certtools/intelmq
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol. observed · 2026-08-28
Health v2 · maintenance only
63/100
- Activity 79
- Release rhythm 22
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 211.5
- age_days: 4453
- days_rel: 305
- days_push: 127
- n_releases_24m: 3
Adoption not part of the score
1133 stars · 318 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
IntelMQ is an open-source solution for IT security teams (CERTs, CSIRTs, SOCs) for collecting and processing security feeds using a message queuing protocol. It provides a modular bot-based pipeline architecture for automated incident handling, threat intelligence processing, and situational awareness.
Use cases
- collect and process security feeds from multiple sources
- automate incident handling workflows for CERTs and CSIRTs
- parse and normalize threat intelligence data into a common format
- aggregate indicators of compromise (IOCs) from various feeds
- automate abuse notifications to network owners
- build situational awareness dashboards from security events
- integrate threat intelligence with MISP, CIF, and other tools
- store processed security events in databases like PostgreSQL or Elasticsearch
When to choose
- you are a CERT/CSIRT/SOC needing to automate incident handling
- you need to collect and normalize threat intelligence from many heterogeneous feeds
- you want a stream-oriented, stateless pipeline for processing large volumes of security events
- you need to integrate with MISP, n6, CIF, or other threat intelligence platforms
- you want a community-driven, open-source tool with a data harmonization ontology
When to avoid
- you need a manually curated indicator database with event correlation (use MISP instead)
- you need a simple single-feed parser without pipeline orchestration
- you require a fully managed SaaS solution rather than self-hosted infrastructure
- your team cannot maintain a Python-based botnet of processing bots
Facets
framework · maturity active
message-queue etl streaming workflow-automation security webhook api-framework security python self-hosted threat-intelligence ioc csirt cert soc incident-handling security-feeds abuse-handling misp-integration data-harmonization automation incident-response linux docker
10 sources
- readme: https://github.com/certtools/intelmq · fetched 2026-08-28 · b4d68dc855d0
- homepage: https://docs.intelmq.org/latest/ · fetched 2026-08-29 · a71b145b51de
- site_page: https://docs.intelmq.org/latest/admin/installation/linux-packages · fetched 2026-08-29 · 92f43dd73bf9
- site_page: https://docs.intelmq.org/latest/admin/installation/pypi · fetched 2026-08-29 · d945b3bb0c1d
- site_page: https://docs.intelmq.org/latest/admin/installation/dockerhub · fetched 2026-08-29 · 887fd73070c4
- site_page: https://docs.intelmq.org/latest/admin/integrations/misp · fetched 2026-08-29 · 7873a80756ca
- site_page: https://docs.intelmq.org/latest/admin/integrations/n6 · fetched 2026-08-29 · 8dfeaeb82380
- site_page: https://docs.intelmq.org/latest/admin/integrations/cifv3 · fetched 2026-08-29 · 3d7795be730c
- site_page: https://docs.intelmq.org/latest/admin/beta-features · fetched 2026-08-29 · 2c4999be0384
- site_page: https://docs.intelmq.org/latest/admin/faq · fetched 2026-08-29 · b81a3f79c420
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| certtools/intelmq | main | 63 |
For agents
markdown · JSON · MCP: product_card(name="certtools/intelmq")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem