What This Looks Like for a Real Organization: A Walkthrough
A note before this starts: this is a synthetic, illustrative walkthrough, not a real deployment. No actual school district or organization is represented here, and the vulnerability example below is a realistic but fictional stand in for the kind of entry that appears in CISA's real feed, not an actual current CVE. This exists to make the pipeline concrete for anyone trying to understand what the output actually looks like, while a real pilot deployment is still being sought. When that happens, it'll get its own writeup, clearly labeled as real.
The scenario
Picture a small K to 12 school district IT office. One IT generalist covers everything, network, helpdesk, a handful of servers, and whatever security responsibility exists by default rather than by design. No dedicated security staff, no budget for a threat intel subscription, no time to manually check vulnerability feeds between everything else on their plate. This is exactly the kind of organization the tool is built for, and it's a common profile among the public sector entities CISA has specifically flagged as under protected.
Step 1: the org profile
Setting this up takes a few minutes. The IT generalist lists the software and platforms the district actually depends on:
```yaml organization_name: "Example School District IT Office" products: - "Google Workspace" - "PowerSchool" - "Zoom" - "Fortinet" ```
That's it. No security expertise required to fill this out, just knowing what the district runs day to day.
Step 2: ingestion
Each day, the pipeline pulls CISA's Known Exploited Vulnerabilities catalog. On a typical day this might return a handful of newly added entries, most completely unrelated to anything this district runs, a vulnerability in industrial control software, or a content management system nobody here has heard of.
Step 3: filtering
Say the day's feed includes an illustrative entry like this one:
``` Vendor: Fortinet Product: FortiOS CVE ID: CVE-2026-XXXXX (illustrative example, not a real entry) Date added: recent ```
The filtering module checks this against the district's profile. "Fortinet" is an exact match against their declared products. This entry gets flagged as relevant, everything else in that day's feed that doesn't match anything in their profile gets quietly filtered out, no noise reaches them.
Step 4: triage
Because it's an exact match and was added recently, this entry gets scored Critical. If it had matched only loosely, an adjacent product rather than an exact one, or been added weeks earlier, it would have landed as Watch instead, still worth knowing, less urgent.
Step 5: the digest
This is what actually lands in the IT generalist's inbox:
``` Threat Intel Digest for Example School District IT Office
1 critical, 0 to watch, 0 informational. ==================================================
[Critical] Fortinet FortiOS (CVE-2026-XXXXX)
What happened: A vulnerability in FortiOS is being actively exploited right now, according to CISA.
Why it matters to you: You're running Fortinet based on your profile. Attackers already know how to exploit this.
What to do: Update to the patched version as soon as possible. If you can't update immediately, review Fortinet's advisory for interim mitigation steps. Due by: [CISA's required remediation date for this entry] ```
No jargon, no ambiguity, no need to cross reference anything else to understand what's being asked. On a quiet day with nothing relevant, the same district would instead get a short message confirming the check ran and nothing urgent came up, so the tool never goes silent in a way that could be mistaken for broken.
Why this matters more than the code itself
The engineering behind this (covered in the architecture writeup) is the harder problem to solve well. But this is the part that actually matters to the person on the receiving end: an email that tells them, in under thirty seconds of reading, whether today is a day they need to act. That's the entire design goal, made concrete.
A real deployment, with a real organization's real software and a real person reading real digests over time, is the next real test of whether this actually holds up outside a synthetic example like this one.
Follow the build
This project is open source and public from day one. Track progress, read the design docs, or contribute at github.com/jdeveloping-ux/oss-threat-intel ↗