Feed automation CSIRT-led

n6

Collects, manages and distributes security incident and threat feeds to authorized users through a REST API and web interface.

By CERT Polska · Poland

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Feed automation
Developer or maintainer
CERT Polska
Recorded country
Poland
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

Upstream README explicitly attributes development to CERT Polska.

Reported capabilities

  • Feed handling
  • REST API and web portal
  • Authorized distribution

Scope and limits

The CERT.PL web portal is a deployment, not evidence of a generally offered SaaS product.

Inspect the research evidence 4 source observations
  1. identity / origin / capabilities / deployment

    README describes collection, management and distribution of security information; identifies CERT Polska as developer and includes Docker deployment files.

    Read source
  2. license

    Actual license text is GNU Affero General Public License version 3.

    Read source
  3. country

    Verified organization identifies Warsaw and the Polish CERT.PL domain.

    Read source
  4. maintenance

    Upstream GitHub API reports nonarchived repository with code pushed 2026-06-04; an activity signal, not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

MISP Integration

Includes a configurable MISP collector that fetches events and attached samples through PyMISP and publishes them to n6 queues. This is ingestion into n6, not a bidirectional connector.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Plan a security feed pipeline with parsing, validation, deduplication, delivery and failure checks. Source-linked guidance for IntelMQ and n6 evaluation.

Automate security feeds without losing context