Threat intelligence Institution-led
NERD
Aggregates data about known malicious network entities, chiefly IP addresses, and presents the combined context to investigators.
By CESNET · Czechia
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Threat intelligence
- Developer or maintainer
- CESNET
- Recorded country
- Czechia
- Product model
- Open source
- Deployment
- Self-hosted / Public service
- Software license
- Dual: CESNET three-clause permissive terms or GPL-2.0-or-later
- Upstream status
- Active
- Evidence class
- Institution-led
What the sources establish
Origin noteCESNET publishes NERD and names its Czech security research programme as development context.
Reported capabilities
- Malicious IP context
- Data aggregation
- Web and daemon components
Scope and limits
CESNET's public web/API service exposes most data without registration, while full access is limited to trusted partners. Independent self-deployment is possible with assistance but upstream says installation scripts are incompletely tested and documented and some features depend on Warden access. Upstream root license uses alternative terms.
Inspect the research evidence 5 source observations
identity / origin / capabilities / deployment
CESNET operates a public web interface and API with basic access to most data; full access requires trusted-partner approval. The site recommends its hosted instance because self-installation scripts are incomplete and parts require Warden data, though operators can request deployment help.
Read sourceidentity / origin / capabilities / deployment
README identifies source software and hosted service, malicious entity data aggregation, and Czech-funded development.
Read sourcelicense
Actual LICENSE offers CESNET three-clause permissive terms or GPL version 2 or later.
Read sourcecountry
CESNET describes its Czech Republic association and services.
Read sourcemaintenance
Upstream GitHub API reports nonarchived repository with code pushed 2026-09-28; an activity signal, not a support guarantee.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs