Detection and monitoring Institution-led

MADCAT

Runs a low-interaction network sensor that records connection attempts across services to help analysts observe mass scanning and attack patterns.

By German Federal Office for Information Security (BSI) · Germany

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
German Federal Office for Information Security (BSI)
Recorded country
Germany
Product model
Open source
Deployment
Self-hosted
Software license
GPL-3.0
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

The upstream MADCAT v2 project is published by Germany's Federal Office for Information Security, whose project organization lists Bonn, Germany.

Reported capabilities

  • Low-interaction network sensor
  • Connection attempt logging
  • Attack-pattern observation

Scope and limits

The README describes higher-interaction response, DPI routing proxy and Docker appliance as planned or in progress. Bundled libraries retain their respective licenses; no production fitness claim is made.

Inspect the research evidence 4 source observations
  1. identity / capabilities / deployment

    README describes a self-built low-interaction, honeypot-like connection sensor, with Linux build instructions, that records contact attempts.

    Read source
  2. origin / country

    Project is in the official German BSI GitHub organization, which identifies the federal security office and Bonn location.

    Read source
  3. license

    Actual LICENSE.md contains GNU GPL version 3 text; the README identifies separately licensed included libraries.

    Read source
  4. maintenance

    Upstream default-branch Atom feed records a commit on 2026-08-07; branch activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection