YARA Capability
The local Yara analyzer scans files using documented community rule collections and operator-supplied signatures.
An independent tool index
for incident response teams
Threat intelligence EU-developed
Enriches files and indicators such as IP addresses, domains and hashes through configurable analyzers, with a shared REST API and investigative interface.
By Certego / IntelOwl project · Italy
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Certego says it created IntelOwl in 2020; upstream says project management moved fully to Certego with version 6.8.0. Certego is based in Modena, Italy.
Certego is the Italian project steward, with international community contributors; this does not establish Italian origin for every analyzer. Self-hosting uses Docker Compose and is supported/tested chiefly on Ubuntu; bundled third-party analyzers and external services have separate terms or credentials. The hosted Honeynet demo requires an invitation and is not listed as a public service. The v6.8.0 release warns that its Docker build lacks ARM support.
identity / capabilities / origin
Upstream README identifies IntelOwl as a threat-intelligence platform, describes file/observable enrichment, REST API and web GUI, and says management is fully in Certego's hands since version 6.8.0.
Read sourceorigin
Certego's January 2025 retrospective says its team launched IntelOwl at the start of 2020 and credits both Certego and international open-source contributors.
Read sourcecountry
Certego's company page describes it as an Italian provider headquartered in Modena; this establishes the country of the project steward, not every contributor.
Read sourcelicense
The upstream root LICENSE is the complete GNU Affero General Public License version 3 text.
Read sourcedeployment
Official instructions install the server with Docker Compose, initialize environment files and start a local web application; they say Ubuntu is the tested platform.
Read sourcemaintenance
Upstream lists v6.8.0 as latest, released 31 August during GSoC 2026 work, with a release note that ARM Docker builds are unavailable for this version; release activity is not a support guarantee.
Read sourcelicense / deployment
Upstream legal notice requires users to review separate terms for third-party packages, tools and media downloaded or installed with IntelOwl.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
The local Yara analyzer scans files using documented community rule collections and operator-supplied signatures.
The Suricata analyzer inspects submitted PCAP files with the Suricata engine and IDS signatures.
MISP analyzers look up observables and hashes; a configured connector creates a MISP event linking an IntelOwl analysis.
An OpenCTI analyzer looks up observables; a configured connector creates an observable and linked report for an IntelOwl analysis.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs