Threat intelligence Institution-led

NERD

Aggregates data about known malicious network entities, chiefly IP addresses, and presents the combined context to investigators.

By CESNET · Czechia

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
CESNET
Recorded country
Czechia
Product model
Open source
Deployment
Self-hosted / Public service
Software license
Dual: CESNET three-clause permissive terms or GPL-2.0-or-later
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

CESNET publishes NERD and names its Czech security research programme as development context.

Reported capabilities

  • Malicious IP context
  • Data aggregation
  • Web and daemon components

Scope and limits

CESNET's public web/API service exposes most data without registration, while full access is limited to trusted partners. Independent self-deployment is possible with assistance but upstream says installation scripts are incompletely tested and documented and some features depend on Warden access. Upstream root license uses alternative terms.

Inspect the research evidence 5 source observations
  1. identity / origin / capabilities / deployment

    CESNET operates a public web interface and API with basic access to most data; full access requires trusted-partner approval. The site recommends its hosted instance because self-installation scripts are incomplete and parts require Warden data, though operators can request deployment help.

    Read source
  2. identity / origin / capabilities / deployment

    README identifies source software and hosted service, malicious entity data aggregation, and Czech-funded development.

    Read source
  3. license

    Actual LICENSE offers CESNET three-clause permissive terms or GPL version 2 or later.

    Read source
  4. country

    CESNET describes its Czech Republic association and services.

    Read source
  5. maintenance

    Upstream GitHub API reports nonarchived repository with code pushed 2026-09-28; an activity signal, not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs