Threat intelligence CSIRT-led

Taranis NG

Collects open-source intelligence, supports analyst reporting and controlled team collaboration, and publishes outputs from a self-hosted Docker deployment.

By SK-CERT · Slovakia

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
SK-CERT
Recorded country
Slovakia
Product model
Open source
Deployment
Self-hosted
Software license
EUPL-1.2
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

README explicitly credits SK-CERT and the wider CSIRT community.

Reported capabilities

  • OSINT collection
  • Analyst reports
  • Team collaboration

Scope and limits

Distinct from discontinued Dutch Taranis3; follow current Docker guide for operational warnings.

Inspect the research evidence 3 source observations
  1. identity / origin / country / capabilities / deployment

    README credits SK-CERT, describes OSINT collection, reports, collaboration and Docker Compose deployment.

    Read source
  2. license

    Actual LICENSE.md is European Union Public Licence version 1.2.

    Read source
  3. maintenance

    Upstream changelog documents release 26.02.1 dated 10 February 2026 and further documented work.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

European Regional Development Fund (ERDF) · Operational Programme Integrated Infrastructure (OPII)

The upstream project credits ERDF support through OPII for Taranis NG. It does not identify the specific action or funding dates in this acknowledgement.

Connecting Europe Facility (CEF) · MeliCERTes Facility

Reference: SMART2018/1024

The upstream project credits CEF support through the MeliCERTes Facility. SMART2018/1024 is a contract reference; the acknowledgement does not establish ongoing funding.

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs