Detection and monitoring Institution-led
MADCAT
Runs a low-interaction network sensor that records connection attempts across services to help analysts observe mass scanning and attack patterns.
By German Federal Office for Information Security (BSI) · Germany
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- German Federal Office for Information Security (BSI)
- Recorded country
- Germany
- Product model
- Open source
- Deployment
- Self-hosted
- Software license
- GPL-3.0
- Upstream status
- Active
- Evidence class
- Institution-led
What the sources establish
Origin noteThe upstream MADCAT v2 project is published by Germany's Federal Office for Information Security, whose project organization lists Bonn, Germany.
Reported capabilities
- Low-interaction network sensor
- Connection attempt logging
- Attack-pattern observation
Scope and limits
The README describes higher-interaction response, DPI routing proxy and Docker appliance as planned or in progress. Bundled libraries retain their respective licenses; no production fitness claim is made.
Inspect the research evidence 4 source observations
identity / capabilities / deployment
README describes a self-built low-interaction, honeypot-like connection sensor, with Linux build instructions, that records contact attempts.
Read sourceorigin / country
Project is in the official German BSI GitHub organization, which identifies the federal security office and Bonn location.
Read sourcelicense
Actual LICENSE.md contains GNU GPL version 3 text; the README identifies separately licensed included libraries.
Read sourcemaintenance
Upstream default-branch Atom feed records a commit on 2026-08-07; branch activity is not a support guarantee.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection