with collections and authenticated consumer access; it does not provide customer-hosted TIE installation.

    Read source
  3. origin / license

    DCSO calls TIE its own platform for integrating DCSO, public and commercial data into customer environments; the document markets a service but does not contain complete software or feed-license terms.

    Read source
  4. country

    DCSO names its German GmbH and Berlin office in the site footer; paired with its own-platform statement this supports a German product lead, not all contributor locations.

    Read source
  5. maintenance / license

    Dated 18 December 2025 vendor Q&A explains live TIE source harmonization, standards integration and external feed licensing; it shows continuing operation within the review window, not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs