Skip to main content

Built a self-hosted threat intel aggregator, finally cleaned it up enough to open source it

0
Medium
Published: 09/14/2026 (09/14/2026, 23:08:51 UTC)
Source: Reddit ThreatIntel

Description

This content describes an open-source self-hosted threat intelligence aggregator tool designed to collect, deduplicate, and correlate threat intelligence feeds from over 60 sources. It includes features such as IOC extraction, ATT&CK mapping, integration with asset inventories, and detection engineering capabilities. The tool can run locally or integrate with Azure environments and supports optional AI triage. It is not a vulnerability or exploit but rather a security tool release.

Reddit Discussion

r/threatintel·posted by u/3eandrews3
00

Been sitting on this since May, so figured I'd just put it out there. Basically I got tired of manually checking a dozen+ vendor blogs every morning to see if anything was actually relevant to what I run, so I built something that pulls from 60ish feeds (CISA, Talos, MSRC, SANS, the usual suspects), dedupes it, pulls out IOCs, and maps everything to ATT&CK so you're not just staring at a wall of blog titles.

The part I actually care about is the "your stack" thing, you tell it what EDR/cloud/SIEM/firewall you run and it filters down to what's relevant instead of dumping every CVE on earth on you. If you've got RunZero hooked up it goes a step further and actually checks your live asset inventory, so instead of "this affects Fortinet devices" you get "this affects 3 assets you actually have right now," which is the difference between reading a blog post and knowing you have a problem today.

Also has a whole detection engineering side if you're into that, you can import your own KQL/Sigma/SPL/YARA/Suricata rules, or if you're on Sentinel it'll sync and help tune your analytics rules. Everything that touches an actual rule gets run through a static gate + backtest before it's treated as good, and there's an audit log so you can see what's failing instead of just trusting it blindly.

Runs fully local with docker compose or you can point it at Azure/Entra if that's your environment already. Same code either way, just env vars.

Heads up before anyone asks, there's an AI triage piece that's optional, it's not required to run the thing and the basic tier has it off entirely. I worked in this space building it and I'm aware "AI powered security tool" is basically a meme at this point so no hard feelings if that's an instant close-tab for you, the core aggregation/dedup/ATT&CK mapping stuff works without it.

It's MIT licensed, repo's here if anyone wants to poke at it or tell me what's broken: Threat Intel Aggregator

Screenshots in the readme if you want to see it before cloning. Happy to answer questions, hear how it could be improved, or why it sucks

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 05:02:09 UTC

Technical Analysis

The subject is a self-hosted threat intelligence platform that aggregates RSS feeds from numerous security vendors, extracts indicators of compromise, maps data to the MITRE ATT&CK framework, and filters alerts based on the user's environment and asset inventory. It supports integration with RunZero for live asset correlation and can import custom detection rules in various formats. The platform offers deployment options ranging from fully local setups to Azure-integrated environments with Microsoft Entra ID SSO. An optional AI triage component classifies threat severity and summarizes findings but is not required for core functionality. The project is open source under the MIT license and aims to reduce manual effort in threat intelligence consumption.

Potential Impact

There is no security vulnerability or threat described. The content is informational about a security tool that helps organizations manage and prioritize threat intelligence. No direct impact or exploitation risk is indicated.

Defensive Guidance

Not applicable, as this is not a vulnerability or threat but a security tool release. Users interested in the tool should review the source code and documentation for deployment and operational guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ThreatIntelligence+threatintel+websecurityresearch
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":38,"reasons":["external_link","newsworthy_keywords:rce","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["rce"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa8d14c55bf5e2cf5290cf9

Added to database: 09/15/2026, 05:02:04 UTC

Last enriched: 09/15/2026, 05:02:09 UTC

Last updated: 09/15/2026, 09:01:28 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses