Detection and monitoring Institution-led

ipfixprobe

Exports bidirectional network flow records with protocol metadata and telemetry for downstream monitoring and investigation systems.

By CESNET · Czechia

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CESNET
Recorded country
Czechia
Product model
Open source
Deployment
Self-hosted
Software license
BSD-3-Clause
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

CESNET's upstream repository and license identify the Czech association.

Reported capabilities

  • Bidirectional IPFIX export
  • Protocol parsers
  • High-speed capture options

Scope and limits

A telemetry producer, not an alerting engine by itself; optional hardware acceleration does not mean hardware is required.

Inspect the research evidence 4 source observations
  1. identity / origin / capabilities / deployment

    README describes modular bidirectional flow export, TLS/QUIC/HTTP/DNS parsers and package installation.

    Read source
  2. license

    Actual license text identifies BSD 3-Clause and CESNET copyright.

    Read source
  3. country

    CESNET identifies itself as an association operating across the Czech Republic.

    Read source
  4. maintenance

    Upstream release list has versions 5.4.0 and 5.5.0 dated 7 and 9 October 2026.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection