OSINT · Threat Intelligence · Open Source

Threat intelligence for the organizations the enterprise market leaves behind.

Commercial threat-intel platforms cost more per year than many small businesses, nonprofits, and public-sector offices spend on their entire IT budget. This is an open, low-cost pipeline that pulls the same public intelligence those platforms charge for — starting with CISA's Known Exploited Vulnerabilities catalog — and turns it into a plain-language digest a non-technical decision maker can actually act on.

Data source
CISA KEV catalog
confirmed exploited only
Output
Plain-language digest
not a raw feed dump
License
Open & public
from day one
01The Problem

The soft underbelly of American cyber resilience isn't where most people think.

When people picture a major cyberattack, they picture a Fortune 500 company, a hospital system, a pipeline. What rarely makes the headline is the twelve-person accounting firm hit with ransomware, the local food bank whose donor database was quietly exfiltrated, or the small manufacturer that had no idea it was the weak link in a much larger supply chain until it was too late.

The next major incident affecting a hospital, a utility, or a school district is increasingly likely to start somewhere much smaller: a vendor, a nonprofit partner, a small business with a login into a bigger system. Attackers have figured out that the path of least resistance into a well-defended target often runs straight through a poorly-defended one standing next to it.

The tools that exist to close this gap fall into two categories: enterprise platforms priced for a six- or seven-figure security budget, and a patchwork of free, individually excellent OSINT tools that require enough security background to know which to use and how to stitch their output into something actionable. Neither works for the organization with one overworked IT generalist and no security team at all.

What's missing is something in between — tooling that pulls from the same open, low-cost intelligence sources larger platforms charge for, and turns raw signal into something a non-technical decision maker can act on: here is what changed, here is why it matters to you, here is what to do about it.

02The Tool

A five-stage pipeline that turns a public vulnerability feed into an email a non-technical person can act on.

</>View the source & design docs ↗

The engineering here is intentionally modest — ingestion and email delivery are the easy parts. The real work is the filtering and triage in the middle, the steps that decide what a busy organization with no security team ever needs to see.

  1. Ingestion01

    Pull the feed

    Fetch new and updated entries from CISA's Known Exploited Vulnerabilities catalog since the last run. KEV only lists vulnerabilities with confirmed, active exploitation — so everything entering the pipeline is already a strong signal.

  2. Org profile02

    Know the organization

    A small config lists what the organization actually runs — WordPress, QuickBooks, a specific VPN appliance, Microsoft 365. This is the key differentiator: without it, the tool would just be forwarding a raw feed nobody can read.

  3. Filtering03

    Cut the noise

    The filter matches each entry against the org's declared stack using exact and substring logic, narrowing a feed of hundreds of entries down to the handful that are actually relevant to that specific organization.

  4. Triage04

    Rank what's left

    Rule-based scoring — deliberately explainable, not machine learning — sorts matches into Critical, Watch, and Informational based on match confidence (exact vs substring) and how recently the vulnerability was added.

  5. Digest05

    Say it in plain language

    Each entry becomes three short lines: what happened, why it matters to you specifically, and what to do about it. Critical items get a direct action; everything else stays low-key. Delivered as an email, not a dashboard.

Critical

Exact match to the org's declared software and recently added to KEV. Confirmed exploited and directly relevant right now — gets a short, direct action recommendation.

Watch

Matches the profile but is either a partial match or was added a while ago. Worth confirming the specific version is patched, but lower urgency.

Informational

Passed the initial filter but doesn't meet the bar above. Included for awareness so the digest never goes fully silent.

03Interactive Demo

See the filtering and triage logic run — live, in your browser.

Pick a sample organization, edit what it runs, and watch a fixed set of KEV-style entries get filtered and triaged into a plain-language digest. Everything below runs client-side on static sample data — no live CISA call, no backend, no credentials. It demonstrates the logic, not the production infrastructure.

sample data · run date pinned to 2026-07-06 · 10 KEV entries in the sample

Step 1 — Choose an org profile

Step 2 — Edit the software stack

This is the org profile the real tool matches the feed against. Add or remove products and the results update instantly.

WordPressMOVEit TransferMicrosoft 365Fortinet FortiOS

Try adding

Result — triage summary

2
CRITICAL
1
WATCH
0
INFO

10 entries in → 3 relevant to Community Food Bank → 2 need attention now.

Filtered & triaged entries

3 of 10
  • CRITICALCVE-2023-34362exact match · added 4d ago

    Progress MOVEit Transfer — SQL Injection Vulnerability

    Exact match to your "moveit transfer" and added to KEV 4 days ago — confirmed exploited and directly relevant right now.

  • CRITICALCVE-2022-30190exact match · added 11d ago

    Microsoft Windows Support Diagnostic Tool (MSDT) — Remote Code Execution Vulnerability

    Exact match to your "microsoft 365" and added to KEV 11 days ago — confirmed exploited and directly relevant right now.

  • WATCHCVE-2023-27997exact match · added 26d ago

    Fortinet FortiOS — Heap-Based Buffer Overflow Vulnerability

    Exact match to your "fortinet fortios", but it was added 26 days ago, so it's likely already on your radar. Confirm it's patched.

Sample digest output

what the org would receive
To: it@communityfoodbank.org
Subject: Your threat digest — 2 items need attention

[CRITICAL] MOVEit Transfer: SQL Injection Vulnerability

What happened: A SQL injection flaw in MOVEit Transfer lets an unauthenticated attacker access and alter the file transfer database.

Why it matters: You listed moveit transfer in your profile, and this is being actively exploited according to CISA.

What to do: Apply the vendor patch immediately. If you can't patch today, disable HTTP/HTTPS traffic to the MOVEit server until you can.

[CRITICAL] Windows Support Diagnostic Tool (MSDT): Remote Code Execution Vulnerability

What happened: The 'Follina' flaw lets a malicious document run code through the Windows diagnostic tool.

Why it matters: You listed microsoft 365 in your profile, and this is being actively exploited according to CISA.

What to do: Ensure Windows is fully updated. This affects Windows / Microsoft 365 endpoints broadly.

[WATCH] FortiOS: Heap-Based Buffer Overflow Vulnerability

What happened: A heap overflow in FortiOS SSL-VPN can let a remote attacker run code via crafted requests.

Why it matters: You listed fortinet fortios in your profile, and this is being actively exploited according to CISA.

What to do: Upgrade FortiOS to a fixed version. Disable SSL-VPN if you can't upgrade right away.

Generated from CISA KEV · rule-based triage · reply to update your software profile

This is a static illustration of the pipeline's logic. The production tool runs the same steps as a scheduled backend job against the live CISA KEV catalog and delivers real email. See the implementation ↗

04Writing

The reasoning behind the build, written out in full.

All articles →

Full articles live here on the site, not scattered across other platforms. This is where the thinking behind the project gets worked out in the open.

05About & Contact

Why I'm building this.

This isn't a hypothetical gap to be solved someday. It has a name, a set of federal programs already trying to address pieces of it, and a growing body of evidence connecting it directly to the large-scale incidents that do make headlines. The small businesses, nonprofits, and public-sector offices operating without a security team aren't a side concern in national cyber resilience — given how often they sit one step upstream from the systems everyone depends on, they may be the part of the picture that matters most.

Anyone who has spent time doing OSINT and digital forensics work sees this pattern up close. Most of the information needed to catch these threats early already exists in the open — it's just scattered, technical, and built for analysts who already have a security operations center behind them. This project takes that same public signal and turns it into something a nonprofit director or small-business owner can act on.

The early version is already working: pulling live data from CISA's Known Exploited Vulnerabilities catalog, matching it against an organization's actual software profile, and turning it into a plain-language digest instead of a raw feed dump — open source and public from day one, because the whole point is accessibility, not another walled-off platform.

Status

Core loop working end to end against CISA KEV. Next milestone: testing against a real organization's environment rather than synthetic test data. Following the build here and in the repo.