Data attributions
Every external data source ingested into MITRE Explorer Plus, grouped by license class
MITRE Explorer Plus aggregates ~30 authoritative threat-intelligence, vulnerability, and compliance feeds. The application code is ISC-licensed; the underlying data inherits each source’s upstream license. Below is the full inventory + the upstream URLs you should cite if you derive further work from anything you see here.
Public domainno attribution required
Works of the United States government (17 USC §105) — free to use, modify, and redistribute without restriction or attribution. Attribution still appreciated.
| Source | License | What we use |
|---|---|---|
| NIST 800-53 Rev. 5 | Public domain (17 USC §105) | Security and privacy controls for federal information systems. |
| NIST CSF v2 | Public domain (17 USC §105) | Cybersecurity Framework v2 subcategories + CRI Profile crosswalk. |
| NIST 800-66 r2 | Public domain | HIPAA Security Rule implementation guidance. |
| CISA Known Exploited Vulnerabilities | Public domain | Vulnerabilities known to be actively exploited in the wild. |
| NVD (NIST National Vulnerability Database) | Public domain | CVE metadata, CVSS scores, CPE enrichment. |
| MITRE CWE | Public domain (DHS-funded) | Common Weakness Enumeration taxonomy. |
Permissive open-sourceattribution appreciated
MIT / Apache 2.0 / CC0 / Detection Rule License — free for any use, commercial or otherwise. Attribution is appreciated by the upstream maintainers.
| Source | License | What we use |
|---|---|---|
| MITRE ATT&CK | Apache 2.0 | Adversary tactics, techniques, sub-techniques, groups, software, campaigns, mitigations, data sources/components. |
| MITRE CAPEC | Public domain (DHS-funded) | Common Attack Pattern Enumeration and Classification — full taxonomy + CWE→ATT&CK bridge. |
| MITRE D3FEND | MIT | Defensive countermeasure knowledge graph mapped to ATT&CK. |
| MITRE Engage | Apache 2.0 | Adversary engagement / deception activity mappings. |
| CTID (Center for Threat-Informed Defense) | Apache 2.0 | Hand-curated CVE → ATT&CK technique mappings. |
| VERIS | Apache 2.0 | Verizon DBIR Vocabulary for Event Recording and Incident Sharing. |
| RE&CT | MIT | ATC incident response playbook actions. |
| SigmaHQ | Detection Rule License (permissive) | 3,000+ detection rules mapped to ATT&CK techniques. |
| Atomic Red Team | MIT | 1,700+ adversary-emulation tests. |
| abuse.ch (ThreatFox + MalwareBazaar) | CC0 | Public-domain malware-family + IOC feeds (IPs, domains, URLs, hashes). |
| CVElistV5 | CC0 (CVE Program) | Authoritative CVE Program JSON feed — what NIST NVD consumes. |
Creative Commons (attribution required)must credit
CC BY 4.0 and CC BY-SA 4.0 — free to use and redistribute provided attribution is given. Share-alike (BY-SA) additionally requires derivative works to carry the same license. This page is part of that attribution.
| Source | License | What we use |
|---|---|---|
| MITRE ATLAS | CC BY 4.0 | AI/ML adversarial threat techniques + mitigations. |
| OWASP Top 10 (Web 2021, ML 2023, LLM 2025) | CC BY-SA 4.0 | Web, ML, and LLM security-risk categories — used with attribution to OWASP. |
| OSV.dev | CC BY 4.0 | Distributed vulnerability database for open-source projects (Google). |
| GHSA (GitHub Security Advisories) | CC BY 4.0 | OSS package advisories — npm, PyPI, Maven, Go, RubyGems, Composer, Rust, etc. |
| EPSS (FIRST.org) | CC BY 4.0 | Exploit Prediction Scoring System — daily probability scores per CVE. |
| ThaiCERT / ETDA Actor Encyclopedia | CC BY 4.0 | 500+ external threat-actor profiles. |
| Secure Controls Framework (SCF) | CC BY 4.0 | Catalogue of 1,469 controls cross-mapped to ~250 compliance and regulatory frameworks. Powers /compliance/* — the regulatory lens (NIS2, DORA, PCI DSS, ISO 27002, HIPAA, GDPR, NIST 800-53, CMMC, ...). |
Enrichment APIssee ToS
API-fetched data subject to the provider’s terms of service. We store only minimal derived records (aggregate verdicts, summary metadata) and never redistribute full responses.
| Source | License | What we use |
|---|---|---|
| AlienVault OTX | OTX community contribution terms | Threat-report pulses + IOC indicators consumed via API. |
| VirusTotal | VirusTotal Terms of Service | Domain and file-hash verdict counts (malicious/suspicious/harmless) — only aggregate verdicts stored, no full report content redistributed. |
RSS / blog indexing
Public RSS feeds — we index titles, URLs, and short summaries (typical for an aggregator). Articles remain the copyright of their original publishers.
| Source | License | What we use |
|---|---|---|
| The DFIR Report | Article copyright respective authors; we store title + URL + summary for indexing. | Incident-response intrusion writeups. |
| Unit 42 (Palo Alto Networks) | Article copyright PANW; indexed. | Threat-intel research blog. |
| Microsoft Security Blog | Article copyright Microsoft; indexed. | Microsoft threat research. |
| Cisco Talos | Article copyright Cisco Talos; indexed. | Talos threat-intel research. |
Disclaimers
- This site is not affiliated with, sponsored by, or endorsed by MITRE Corporation. “ATT&CK” and “ATLAS” are registered trademarks of MITRE Corporation.
- OWASP® and the OWASP logo are trademarks of the OWASP Foundation.
- NIST does not endorse this product or service.
- Errors or omissions in attribution? Reach out at contact @ mitre-explorer.org.