Feed automation CSIRT-led

IntelMQ

Collects and processes security feeds through message-queued bots to automate incident handling, notifications and exchange with other systems.

By CERT.at / IntelMQ community · Austria

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Feed automation
Developer or maintainer
CERT.at / IntelMQ community
Recorded country
Austria
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

EU CSIRTs Network Tooling WG names CERT.at as lead; upstream credits a wider European CERT community.

Reported capabilities

  • Feed collection and processing
  • Automated incident notifications
  • Message-queue architecture

Scope and limits

Multi-CSIRT project; Austria identifies the directory-listed lead, not every contributor or all engineering.

Inspect the research evidence 4 source observations
  1. identity / capabilities / deployment

    README describes message-queued security-feed processing and automated incident workflows for CERTs and CSIRTs.

    Read source
  2. license

    Actual license text is GNU Affero General Public License version 3.

    Read source
  3. origin / country

    The CSIRTs Network Tooling WG lists IntelMQ with CERT.at as lead.

    Read source
  4. maintenance

    Upstream NEWS records version 3.5.0 released 1 November 2025 and documents a 3.5.1 patch under development.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

MISP Integration

MISP bots collect events, look up matching source IPs, create MISP feeds and create events through the MISP API.

Elastic Integration

Documents event delivery to Elasticsearch through a Redis output bot and Logstash. The walkthrough targets ELK 6.8.0, so current-version setup needs adaptation.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Plan a security feed pipeline with parsing, validation, deduplication, delivery and failure checks. Source-linked guidance for IntelMQ and n6 evaluation.

Automate security feeds without losing context