- Keeps lists of known malicious entities
- Collects additional details from external sources
- Transforms known information into reputation scores
- Forecasts next-day threat levels using machine learning
Basic features
The NERD (Network Entity Reputation Database) system collects and stores data on cyber threat sources from various sources, primarily Warden and MISP. It maintains a constantly updated database of known malicious network entities, currently focusing on IP addresses.
The system provides detailed information on each entity, including when and where it was reported as malicious, ancillary data such as hostname or geolocation, and a numerical representation of the IP's reputation, indicating its threat level. Basic information on associated BGP prefixes, ASNs, registered IP blocks, and organizations (from WHOIS databases) is also stored. Most of the data is publicly accessible via a web interface.
The service is free of charge.