Threat intelligence for the organizations the enterprise market leaves behind.
Commercial threat-intel platforms cost more per year than many small businesses, nonprofits, and public-sector offices spend on their entire IT budget. This is an open, low-cost pipeline that pulls the same public intelligence those platforms charge for — starting with CISA's Known Exploited Vulnerabilities catalog — and turns it into a plain-language digest a non-technical decision maker can actually act on.
- Data source
- CISA KEV catalog
- confirmed exploited only
- Output
- Plain-language digest
- not a raw feed dump
- License
- Open & public
- from day one
The soft underbelly of American cyber resilience isn't where most people think.
When people picture a major cyberattack, they picture a Fortune 500 company, a hospital system, a pipeline. What rarely makes the headline is the twelve-person accounting firm hit with ransomware, the local food bank whose donor database was quietly exfiltrated, or the small manufacturer that had no idea it was the weak link in a much larger supply chain until it was too late.
The next major incident affecting a hospital, a utility, or a school district is increasingly likely to start somewhere much smaller: a vendor, a nonprofit partner, a small business with a login into a bigger system. Attackers have figured out that the path of least resistance into a well-defended target often runs straight through a poorly-defended one standing next to it.
The tools that exist to close this gap fall into two categories: enterprise platforms priced for a six- or seven-figure security budget, and a patchwork of free, individually excellent OSINT tools that require enough security background to know which to use and how to stitch their output into something actionable. Neither works for the organization with one overworked IT generalist and no security team at all.
What's missing is something in between — tooling that pulls from the same open, low-cost intelligence sources larger platforms charge for, and turns raw signal into something a non-technical decision maker can act on: here is what changed, here is why it matters to you, here is what to do about it.
A five-stage pipeline that turns a public vulnerability feed into an email a non-technical person can act on.
</>View the source & design docs ↗The engineering here is intentionally modest — ingestion and email delivery are the easy parts. The real work is the filtering and triage in the middle, the steps that decide what a busy organization with no security team ever needs to see.
- Ingestion01
Pull the feed
Fetch new and updated entries from CISA's Known Exploited Vulnerabilities catalog since the last run. KEV only lists vulnerabilities with confirmed, active exploitation — so everything entering the pipeline is already a strong signal.
- Org profile02
Know the organization
A small config lists what the organization actually runs — WordPress, QuickBooks, a specific VPN appliance, Microsoft 365. This is the key differentiator: without it, the tool would just be forwarding a raw feed nobody can read.
- Filtering03
Cut the noise
The filter matches each entry against the org's declared stack using exact and substring logic, narrowing a feed of hundreds of entries down to the handful that are actually relevant to that specific organization.
- Triage04
Rank what's left
Rule-based scoring — deliberately explainable, not machine learning — sorts matches into Critical, Watch, and Informational based on match confidence (exact vs substring) and how recently the vulnerability was added.
- Digest05
Say it in plain language
Each entry becomes three short lines: what happened, why it matters to you specifically, and what to do about it. Critical items get a direct action; everything else stays low-key. Delivered as an email, not a dashboard.
Exact match to the org's declared software and recently added to KEV. Confirmed exploited and directly relevant right now — gets a short, direct action recommendation.
Matches the profile but is either a partial match or was added a while ago. Worth confirming the specific version is patched, but lower urgency.
Passed the initial filter but doesn't meet the bar above. Included for awareness so the digest never goes fully silent.
See the filtering and triage logic run — live, in your browser.
Pick a sample organization, edit what it runs, and watch a fixed set of KEV-style entries get filtered and triaged into a plain-language digest. Everything below runs client-side on static sample data — no live CISA call, no backend, no credentials. It demonstrates the logic, not the production infrastructure.
Step 1 — Choose an org profile
Step 2 — Edit the software stack
This is the org profile the real tool matches the feed against. Add or remove products and the results update instantly.
Try adding
Result — triage summary
10 entries in → 3 relevant to Community Food Bank → 2 need attention now.
Filtered & triaged entries
3 of 10- CRITICALCVE-2023-34362exact match · added 4d ago
Progress MOVEit Transfer — SQL Injection Vulnerability
Exact match to your "moveit transfer" and added to KEV 4 days ago — confirmed exploited and directly relevant right now.
- CRITICALCVE-2022-30190exact match · added 11d ago
Microsoft Windows Support Diagnostic Tool (MSDT) — Remote Code Execution Vulnerability
Exact match to your "microsoft 365" and added to KEV 11 days ago — confirmed exploited and directly relevant right now.
- WATCHCVE-2023-27997exact match · added 26d ago
Fortinet FortiOS — Heap-Based Buffer Overflow Vulnerability
Exact match to your "fortinet fortios", but it was added 26 days ago, so it's likely already on your radar. Confirm it's patched.
Sample digest output
what the org would receive[CRITICAL] MOVEit Transfer: SQL Injection Vulnerability
What happened: A SQL injection flaw in MOVEit Transfer lets an unauthenticated attacker access and alter the file transfer database.
Why it matters: You listed moveit transfer in your profile, and this is being actively exploited according to CISA.
What to do: Apply the vendor patch immediately. If you can't patch today, disable HTTP/HTTPS traffic to the MOVEit server until you can.
[CRITICAL] Windows Support Diagnostic Tool (MSDT): Remote Code Execution Vulnerability
What happened: The 'Follina' flaw lets a malicious document run code through the Windows diagnostic tool.
Why it matters: You listed microsoft 365 in your profile, and this is being actively exploited according to CISA.
What to do: Ensure Windows is fully updated. This affects Windows / Microsoft 365 endpoints broadly.
[WATCH] FortiOS: Heap-Based Buffer Overflow Vulnerability
What happened: A heap overflow in FortiOS SSL-VPN can let a remote attacker run code via crafted requests.
Why it matters: You listed fortinet fortios in your profile, and this is being actively exploited according to CISA.
What to do: Upgrade FortiOS to a fixed version. Disable SSL-VPN if you can't upgrade right away.
Generated from CISA KEV · rule-based triage · reply to update your software profile
This is a static illustration of the pipeline's logic. The production tool runs the same steps as a scheduled backend job against the live CISA KEV catalog and delivers real email. See the implementation ↗
The reasoning behind the build, written out in full.
All articles →Full articles live here on the site, not scattered across other platforms. This is where the thinking behind the project gets worked out in the open.
What This Looks Like for a Real Organization: A Walkthrough
A synthetic, clearly labeled walkthrough of the full pipeline for a small school district IT office — from org profile to the actual digest email that lands in an inbox.
Starting Graduate School With a Problem Already in Hand
Most people start a graduate program looking for direction. I'm starting mine already pointed somewhere — toward making threat intelligence accessible to organizations that can't afford the enterprise version of it.
Building Threat Intel Tooling for Organizations Without a SOC: Design Decisions and Tradeoffs
The harder part of building for organizations without a security team isn't ingesting threat data — it's every design decision that follows: what feed to trust first, how to match software without drowning in false positives, and why explainable beats sophisticated.
The Soft Underbelly of American Cyber Resilience Isn't Where You Think
The next major incident against a hospital or utility is increasingly likely to start somewhere much smaller — a vendor, a nonprofit, a small business — and the market has left those organizations without affordable ways to see threats coming.
Why I'm building this.
This isn't a hypothetical gap to be solved someday. It has a name, a set of federal programs already trying to address pieces of it, and a growing body of evidence connecting it directly to the large-scale incidents that do make headlines. The small businesses, nonprofits, and public-sector offices operating without a security team aren't a side concern in national cyber resilience — given how often they sit one step upstream from the systems everyone depends on, they may be the part of the picture that matters most.
Anyone who has spent time doing OSINT and digital forensics work sees this pattern up close. Most of the information needed to catch these threats early already exists in the open — it's just scattered, technical, and built for analysts who already have a security operations center behind them. This project takes that same public signal and turns it into something a nonprofit director or small-business owner can act on.
The early version is already working: pulling live data from CISA's Known Exploited Vulnerabilities catalog, matching it against an organization's actual software profile, and turning it into a plain-language digest instead of a raw feed dump — open source and public from day one, because the whole point is accessibility, not another walled-off platform.
Get in touch
Built by Jason Dedjoe
Status
Core loop working end to end against CISA KEV. Next milestone: testing against a real organization's environment rather than synthetic test data. Following the build here and in the repo.