Aller au contenu

Security public data

Vulnerabilities, techniques, groups and logs — each traceable to its source.

Loading the data…

Scope and how the data is collected

A first snapshot: the 50 most recent KEV entries, three ATT&CK groups with their techniques, and OTRF's public lab logs. SCAP is a catalog of specifications, not an evaluation engine or the full set of check definitions. Automatic updates are not configured.

Sourced claims, observed logs and analysis scenarios are kept apart. A KEV listing alone never decides that a particular asset is vulnerable or names an attacker.

The IPLD CIDs are the source of truth; the JSON-LD and Datomic forms are generated from the same data. The blocks are served over HTTPS. Distribution to the IPFS network and registration under the encyclopedia's single ref are separate steps.

MITRE ATT&CK terms of use · OTRF terms of use