Built a self-hosted threat intel aggregator, finally cleaned it up enough to open source it
This content describes an open-source self-hosted threat intelligence aggregator tool designed to collect, deduplicate, and correlate threat intelligence feeds from over 60 sources. It includes features such as IOC extraction, ATT&CK mapping, integration with asset inventories, and detection engineering capabilities. The tool can run locally or integrate with Azure environments and supports optional AI triage. It is not a vulnerability or exploit but rather a security tool release.
AI Analysis
Technical Summary
The subject is a self-hosted threat intelligence platform that aggregates RSS feeds from numerous security vendors, extracts indicators of compromise, maps data to the MITRE ATT&CK framework, and filters alerts based on the user's environment and asset inventory. It supports integration with RunZero for live asset correlation and can import custom detection rules in various formats. The platform offers deployment options ranging from fully local setups to Azure-integrated environments with Microsoft Entra ID SSO. An optional AI triage component classifies threat severity and summarizes findings but is not required for core functionality. The project is open source under the MIT license and aims to reduce manual effort in threat intelligence consumption.
Potential Impact
There is no security vulnerability or threat described. The content is informational about a security tool that helps organizations manage and prioritize threat intelligence. No direct impact or exploitation risk is indicated.
Mitigation Recommendations
Not applicable, as this is not a vulnerability or threat but a security tool release. Users interested in the tool should review the source code and documentation for deployment and operational guidance.
Built a self-hosted threat intel aggregator, finally cleaned it up enough to open source it
Description
This content describes an open-source self-hosted threat intelligence aggregator tool designed to collect, deduplicate, and correlate threat intelligence feeds from over 60 sources. It includes features such as IOC extraction, ATT&CK mapping, integration with asset inventories, and detection engineering capabilities. The tool can run locally or integrate with Azure environments and supports optional AI triage. It is not a vulnerability or exploit but rather a security tool release.
Reddit Discussion
Been sitting on this since May, so figured I'd just put it out there. Basically I got tired of manually checking a dozen+ vendor blogs every morning to see if anything was actually relevant to what I run, so I built something that pulls from 60ish feeds (CISA, Talos, MSRC, SANS, the usual suspects), dedupes it, pulls out IOCs, and maps everything to ATT&CK so you're not just staring at a wall of blog titles.
The part I actually care about is the "your stack" thing, you tell it what EDR/cloud/SIEM/firewall you run and it filters down to what's relevant instead of dumping every CVE on earth on you. If you've got RunZero hooked up it goes a step further and actually checks your live asset inventory, so instead of "this affects Fortinet devices" you get "this affects 3 assets you actually have right now," which is the difference between reading a blog post and knowing you have a problem today.
Also has a whole detection engineering side if you're into that, you can import your own KQL/Sigma/SPL/YARA/Suricata rules, or if you're on Sentinel it'll sync and help tune your analytics rules. Everything that touches an actual rule gets run through a static gate + backtest before it's treated as good, and there's an audit log so you can see what's failing instead of just trusting it blindly.
Runs fully local with docker compose or you can point it at Azure/Entra if that's your environment already. Same code either way, just env vars.
Heads up before anyone asks, there's an AI triage piece that's optional, it's not required to run the thing and the basic tier has it off entirely. I worked in this space building it and I'm aware "AI powered security tool" is basically a meme at this point so no hard feelings if that's an instant close-tab for you, the core aggregation/dedup/ATT&CK mapping stuff works without it.
It's MIT licensed, repo's here if anyone wants to poke at it or tell me what's broken: Threat Intel Aggregator
Screenshots in the readme if you want to see it before cloning. Happy to answer questions, hear how it could be improved, or why it sucks
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The subject is a self-hosted threat intelligence platform that aggregates RSS feeds from numerous security vendors, extracts indicators of compromise, maps data to the MITRE ATT&CK framework, and filters alerts based on the user's environment and asset inventory. It supports integration with RunZero for live asset correlation and can import custom detection rules in various formats. The platform offers deployment options ranging from fully local setups to Azure-integrated environments with Microsoft Entra ID SSO. An optional AI triage component classifies threat severity and summarizes findings but is not required for core functionality. The project is open source under the MIT license and aims to reduce manual effort in threat intelligence consumption.
Potential Impact
There is no security vulnerability or threat described. The content is informational about a security tool that helps organizations manage and prioritize threat intelligence. No direct impact or exploitation risk is indicated.
Defensive Guidance
Not applicable, as this is not a vulnerability or threat but a security tool release. Users interested in the tool should review the source code and documentation for deployment and operational guidance.
Technical Details
- Source Type
- Subreddit
- ThreatIntelligence+threatintel+websecurityresearch
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":38,"reasons":["external_link","newsworthy_keywords:rce","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aa8d14c55bf5e2cf5290cf9
Added to database: 09/15/2026, 05:02:04 UTC
Last enriched: 09/15/2026, 05:02:09 UTC
Last updated: 09/15/2026, 09:01:28 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.