Detection and monitoring Institution-led

Mentat

Processes structured security events in a modular SIEM, providing a web interface, searchable event records and periodic notifications to affected networks.

By CESNET · Czechia

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CESNET
Recorded country
Czechia
Product model
Open source
Deployment
Self-hosted
Software license
MIT
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

CESNET publishes the Mentat SIEM source and attributes the system copyright to the Czech association.

Reported capabilities

  • IDEA event processing
  • Web interface and API
  • Per-network event reporting

Scope and limits

The CESNET-hosted Mentat service and the self-installable software are one system; setup uses several components and can require advanced administration.

Inspect the research evidence 5 source observations
  1. identity / origin / country

    Upstream README names Mentat SIEM and credits CESNET as copyright holder.

    Read source
  2. license

    Actual repository LICENSE.txt grants MIT terms with CESNET copyright.

    Read source
  3. capabilities

    Upstream manual documents event reports by group/severity, web report detail and feedback, and classified event data.

    Read source
  4. deployment

    Upstream manual provides self-installation, quickstart, web interface and API sections.

    Read source
  5. maintenance

    Upstream latest commit records version 2.15.4 deployment on 25 June 2026.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection