Jérôme Léonard is a cyber threat intelligence specialist with nearly 17 years in information security and nine years of focused professional experience, based in Paris. He leads CTI activities and brings deep hands-on expertise in threat hunting, malware and memory analysis, digital forensics, incident response, and secure infrastructure design. Jérôme is an active open-source contributor on TheHive Project’s Cortex and Cortex-Analyzers, where he developed and hardened MISP module integration and improved Nessus analyzer reporting and presentation. His work combines operational incident handling with tooling improvements that make threat intelligence workflows more automatable and auditable. He also teaches information security courses, demonstrating a commitment to knowledge sharing and operational maturity.
Contributions:14 reviews, 926 commits, 160 PRs in 5 years 11 months
Contributions summary:Jérôme's contributions primarily focused on the implementation of new features and functionality within the Cortex Analyzers repository, specifically related to integrating the Nessus vulnerability scanner. They merged branches, potentially incorporating new functionality, and modified the long report templates by fixing display issues with progress bars and colors. These changes involved updating templates, which suggests a focus on the presentation and integration of vulnerability data within the system. Furthermore, the user added and changed the summary() function and updated other short reports templates to use a taxonomie, revealing expertise in data presentation and possibly reporting.
Cortex: a Powerful Observable Analysis and Active Response Engine
Role in this project:
Back-end Developer
Contributions:13 commits, 13 pushes, 1 branch in 3 years 10 months
Contributions summary:Jérôme primarily focused on developing and refining a module loader for the Cortex project, specifically for integrating with MISP modules. Their commits demonstrate the creation and modification of a Python script (`misp-modules-loader.py`) to load and execute MISP modules, manage module paths, and handle input/output using JSON. The user improved functionality by adding listing capabilities, information retrieval, and handling JSON serialization/deserialization to address errors. These changes collectively enhanced the integration capabilities of Cortex with external threat intelligence modules.
cortexpythondfirengineobservable
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.