# certtools/intelmq

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Repository: https://github.com/certtools/intelmq
Canonical: https://ross.abutalabs.com/products/intelmq
Homepage: https://docs.intelmq.org/latest/
Language: Python
License: AGPL-3.0
License Family: copyleft
Topics: cybersecurity, threat, ioc, malware, phishing, cert, csirt, intelligence, incident-response, alerts, feeds, incident, handling, automation, ihap, python
Last push: 2026-04-28T19:55:15+00:00

## Health v2 (maintenance only)
Score: 63/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 79, release rhythm 22, longevity 100
- inputs: {"age_days": 4453, "days_push": 127, "days_rel": 305, "gap_med": 211.5, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1133, forks 318 (observed 2026-08-28T04:03:43.049590+00:00)

## What it is
IntelMQ is an open-source solution for IT security teams (CERTs, CSIRTs, SOCs) for collecting and processing security feeds using a message queuing protocol. It provides a modular bot-based pipeline architecture for automated incident handling, threat intelligence processing, and situational awareness.

## Use cases
- collect and process security feeds from multiple sources
- automate incident handling workflows for CERTs and CSIRTs
- parse and normalize threat intelligence data into a common format
- aggregate indicators of compromise (IOCs) from various feeds
- automate abuse notifications to network owners
- build situational awareness dashboards from security events
- integrate threat intelligence with MISP, CIF, and other tools
- store processed security events in databases like PostgreSQL or Elasticsearch

## When to choose
- you are a CERT/CSIRT/SOC needing to automate incident handling
- you need to collect and normalize threat intelligence from many heterogeneous feeds
- you want a stream-oriented, stateless pipeline for processing large volumes of security events
- you need to integrate with MISP, n6, CIF, or other threat intelligence platforms
- you want a community-driven, open-source tool with a data harmonization ontology

## When to avoid
- you need a manually curated indicator database with event correlation (use MISP instead)
- you need a simple single-feed parser without pipeline orchestration
- you require a fully managed SaaS solution rather than self-hosted infrastructure
- your team cannot maintain a Python-based botnet of processing bots

## Facets
- artifact type: framework
- maturity: active
- function: message-queue, etl, streaming, workflow-automation, security, webhook, api-framework
- domain: security
- platform: python, self-hosted
- tags: threat-intelligence, ioc, csirt, cert, soc, incident-handling, security-feeds, abuse-handling, misp-integration, data-harmonization, automation, incident-response, linux, docker

## Member repositories
- certtools/intelmq (main) score 63

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:43.049590+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:37:25.010925+00:00, confidence not recorded.
  - readme: https://github.com/certtools/intelmq (fetched 2026-08-28T04:03:43.049590+00:00, sha b4d68dc855d0)
  - homepage: https://docs.intelmq.org/latest/ (fetched 2026-08-29T12:42:21.722936+00:00, sha a71b145b51de)
  - site_page: https://docs.intelmq.org/latest/admin/installation/linux-packages (fetched 2026-08-29T12:42:21.726075+00:00, sha 92f43dd73bf9)
  - site_page: https://docs.intelmq.org/latest/admin/installation/pypi (fetched 2026-08-29T12:42:21.727806+00:00, sha d945b3bb0c1d)
  - site_page: https://docs.intelmq.org/latest/admin/installation/dockerhub (fetched 2026-08-29T12:42:21.729475+00:00, sha 887fd73070c4)
  - site_page: https://docs.intelmq.org/latest/admin/integrations/misp (fetched 2026-08-29T12:42:21.730961+00:00, sha 7873a80756ca)
  - site_page: https://docs.intelmq.org/latest/admin/integrations/n6 (fetched 2026-08-29T12:42:21.732695+00:00, sha 8dfeaeb82380)
  - site_page: https://docs.intelmq.org/latest/admin/integrations/cifv3 (fetched 2026-08-29T12:42:21.734642+00:00, sha 3d7795be730c)
  - site_page: https://docs.intelmq.org/latest/admin/beta-features (fetched 2026-08-29T12:42:21.736273+00:00, sha 2c4999be0384)
  - site_page: https://docs.intelmq.org/latest/admin/faq (fetched 2026-08-29T12:42:21.738169+00:00, sha b81a3f79c420)
- Data as of 2026-08-30T08:39:29.467469+00:00.
