Attributions and licences
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Source licences and API terms require these notices to stay publicly reachable, so this register is public and is never placed behind any gate. Each entry below states the source, its terms, the exact obligation, and a back-link where required.
Licence and attribution obligations
Source reported means the named source asserted the fact. Corroborating observation marks an independent external observation. Tracker computed and Tracker inference are Cybersecurity Tracker outputs, not statements by the named source.
Source last published is when the source published the material. Source last updated is when the source last changed the material. Tracker last fetched is when Cybersecurity Tracker retrieved it. Tracker last fetched never substitutes for Source last published or Source last updated.
- SigmaHQ detection rulesDetection Rule License (DRL) 1.1
Detection rules indexed by ATT&CK technique.
Requires author attribution, a back-link to the rule, and the licence notice, shown wherever the rule text appears. Rules are stored and shown verbatim.
Back-link: SigmaHQ/sigma
- Atomic Red Team (Red Canary)MIT
Validation-test metadata only (never the attack commands).
Requires the copyright notice and a "not affiliated with or endorsed by Red Canary" disclaimer. This tracker is not affiliated with or endorsed by Red Canary. Test metadata only, never the attack commands.
Back-link: redcanaryco/atomic-red-team
- Exploit-DB (OffSec)GPL-2.0
Exploit metadata index (links only, never code).
Attribute Exploit-DB; metadata and links only, never the exploit code.
- Metasploit Framework (Rapid7)BSD-3-Clause
Exploit-module name, reliability rank, and Framework link (never module source).
Copyright 2006-2026, Rapid7, Inc. Retain the copyright notice, BSD-3-Clause conditions, and warranty disclaimer in distributions. Neither Rapid7 nor contributor names may be used for endorsement without prior written permission. The complete required notice is reproduced in NOTICE.
Back-link: Metasploit Framework
- Greenbone OpenVAS Community FeedOpen Database License (ODbL) 1.0; individual VTs retain their per-file licence
Factual OpenVAS VT-to-CVE mappings: OID, name, creation date, and source link; never NASL code or prose.
Contains information from OPENVAS COMMUNITY FEED (GCF, https://www.greenbone.net/en/gcf-odbl-license/) which is made available here under the Open Database License (ODbL, https://opendatacommons.org/licenses/odbl/odbl-10.txt). The scanner_detections entries whose scanner is greenbone remain an identifiable, machine-readable ODbL component; applicable ODbL notice, attribution, share-alike, and database or alteration-file obligations must travel with downstream reuse. No Greenbone logo, endorsement, or commercial-scanner claim is made.
Back-link: Greenbone OpenVAS Community Feed
- ProjectDiscovery Nuclei templatesMIT
CVE-tagged template ID, name, and source link; no publication date is inferred.
MIT License. Copyright (c) 2025 ProjectDiscovery, Inc. Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Back-link: projectdiscovery/nuclei-templates
- Open Cloud Vulnerability Database (Wiz)CC BY 4.0
Cloud vulnerabilities as no-CVE entities.
Attribute Wiz and contributors, link the entry, link the licence, and indicate changes.
Back-link: wiz-sec/open-cvdb
- ENISA EU Vulnerability Database (EUVD)CC BY 4.0
EU exploited vulnerabilities and independent CVSS.
Attribute ENISA, link the licence and source where reasonably practicable, and indicate changes.
- CERT-EU security advisories and threat intelligenceCC BY 4.0
Attributed news cards from security advisories and threat intelligence, including the headline, summary, publication date when provided, and original link.
Copyright Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU). Credit CERT-EU and link each original publication and this legal notice. The tracker selects, normalizes, summarizes, classifies, and may deduplicate or cluster feed items, and identifies those operations here as changes. Third party works, logos, names, and other industrial property are excluded from the licence claim.
Back-link: CERT-EU publications
- GitHub Advisory DatabaseCC BY 4.0
Package ecosystem, affected range, and first patched version from GitHub Security Advisories.
Credit the GitHub Advisory Database; link the original advisory and the CC BY 4.0 licence wherever package, affected-range, or fixed-version statements are shared. The tracker republishes those source statements without modification; a downstream modification must be identified. No endorsement is implied.
Back-link: GitHub Advisory Database
- Exploit Prediction Scoring System (EPSS), FIRST.orgFIRST EPSS usage terms
Current exploit-probability scores, percentiles, and historical score trends.
FIRST grants free public use, including commercial use, and asks for attribution where possible. Use the source's requested wording: "See EPSS at https://www.first.org/epss".
Back-link: FIRST EPSS
- RansomLookCC BY 4.0
Ransomware leak-site claims (primary).
Attributed on the breaches page, here, and in any API response that re-exposes it. Leak-site claims are unverified.
- Have I Been PwnedCC BY 4.0
Verified breach directory (organization, account count, data classes) shown as confirmed breach rows.
Attribute HaveIBeenPwned.com, link the licence and source where reasonably practicable, and indicate changes.
- OpenSSF Malicious Packages (via OSV)Apache-2.0
Open-source supply-chain compromises (MAL ids).
Attribute the Open Source Security Foundation (OpenSSF) and Open Source Vulnerabilities (OSV), which distributes the data.
Back-link: ossf/malicious-packages
- endoflife.dateMIT
End of Support and End of Life dates.
Attribute endoflife.date and retain its copyright and licence notice.
- ICS Advisory ProjectOpen Database License (ODbL) v1.0
The enumeration of CISA OT/ICS advisories (the CSAF advisories themselves are US-Government public domain).
Attribute the ICS Advisory Project and keep the ODbL notice with public use of the database.
- MITRE ATT&CK, ATLAS, and Center for Threat-Informed Defense (CTID) mappingsMITRE terms of use
Techniques, mitigations, group relationships, the AI/ML ATLAS framework, and the CVE-to-technique and NIST 800-53 mappings.
Present MITRE's names and links per MITRE's terms. ATT&CK and ATLAS are used with attribution to The MITRE Corporation; the mappings are from MITRE Engenuity's Center for Threat-Informed Defense.
Back-link: attack.mitre.org
- ETDA / ThaiCERT Threat Group CardsCC BY-NC-SA 4.0
Actor origin, motivation, victim sectors, and victim countries.
Copyright © Electronic Transactions Development Agency, 2019-2026. Attribute ETDA/ThaiCERT, link the source card and licence, indicate changes, use only non-commercially, and license adaptations under CC BY-NC-SA 4.0. Retain the source notice: "All information contained herein is provided on an “As Is” basis with no warranty whatsoever."
Back-link: ETDA Threat Group Cards
- Malpedia (Fraunhofer FKIE)CC BY-NC-SA 3.0
Public malware-family names, aliases, actor associations, and family links.
Credit Malpedia (Fraunhofer FKIE), link the family page and licence, indicate changes, use only non-commercially, and share adaptations alike under CC BY-NC-SA 3.0. Only publicly accessible family content is used; non-public material governed as TLP:AMBER is not re-exposed. Retain the source's disclaimer: "Everything is provided as is".
Back-link: Malpedia
- VulnCheckCommercial API (attribution required)
Exploitation catalog (KEV), NVD++ record mirror, and threat-actor crosswalk.
Prominent "VulnCheck KEV", "VulnCheck NVD++", or "VulnCheck" attribution wherever the corresponding data is shown.
- ShodanShodan Website & API Plans Terms of Service
Dated aggregate internet-facing instance counts used as product-wide blast-radius context.
The tracker uses the licensed API and exposes only a dated aggregate product-wide count, not underlying Shodan records. It names and links Shodan for provenance; no Shodan trademark licence, sublicense, or downstream redistribution right is granted, and any separate API-plan agreement controls.
Back-link: Shodan
- Red Hat Security Data (CSAF 2.0 advisories)CC BY 4.0
Cross-vendor Patch Day rows: the CVE to fixed-version mapping from RHSA, RHBA, and RHEA advisories, with Red Hat's own published severity.
Requires attribution to Red Hat, Inc. and a link to the original advisory, per the CSAF document's own legal disclaimer. Every available original-advisory self reference is preserved; the Patch Day coverage note reports the measured link ratio.
Back-link: Red Hat Security Data
- Canonical Ubuntu Security metadataCC BY-SA 4.0
Ubuntu release and source-package fixed-version statements joined to tracked records by Canonical's exact upstream CVE.
Canonical states: "This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License." Credit Canonical Ubuntu Security, link the source and licence, identify the tracker's exact-CVE extraction and normalization as changes, and keep adapted material under CC BY-SA 4.0 or a compatible licence.
Back-link: Canonical Ubuntu OSV security metadata
- CVE Program (The MITRE Corporation)CVE Program Terms of Use (CVE is a trademark; the CVE logo is a registered trademark of The MITRE Corporation)
CVE List records, CNA and CISA ADP data, source-quoted applicability qualifiers, and CISA Vulnrichment SSVC decision points.
Attribute "CVE™ data from the CVE Program (MITRE)" wherever records are shown and reproduce Copyright © 1999-2026, The MITRE Corporation. CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. Record metadata only, which is inherent to the source.
- U.S. Department of JusticeU.S. federal public domain (except identified third-party material)
Official cybercrime arrest, indictment, seizure, disruption, and takedown announcements.
Attribute the U.S. Department of Justice and link the original release. Do not reproduce seals, logos, photographs, or identified third-party material without a separate rights review.
Back-link: U.S. Department of Justice
- UK National Crime AgencyOpen Government Licence v3.0 (the linked NCA terms page was marked expired when checked 2026-08-21)
Official UK cybercrime arrest, seizure, disruption, and takedown announcements.
Attribute the National Crime Agency, link the original release and OGL v3.0, and do not use the NCA logo or imply endorsement. Present adapted metadata accurately and non-misleadingly. The NCA site still links its terms page, but that page displayed an Expired banner when checked 2026-08-21; this caveat is retained rather than overstating the grant.
Back-link: National Crime Agency
- U.S. Treasury Office of Foreign Assets ControlU.S. federal public domain (except identified third-party material)
Official current cyber-related sanctions-list entries and newly observed additions.
Attribute the U.S. Treasury Office of Foreign Assets Control and link the official sanctions-list service. This tracker exposes action metadata and links, not personal identifiers or an alternative compliance list.
Back-link: OFAC Sanctions List Service
- Cybersecurity and Infrastructure Security Agency newsTLP:CLEAR unless otherwise marked; U.S. federal public domain subject to third-party rights
Official cyber disruption and infrastructure-takedown announcements.
Attribute CISA and link the original item. Share TLP:CLEAR material without implying endorsement, preserve any more restrictive marking, and exclude logos and identified third-party material unless separately permitted.
Back-link: CISA News
Attributed voluntarily
ransomware.live is the failover source for ransomware leak-site claims. It carries no data licence that requires attribution: its own code is released under the Unlicense, a public domain dedication, and the aggregated leak-site claims it republishes are not its copyrightable work.
Attribution is not required for ransomware.live. This tracker attributes it anyway, out of courtesy, so no reader should mistake this credit for a licence obligation. Leak-site claims are unverified.
abuse.ch ThreatFox contributes the in-the-wild indicator of compromise (IOC) metadata shown on a CVE's detail panel. abuse.ch is understood to release ThreatFox data into the public domain under Creative Commons Zero (CC0), a designation the operator confirms on the live source; either way it carries no attribution requirement.
Attribution is not required for abuse.ch ThreatFox. This tracker attributes it anyway, for provenance, so no reader should mistake this credit for a licence obligation. Only IOC metadata and a link back to the abuse.ch source page are shown; a raw indicator is never rendered as a clickable link, and a URL indicator is defanged on display.
Public-domain government sources
CISA (the Known Exploited Vulnerabilities catalog and the CSAF advisory feeds), the National Vulnerability Database (NVD) at NIST, and the US Securities and Exchange Commission's EDGAR filings are United States Government works in the public domain and carry no attribution obligation. This tracker names them anyway, for provenance.
This page renders the repository's shared attributions.json register. Its licence findings and exact obligations are documented in SOURCES.md and NOTICE.