MISP Integration
Exports monitored domains from Website Monitoring and DNS Threats Monitored to MISP. Requires a configured MISP instance and API key; the UI tracks whether a domain has already been exported.
An independent tool index
for incident response teams
Threat intelligence CSIRT-led
Monitors vulnerability, ransomware and news sources against watch terms, collecting results and sending alerts through a self-hosted analyst interface.
By Thales Group CERT · France
Primary sources connect this project to an EU CSIRT as developer or lead.
Thales Group CERT calls itself the developer; prominent project contributors publicly identify with Thales CERT in France.
Coverage depends on configured external sources, credentials and feeds; this does not establish completeness or quality of alerts. French country label refers to the evidenced project team.
identity / capabilities / deployment
README describes Django/React threat-intelligence monitoring of CVE, ransomware and RSS sources with keyword alerts and Docker deployment.
Read sourceorigin
Official documentation explicitly says Watcher was developed by Thales Group CERT.
Read sourceorigin / country
Creator's self-reported profile identifies Félix Herrenschmidt, Thales CERT, France, and names Watcher.
Read sourcecountry
Another major contributor's profile identifies Thales CERT, France and Watcher development.
Read sourcelicense
Actual root LICENSE contains GNU Affero General Public License version 3 text.
Read sourcemaintenance
Upstream default-branch Atom feed records a commit on 2026-10-02; branch activity is not a support guarantee.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Exports monitored domains from Website Monitoring and DNS Threats Monitored to MISP. Requires a configured MISP instance and API key; the UI tracks whether a domain has already been exported.
Creates TheHive alerts from Watcher notifications and manual exports. Requires TheHive API credentials and the configured Watcher custom field to exist in TheHive.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs