Detection and monitoring Institution-led
Mentat
Processes structured security events in a modular SIEM, providing a web interface, searchable event records and periodic notifications to affected networks.
By CESNET · Czechia
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- CESNET
- Recorded country
- Czechia
- Product model
- Open source
- Deployment
- Self-hosted
- Software license
- MIT
- Upstream status
- Active
- Evidence class
- Institution-led
What the sources establish
Origin noteCESNET publishes the Mentat SIEM source and attributes the system copyright to the Czech association.
Reported capabilities
- IDEA event processing
- Web interface and API
- Per-network event reporting
Scope and limits
The CESNET-hosted Mentat service and the self-installable software are one system; setup uses several components and can require advanced administration.
Inspect the research evidence 5 source observations
identity / origin / country
Upstream README names Mentat SIEM and credits CESNET as copyright holder.
Read sourcelicense
Actual repository LICENSE.txt grants MIT terms with CESNET copyright.
Read sourcecapabilities
Upstream manual documents event reports by group/severity, web report detail and feedback, and classified event data.
Read sourcedeployment
Upstream manual provides self-installation, quickstart, web interface and API sections.
Read sourcemaintenance
Upstream latest commit records version 2.15.4 deployment on 25 June 2026.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection