Detection and monitoring Institution-led
NEMEA
Analyzes network flows through modular detectors for malicious traffic such as scans, denial-of-service activity and DNS tunneling.
By CESNET · Czechia
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- CESNET
- Recorded country
- Czechia
- Product model
- Open source
- Deployment
- Self-hosted
- Software license
- Dual: CESNET three-clause permissive terms or GPL-2.0-or-later
- Upstream status
- Maintenance unconfirmed
- Evidence class
- Institution-led
What the sources establish
Origin noteUpstream repository belongs to the Czech CESNET association and its license credits CESNET.
Reported capabilities
- Flow-based analysis
- Modular detectors
- Supervisor orchestration
Scope and limits
Meta-repository assembles framework, detectors, modules and supervisor; do not count submodules separately. License covers repository notice; components may vary. Maintenance is Unknown because a dated recent release or update was not established for the combined system.
Inspect the research evidence 4 source observations
maintenance
The reviewed meta-repository documents components and installation but did not establish a dated recent release or update for the combined system; component submodules may have separate activity. Maintenance is marked Unknown pending a component-level check.
Read sourceidentity / origin / capabilities / deployment
README describes NEMEA's flow-based detectors, supervisor, packages and source installation.
Read sourcelicense
COPYING grants three-clause permissive terms with alternative GPL version 2 or later option.
Read sourcecountry
CESNET describes itself as a Czech Republic academic association.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection