Skip to content
View Pranith-Jain's full-sized avatar

Block or report Pranith-Jain

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Pranith-Jain/README.md

Pranith Jain

Security Analyst · Threat Intelligence · Detection Engineering

I build self-updating threat-intel platforms and DFIR tooling that run entirely on the edge — no signup, no API keys to start, free-tier only.

LinkedIn Portfolio DFIR Toolkit Threat Intel Email X

AT A GLANCE

186+ analyst tools · 328-tool MCP server · 60+ IOC providers · 13 replicated TI verticals · 100+ live intel feeds

Pranith's streak
Pranith's GitHub stats Top languages

TECH ARSENAL

LANGUAGES & FRAMEWORKS

TypeScript JavaScript Python React Hono FastAPI Vite Tailwind

SECURITY OPS & THREAT INTEL

VirusTotal Shodan Maltego Wireshark Sumo Logic Elastic Wazuh MITRE ATT&CK

EDGE & DATA

Cloudflare Workers D1 KV R2 Node.js MCP

AUTOMATION, AI & CLOUD

Claude Code n8n OpenAI Google Cloud Azure Git Docker Bash PowerShell


PLATFORMS — live at pranithjain.qzz.io

Platform What it is Link
CRUCIBLE · DFIR Toolkit 186+ interactive tools across 21 categories — triage, OSINT, email defense, detection engineering, AI security, crypto tracing /dfir
PANOPTICON · Threat Intel Self-updating CTI platform — ransomware tracking, CVE/KEV, IOC firehose, actor dossiers; 13 replicated verticals, hourly refresh /threatintel
SCOUT · Recon Scanner External attack-surface scanning — 30+ checks across crawl, JS analysis, secret exposure, scoring /radar
ARGUS · Threat Nexus Nation-state intel dashboard — 3D threat globe, actor timelines, campaign mapping /argus

OPEN SOURCE

Repo What it is
dfir-mcp-server Standalone MCP server proxying all 323 tools of the platform API — deploy your own endpoint for Claude Desktop / Cursor
dfir-threat-intel-agent Autonomous LLM investigator — plans, calls intel tools in parallel, QA-verifies, synthesizes cited reports
portfolio The platform monorepo — React SPA + Worker API + MCP server + cron sync pipelines
DFIR-PLATFORM Standalone /dfir toolkit slice — the open-source distribution of CRUCIBLE
cti-cli Threat intelligence from the terminal — AI copilot, 60+ provider IOC checks, feed monitoring
dfir-cli Offline-first DFIR commands — IOC extraction, hashing, PE analysis, encoding
cti-ai-skills 5 CTI skills for Claude Code, Cursor & Codex
dfir-ai-skills 2 DFIR investigation skills for AI coding assistants

Profile Views GitHub Followers GitHub Stars

Pinned Loading

  1. Pranith-Jain.github.io Pranith-Jain.github.io Public

    TypeScript 1

  2. DFIR-PLATFORM DFIR-PLATFORM Public

    Full-stack DFIR platform - domain security checker, IOC enrichment, phishing analyzer, exposure scanner, privacy check, threat intel feeds

    TypeScript

  3. cti-stix-connector cti-stix-connector Public

    Containerized Python CTI connector that processes IOCs and emits STIX 2.1 bundles

    Python

  4. cti-platform cti-platform Public

    CTI Platform — live ransomware tracking, cross-source IOC correlation, threat actor timelines, intel briefings, and CTI writeup aggregation

    TypeScript

  5. dfir-mcp-server dfir-mcp-server Public

    MCP server exposing 98 DFIR & threat intelligence tools for AI agents — IOC checking, CVE lookup, threat actor enrichment, phishing analysis, and more. Built on Cloudflare Workers.

    TypeScript

  6. stix21-builder stix21-builder Public

    STIX 2.1 bundle builder. Deterministic UUIDv5 IDs, MITRE ATT&CK cross-references, official OASIS TLP markings. Importable into OpenCTI, MISP, or any TAXII 2.1 client.

    TypeScript