Result description
- EME is composed of: i) the EME Platform, that enhances threat intelligence and incident sharing with secure communication and collaboration and presents a customized SIEM for the two primary users, CERTs/CSIRTs and Critical Infrastructure Operators. The platform was developed by Netcompany-Intrasoft and is offered as open source. ii) the APIs for Advanced Threat Intelligence Orchestrator, for integrating threat detection and CTI components to automate detection, reporting and response workflows. Customization of workflows and APIs, using Shuffle, is offered by ICCS. iii) the Collaborative Threat Intelligence Sharing and Storage, which automatically collects and enhances threat intelligence, providing a secure GUI for data presentation, editing, and configuration, used optionally in EME, on top of MISP. It is owned by CERTH and is proprietary.
Addressing target audiences and expressing needs
- Grants and Subsidies
- Other blended financing
- Collaboration
Promote the open source project of EME to the CERT/CSIRT and OESs communities and enhance its adoption. Look for new collaborations for further research and development on the platform/open source software, and offer IT consulting services to potential clients.
- Public or private funding institutions
- International Organisations (ex. OECD, FAO, UN, etc.)
- Research and Technology Organisations
R&D, Technology and Innovation aspects
Expanding testing environments to include real-world critical infrastructure settings and more CERT/CSIRT authorities to validate the platform’s efficacy in diverse IoT and AI-driven systems. Refining automation and response policy execution while continuing to develop additional API integrations to ensure compatibility with a wider array of existing cybersecurity solutions. Advancing forensics capabilities on logs of reported incidents, threats, vulnerabilities and attacks. Advancing the information governance aspects. Engaging with relevant stakeholders to promote EME.
EME incorporates a scalable business model grounded in an open-source framework, designed to address the evolving demands of the cybersecurity landscape while maintaining efficiency, adaptability, and profitability. EME leverages open standards (e.g., STIX, CACAO) and modular architecture to enable interoperability across diverse cybersecurity infrastructures and platforms. The open-source foundation of EME ensures a low-cost entry point for users, fostering rapid adoption. The community-driven model encourages continuous improvements through contributions, while offering a tiered pricing structure for premium support and enterprise features.
- Europe
Result submitted to Horizon Results Platform by EREVNITIKO PANEPISTIMIAKO INSTITOUTO SYSTIMATON EPIKOINONION KAI YPOLOGISTON