IntelMQ's design was influenced by AbuseHelper,
however it was re-written from scratch and aims at:
- Reduce the complexity of system
administration
- Reduce the complexity of
writing new bots for new data feeds
- Reduce the probability of
events lost in all process with persistence functionality (even system
crash)
- Use and improve the existing
Data Harmonization Ontology
- Use JSON format for all
messages
- Integration of the existing
tools (AbuseHelper, CIF)
- Provide easy way to store data
into Log Collectors like ElasticSearch, Splunk, databases (such as
PostgreSQL)
- Provide easy way to create your
own black-lists
- Provide easy communication with
other systems via HTTP RESTFUL API
It follows the following basic meta-guidelines:
- Don't break simplicity - KISS
- Keep it open source - forever
- Strive for perfection while
keeping a deadline
- Reduce complexity/avoid feature
bloat
- Embrace unit testing
- Code readability: test with
unexperienced programmers
- Communicate clearly
Table of Contents
- How to Install
- Developers Guide
- IntelMQ Manager
- Incident Handling Automation Project
- Data Harmonization
- How to Participate
- Licence
How to Install
See INSTALL.
For existing installations, see UPGRADING.
Developers Guide
See Developers Guide.
User Guide
See User Guide.
For support use the intelmq-users mailing list: https://lists.cert.at/cgi-bin/mailman/listinfo/intelmq-users
IntelMQ Manager
Check out this graphical tool and
easily manage an IntelMQ system.
Incident Handling
Automation Project
- URL: http://www.enisa.europa.eu/activities/cert/support/incident-handling-automation
- Mailing-list: ihap@lists.trusted-introducer.org
Data Harmonization
IntelMQ use the Data Harmonization. Check the
following document.
How to participate
- Subscribe to the Intelmq-dev
Mailing list: https://lists.cert.at/cgi-bin/mailman/listinfo/intelmq-dev (for
developers)
- Watch out for our regular
developers conf call
- IRC: server: irc.freenode.net,
channel: #intelmq
- Via github issues
- Via Pull requests (please do
read help.github.com first)
Licence
This software is licensed under GNU Affero General
Public License version 3