Threat Intel Aggregator



A self-hosted threat intelligence platform that aggregates RSS feeds from 60+ security vendors, runs AI triage, correlates findings against your RunZero asset inventory, and surfaces actionable alerts through a dark-mode web dashboard.
Built to run standalone with zero cloud dependency, or fully integrated into an Azure/Entra/Sentinel environment — pick the tier that matches what you've got.
Deployment tiers
| Tier | Script | AI triage | Auth | Storage | You get |
|---|
| Basic | scripts/setup-basic.sh | Off | Local API key | Local Postgres (Docker) | Feed aggregation, IOC extraction, MITRE matrix, dashboards — no AI, no cloud, nothing to sign up for |
| Basic + API | scripts/setup-basic-api.sh | Anthropic (direct) | Local API key | Local Postgres (Docker) | Everything above, plus AI severity/TTP/summary triage |
| Azure + API | scripts/setup-azure.ps1 | Azure AI Foundry | Microsoft Entra ID SSO | Your own Postgres (Azure DB for PostgreSQL, etc.) | Full deployment to Azure Container Apps, SSO with per-user roles. (The detections.ai pipeline integration is coming in a future release — see below.) |
All three run the exact same application code — the only thing that changes is which env vars are set. See Environment Variables for the full reference.
# Basic — no AI, no cloud
./scripts/setup-basic.sh
# Basic + API — adds direct Anthropic triage
./scripts/setup-basic-api.sh
# Azure + API — full SIEM-integrated deployment (PowerShell 7+, az CLI)
./scripts/setup-azure.ps1
The two bash scripts stand up a local Postgres container, apply the schema, and generate backend/.env / frontend/.env.local for you — then print the two commands to actually start the app (pip install + run backend, npm install + run frontend dev server). setup-azure.ps1 is a thin wrapper around infra/provision.ps1, the real Azure Container Apps deployment runbook.
Features
- Feed aggregation — polls 60+ Tier 1/2/3 security RSS feeds on a schedule; deduplicates and filters promotional content automatically
- AI triage — classifies each entry with severity (Critical/High/Medium/Low/Informational), MITRE ATT&CK TTPs, and a plain-English summary. Provider-modular: direct Anthropic API or Azure AI Foundry, switchable via one env var with no functionality lost either way
- IOC extraction — automatically extracts IPs, domains, URLs, file hashes, and CVEs from each entry
- RunZero integration — syncs your asset inventory and correlates threat intel against live assets; matches on CVEs, software names, OS versions, and IP addresses. Three sub-tabs under
RUNZERO: Matches (entries correlated against your inventory, filterable by severity/date/confidence/KEV), Exposure (org-level confirmed/possible standing with remediation tracking), and Metrics (intake vs. remediation trends over time)
- Your Stack — define the software/OS in your environment; re-scores all entries by relevance
- IOC ledger — searchable ledger of all extracted indicators with entry cross-references and STIX/CSV export
- MITRE ATT&CK matrix — heatmap of TTP coverage across your ingested threat intel
- Feed health dashboard — per-feed poll status, consecutive failure tracking, and 7-day article volume
- Detections — a 9-tab review surface (see below) covering everything registered as a detection, whether AI-generated, imported from your own files, or synced from a live Sentinel workspace
- Modular auth — Microsoft Entra ID SSO with role-based access, or a single shared local API key with zero Azure dependency. Auto-detected by the frontend; see Auth modes
This repo actually ships two related but independently-usable things under the "detections" umbrella:
- The
DETECTIONS tab — a self-contained review surface, split into nine sub-tabs:
- All Detections — the full catalog of registered analytics, filterable by technique/disposition/review state, each expandable to its description and full KQL.
- Defender Custom Detections — the same catalog, locked to detections destined for Microsoft Defender for Endpoint's custom detection rules rather than Sentinel analytics rules.
- Alignment Reviews — whenever a detection analytic is registered against a MITRE technique, an AI check compares its actual coverage against MITRE's own description of that technique. When it diverges or only partially covers the technique, it lands here as a human review item with the AI's reasoning, a suggested KQL fix, and that fix's own validation result (static gate + backtest) — never a blind suggestion.
- Disposition Alerts — a rot-detection queue: an approved analytic whose telemetry decays or whose underlying rule starts erroring gets flagged here for re-review, named by its own detection rather than only the shared MITRE technique.
- Generated Hunts — detections are grouped into hunts (one per imported file today; one per originating TI article/detections.ai project once that integration ships), matching Microsoft Sentinel's own Hunts feature. A hunt can be synced into a real Sentinel workspace as a
Microsoft.SecurityInsights/hunts object plus its constituent saved-search queries (gated by SENTINEL_HUNTING_SYNC_ENABLED and a mode — off/manual/auto — configurable per-team in Settings > API Settings; never a silent auto-push unless you opt in).
- Sentinel Hunts — the live inventory of what's actually deployed to your Sentinel workspace's Hunting feature, pulled directly from ARM rather than this app's own sync history; includes per-query test/tune suggestions you can apply or dismiss in place.
- Sentinel Analytics Rules — the same idea for Microsoft Sentinel's Analytics Rules (
Microsoft.SecurityInsights/alertRules) — a distinct Sentinel resource type from Hunting, since these are what actually fire incidents/alerts on a schedule — with the same tune-suggestion apply/dismiss workflow.
- Local Detections — see Running without Sentinel or an AI provider below.
- Audit Log (admin-only) — a cross-pipeline record of every check this app has actually run: AI-generated detection gate/control-probe results, Sentinel hunt sync attempts, and Sentinel hunt-query/analytics-rule test runs, combined into one paginated, filterable list — deliberately covering what no single review tab does on its own.