A mix of frameworks, automations, tools, and experiments — some anonymized due to client confidentiality, others open for the community.
A practical framework for designing national and sector-scale cyber early warning systems. Covers detection architecture, alert routing, stakeholder mapping, and operating models that survive lean staffing. Drawn from engagements with national CERTs across Central and South Asia.
A set of filtering rules and scoring logic for turning raw threat intelligence feeds into actionable alerts. Designed for teams with more feeds than analysts.
An experimental AI agent for first-pass alert triage in CSIRT operations. Human-in-the-loop by design. Not production-ready.
Troy Hunt gives national CERTs and government CSIRTs free access to query and monitor their government domains against billions of breached credentials — domain search via API, with alerts when new breaches hit. More than 45 governments onboarded, from Bangladesh to Bhutan. If you run a national CSIRT and you are not on the list, that gap is fixable in one email.
See the government onboardings→Before buying any threat feed, sign up for this. Shadowserver emails a free daily report on your own ASN or IP ranges: exposed attack surface (open RDP, Elasticsearch, MongoDB) plus malware and botnet activity leaving your network. 90+ report types, by email or API. No charge — it is a nonprofit, and national CERTs can get country-level reports. The first thing I set up with any new CERT.
Request free reports→I'm always interested in collaborating with practitioners who are building in the early warning, CTI, and CSIRT space. If you have a project that aligns, get in touch.
Current open questions I'm exploring: How do lean CSIRTs scale triage without scaling headcount? What does effective public-private coordination actually look like in practice? How can AI agents augment (not replace) human judgment in security operations?