Detection and monitoring Institution-led

NEMEA

Analyzes network flows through modular detectors for malicious traffic such as scans, denial-of-service activity and DNS tunneling.

By CESNET · Czechia

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CESNET
Recorded country
Czechia
Product model
Open source
Deployment
Self-hosted
Software license
Dual: CESNET three-clause permissive terms or GPL-2.0-or-later
Upstream status
Maintenance unconfirmed
Evidence class
Institution-led

What the sources establish

Origin note

Upstream repository belongs to the Czech CESNET association and its license credits CESNET.

Reported capabilities

  • Flow-based analysis
  • Modular detectors
  • Supervisor orchestration

Scope and limits

Meta-repository assembles framework, detectors, modules and supervisor; do not count submodules separately. License covers repository notice; components may vary. Maintenance is Unknown because a dated recent release or update was not established for the combined system.

Inspect the research evidence 4 source observations
  1. maintenance

    The reviewed meta-repository documents components and installation but did not establish a dated recent release or update for the combined system; component submodules may have separate activity. Maintenance is marked Unknown pending a component-level check.

    Read source
  2. identity / origin / capabilities / deployment

    README describes NEMEA's flow-based detectors, supervisor, packages and source installation.

    Read source
  3. license

    COPYING grants three-clause permissive terms with alternative GPL version 2 or later option.

    Read source
  4. country

    CESNET describes itself as a Czech Republic academic association.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection