Threat intelligence CSIRT-led

Watcher

Monitors vulnerability, ransomware and news sources against watch terms, collecting results and sending alerts through a self-hosted analyst interface.

By Thales Group CERT · France

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
Thales Group CERT
Recorded country
France
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

Thales Group CERT calls itself the developer; prominent project contributors publicly identify with Thales CERT in France.

Reported capabilities

  • CVE and ransomware source monitoring
  • Keyword watch rules and alerts
  • Docker-hosted analyst interface

Scope and limits

Coverage depends on configured external sources, credentials and feeds; this does not establish completeness or quality of alerts. French country label refers to the evidenced project team.

Inspect the research evidence 6 source observations
  1. identity / capabilities / deployment

    README describes Django/React threat-intelligence monitoring of CVE, ransomware and RSS sources with keyword alerts and Docker deployment.

    Read source
  2. origin

    Official documentation explicitly says Watcher was developed by Thales Group CERT.

    Read source
  3. origin / country

    Creator's self-reported profile identifies Félix Herrenschmidt, Thales CERT, France, and names Watcher.

    Read source
  4. country

    Another major contributor's profile identifies Thales CERT, France and Watcher development.

    Read source
  5. license

    Actual root LICENSE contains GNU Affero General Public License version 3 text.

    Read source
  6. maintenance

    Upstream default-branch Atom feed records a commit on 2026-10-02; branch activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

MISP Integration

Exports monitored domains from Website Monitoring and DNS Threats Monitored to MISP. Requires a configured MISP instance and API key; the UI tracks whether a domain has already been exported.

TheHive Integration

Creates TheHive alerts from Watcher notifications and manual exports. Requires TheHive API credentials and the configured Watcher custom field to exist in TheHive.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs