CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Licensing

Attributions and licences

Cybersecurity Tracker aggregates open data from many sources. Several of their licences legally require attribution that stays publicly reachable, so this page is public and is never placed behind any gate. Each entry below states the source, its licence, the exact obligation, and a back-link where the licence demands one.

Attribution required by licence

SigmaHQ detection rulesDetection Rule License (DRL) 1.1

Detection rules indexed by ATT&CK technique.

Requires author attribution, a back-link to the rule, and the licence notice, shown wherever the rule text appears. Rules are stored and shown verbatim.

Back-link: SigmaHQ/sigma

Atomic Red Team (Red Canary)MIT

Validation-test metadata only (never the attack commands).

Requires the copyright notice and a "not affiliated with or endorsed by Red Canary" disclaimer. This tracker is not affiliated with or endorsed by Red Canary. Test metadata only, never the attack commands.

Back-link: redcanaryco/atomic-red-team

Exploit-DB (OffSec)GPL-2.0

Exploit metadata index (links only, never code).

Attribute Exploit-DB; metadata and links only, never the exploit code.

Open Cloud Vulnerability Database (Wiz)CC BY 4.0

Cloud vulnerabilities as no-CVE entities.

Attribute Wiz and contributors, and link the entry.

Back-link: wiz-sec/open-cvdb

ENISA EU Vulnerability Database (EUVD)CC BY 4.0

EU exploited vulnerabilities and independent CVSS.

Attribute ENISA.

RansomLookCC BY 4.0

Ransomware leak-site claims (primary).

Attributed on the breaches page, here, and in any API response that re-exposes it. Leak-site claims are unverified.

Have I Been PwnedCC BY 4.0

Verified breach directory (organization, account count, data classes) shown as confirmed breach rows.

Attribute HaveIBeenPwned.com.

OpenSSF Malicious Packages (via OSV)Apache-2.0

Open-source supply-chain compromises (MAL ids).

Attribute the Open Source Security Foundation (OpenSSF) and Open Source Vulnerabilities (OSV), which distributes the data.

Back-link: ossf/malicious-packages

endoflife.dateMIT

End of Support and End of Life dates.

Attribute endoflife.date.

ICS Advisory ProjectOpen Database License (ODbL) v1.0

The enumeration of CISA OT/ICS advisories (the CSAF advisories themselves are US-Government public domain).

Attribute the ICS Advisory Project.

MITRE ATT&CK, ATLAS, and Center for Threat-Informed Defense (CTID) mappingsMITRE terms of use

Techniques, mitigations, group relationships, the AI/ML ATLAS framework, and the CVE-to-technique and NIST 800-53 mappings.

Present MITRE's names and links per MITRE's terms. ATT&CK and ATLAS are used with attribution to The MITRE Corporation; the mappings are from MITRE Engenuity's Center for Threat-Informed Defense.

Back-link: attack.mitre.org

VulnCheckCommercial API (attribution required)

Exploitation catalog (KEV) and the NVD++ record mirror.

Prominent "VulnCheck KEV" and "VulnCheck NVD++" attribution wherever the data is shown.

CVE Program (The MITRE Corporation)CVE Program Terms of Use (CVE® is a registered trademark)

CVE List records: the CVSS scores published by the assigning CNA and by CISA as an Authorized Data Publisher, vendor and product, the description, the published date, and CISA's Vulnrichment SSVC decision points. Also a SOURCE OF RECORD: some CVEs are tracked here because the CVE Program published them and a relevance signal followed, not because another source surfaced them first.

Attribute "CVE® data from the CVE Program (MITRE)" wherever records are shown, and reproduce MITRE's copyright designation. Record metadata only, which is inherent to the source.

Attributed voluntarily

ransomware.live is the failover source for ransomware leak-site claims. It carries no data licence that requires attribution: its own code is released under the Unlicense, a public domain dedication, and the aggregated leak-site claims it republishes are not its copyrightable work.

Attribution is not required for ransomware.live. This tracker attributes it anyway, out of courtesy, so no reader should mistake this credit for a licence obligation. Leak-site claims are unverified.

abuse.ch ThreatFox contributes the in-the-wild indicator of compromise (IOC) metadata shown on a CVE's detail panel. abuse.ch is understood to release ThreatFox data into the public domain under Creative Commons Zero (CC0), a designation the operator confirms on the live source; either way it carries no attribution requirement.

Attribution is not required for abuse.ch ThreatFox. This tracker attributes it anyway, for provenance, so no reader should mistake this credit for a licence obligation. Only IOC metadata and a link back to the abuse.ch source page are shown; a raw indicator is never rendered as a clickable link, and a URL indicator is defanged on display.

Public-domain government sources

CISA (the Known Exploited Vulnerabilities catalog and the CSAF advisory feeds), the National Vulnerability Database (NVD) at NIST, and the US Securities and Exchange Commission's EDGAR filings are United States Government works in the public domain and carry no attribution obligation. This tracker names them anyway, for provenance.

This list is transcribed from the repository's SOURCES.md and NOTICE files, the authoritative record of every source and its licence.