Response coordination CSIRT-led

Flowintel

Organise investigation cases, tasks and analyst notes, with templates, assignments and integrations for threat intelligence workflows.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Response coordination
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

Flowintel’s README credits CIRCL in Luxembourg and David Cruciani, and identifies CIRCL and the EU FETTA project as funders.

Reported capabilities

  • Case and task templates support repeatable response procedures.
  • Integrates MISP taxonomies and galaxy data, with export modules.

Scope and limits

Deployment and integration setup remain the operator’s responsibility.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes organise investigation cases, tasks and analyst notes, with templates, assignments and integrations for threat intelligence workflows. It documents local installation.

    Read source
  2. origin / country

    Flowintel’s README credits CIRCL in Luxembourg and David Cruciani, and identifies CIRCL and the EU FETTA project as funders.

    Read source
  3. license

    The upstream license file specifies AGPL-3.0.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-09-24. This is an activity signal, not a support guarantee.

    Read source
  5. origin / country

    The tooling working group identifies CIRCL as Flowintel’s CSIRT lead.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

MISP Integration

Provides export modules for MISP and enrichment using misp-modules, alongside MISP taxonomies and galaxies for case context.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Move from alert triage to assigned tasks, evidence, shift handoff and closure. A practical case management guide with TheHive and DFIR-IRIS references.

An incident response case management workflow