Security Analyst · Threat Intelligence · Detection Engineering
I build self-updating threat-intel platforms and DFIR tooling that run entirely on the edge — no signup, no API keys to start, free-tier only.
186+ analyst tools · 328-tool MCP server · 60+ IOC providers · 13 replicated TI verticals · 100+ live intel feeds
PLATFORMS — live at pranithjain.qzz.io
| Platform | What it is | Link |
|---|---|---|
| CRUCIBLE · DFIR Toolkit | 186+ interactive tools across 21 categories — triage, OSINT, email defense, detection engineering, AI security, crypto tracing | /dfir |
| PANOPTICON · Threat Intel | Self-updating CTI platform — ransomware tracking, CVE/KEV, IOC firehose, actor dossiers; 13 replicated verticals, hourly refresh | /threatintel |
| SCOUT · Recon Scanner | External attack-surface scanning — 30+ checks across crawl, JS analysis, secret exposure, scoring | /radar |
| ARGUS · Threat Nexus | Nation-state intel dashboard — 3D threat globe, actor timelines, campaign mapping | /argus |
| Repo | What it is |
|---|---|
| dfir-mcp-server | Standalone MCP server proxying all 323 tools of the platform API — deploy your own endpoint for Claude Desktop / Cursor |
| dfir-threat-intel-agent | Autonomous LLM investigator — plans, calls intel tools in parallel, QA-verifies, synthesizes cited reports |
| portfolio | The platform monorepo — React SPA + Worker API + MCP server + cron sync pipelines |
| DFIR-PLATFORM | Standalone /dfir toolkit slice — the open-source distribution of CRUCIBLE |
| cti-cli | Threat intelligence from the terminal — AI copilot, 60+ provider IOC checks, feed monitoring |
| dfir-cli | Offline-first DFIR commands — IOC extraction, hashing, PE analysis, encoding |
| cti-ai-skills | 5 CTI skills for Claude Code, Cursor & Codex |
| dfir-ai-skills | 2 DFIR investigation skills for AI coding assistants |

