grimoire/

Datenquellen

grimoire basiert vollständig auf öffentlichen Threat-Intelligence-Katalogen. Jede Quelle unten ist mit ihrer Lizenz, ihrer Herkunft, ihrem Beitrag zum Graphen und dem Zeitpunkt der letzten Übernahme aufgeführt. Wir geben diese auf Grundlage unseres berechtigten Interesses am Betrieb eines öffentlichen Sicherheits-Wissensgraphen wieder; eigene Daten fügen wir nicht hinzu.

Falls Sie in einer dieser Quellen genannt werden (etwa als Autor einer Erkennungsregel) und dies berichtigt oder entfernt haben möchten, schreiben Sie an hello@temnir.com.

BDU (FSTEC Data Security Threats Database)

FeedRU

Russia's Data Security Threats Database (БДУ), operated by FSTEC — the sovereign Russian vulnerability catalogue, including flaws with no assigned CVE.

Lizenz: No licence published: sovereign RU source (FSTEC), all rights reserved, use at own risk.Quelle ↗Aktualisiert vor 5 Std.

Source: FSTEC BDU (Russia). Republished as factual vulnerability data; no licence is granted by the source.

CERT-Bund (BSI CSAF)

SicherheitshinweiseDE

CERT-Bund, Germany's national CERT at the BSI — publishes CSAF 2.0 security advisories (WID-SEC-…) coordinating vendor and product vulnerabilities.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

Quelle: BSI CERT-Bund. Free for non-commercial re-use with source acknowledgement; commercial re-use requires a separate BSI agreement.

CISA CSAF IT advisories

FeedUS

CISA's machine-readable CSAF 2.0 advisories for information technology (VA series).

Lizenz: Keine Lizenz angegebenQuelle ↗Aktualisiert vor 5 Std.

US Government work, public domain. Courtesy attribution to CISA.

CISA CSAF OT advisories (ICS)

FeedUS

CISA's machine-readable CSAF 2.0 advisories for operational technology — ICS (ICSA) and ICS medical (ICSMA) advisories.

Lizenz: Keine Lizenz angegebenQuelle ↗Aktualisiert vor 5 Std.

US Government work, public domain. Courtesy attribution to CISA.

CISA KEV

FeedUS

CISA's Known Exploited Vulnerabilities catalogue — CVEs with confirmed in-the-wild exploitation, each carrying a U.S. federal remediation due date.

Lizenz: Public domain (17 U.S.C. 105, US Government work)Quelle ↗Noch nicht übernommen

US Government work, public domain. Courtesy attribution to CISA.

CISA Vulnrichment (SSVC)

FeedUS

CISA's Vulnrichment program — SSVC decision points (Exploitation, Automatable, Technical Impact) added to CVE records via CISA's ADP container, for U.S. federal remediation prioritisation.

Lizenz: CC0-1.0 ↗Quelle ↗Aktualisiert vor 5 Std.

US Government work, public domain. Courtesy attribution to CISA.

CNNVD (China National Vulnerability Database of Information Security)

APICN

China's National Vulnerability Database of Information Security (国家信息安全漏洞库), operated under CNITSEC — including flaws catalogued with no assigned CVE.

Lizenz: No licence published: all rights reserved (CNITSEC), use at own risk.Quelle ↗Aktualisiert vor 5 Std.

Source: CNNVD / CNITSEC (China). Republished as factual vulnerability data; no licence is granted by the source.

CTID ATT&CK Mappings

WissensbasisUS

MITRE Center for Threat-Informed Defense mappings of CISA KEV (known-exploited) CVEs to the MITRE ATT&CK techniques they enable — the bridge from a vulnerability to adversary behaviour.

Lizenz: Apache-2.0 ↗Quelle ↗Aktualisiert vor 5 Std.

© Center for Threat-Informed Defense. Licensed under Apache-2.0; incorporates MITRE ATT&CK under its own terms.

EU Vulnerability Database (ENISA)

APIEU

ENISA's EU Vulnerability Database — the European Union's coordinated catalogue of vulnerabilities, established under the NIS2 directive.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Noch nicht übernommen

Source: ENISA European Vulnerability Database. Re-use authorised with acknowledgement of the source.

EUR-Lex — CIR (EU) 2024/2690

WissensbasisEU

Commission Implementing Regulation (EU) 2024/2690 — the technical and methodological requirements underpinning NIS2. Its Annex is the mappable control catalogue; the NIS2 Directive's own Article 21(2) is ten uncontrolled noun-phrases and is deliberately not modelled.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

© European Union, eur-lex.europa.eu. Re-use authorised (Decision 2011/833/EU) with source acknowledgement and indication of any changes.

Exploit-DB

FeedUS

OffSec Exploit Database — a curated archive of public exploits and PoCs, mapped to the CVEs they exploit.

Lizenz: GPL-2.0-or-later ↗Quelle ↗Aktualisiert vor 5 Std.

Exploit Database © OffSec Services Ltd. and contributors, GPL-2.0-or-later.

FIRST EPSS

FeedUS

FIRST's Exploit Prediction Scoring System — daily-updated probabilities that a CVE will be exploited in the next 30 days, with a percentile rank.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

MISP Threat Actor Galaxy

Wissensbasis
Lizenz: CC0-1.0 ↗Quelle ↗Noch nicht übernommen

MISP Galaxy (CC0-1.0 / BSD-2-Clause); clusters derived from MITRE ATT&CK carry ATT&CK's attribution independently.

MITRE ATT&CK

Wissensbasis

MITRE ATT&CK — a knowledge base of real-world adversary tactics and techniques, used to describe how vulnerabilities are exploited.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. ATT&CK, CAPEC, CWE and D3FEND are trademarks of The MITRE Corporation.

MITRE CAPEC

WissensbasisUS

MITRE Common Attack Pattern Enumeration and Classification — attack patterns bridging software weaknesses (CWE) to the ATT&CK techniques that realize them.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. ATT&CK, CAPEC, CWE and D3FEND are trademarks of The MITRE Corporation.

MITRE CTID — ATT&CK to NIST 800-53 mappings

ZuordnungenUS

Center for Threat-Informed Defense mappings-explorer — the ATT&CK technique to NIST SP 800-53 control mappings. Apache-2.0.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

© Center for Threat-Informed Defense. Licensed under Apache-2.0; incorporates MITRE ATT&CK under its own terms.

MITRE CWE

WissensbasisUS

MITRE's Common Weakness Enumeration — a community catalogue of software and hardware weakness types (the CWE-… classes vulnerabilities are mapped to).

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. ATT&CK, CAPEC, CWE and D3FEND are trademarks of The MITRE Corporation.

MITRE D3FEND

WissensbasisUS

MITRE D3FEND — a knowledge graph of defensive cybersecurity countermeasures and their mappings to the ATT&CK techniques they counter.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. ATT&CK, CAPEC, CWE and D3FEND are trademarks of The MITRE Corporation.

Metasploit Framework

FeedUS

Rapid7 Metasploit Framework — exploit/auxiliary modules with a reliability rank, mapped to the CVEs they exploit.

Lizenz: BSD-3-Clause ↗Quelle ↗Aktualisiert vor 5 Std.

Metasploit Framework © Rapid7 LLC and contributors, BSD-3-Clause. Rapid7's name may not be used to endorse derived products.

NIST CSF 2.0 + 800-53 crosswalk

ZuordnungenUS

NIST Cybersecurity Framework 2.0 categories and the NIST 800-53 to CSF informative-reference crosswalk (OLIR/CPRT). US Government public domain.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Aktualisiert vor 5 Std.

Republished courtesy of NIST, U.S. Department of Commerce; not copyrighted in the United States.

NVD / CVE

APIUS

The U.S. National Vulnerability Database — NIST's feed of analysed CVE records, with CVSS scores, CWE mappings and CPE product data.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Noch nicht übernommen

This product uses data from the NVD API but is not endorsed or certified by the NVD.

OSV.dev

FeedUS

Google's Open Source Vulnerabilities database — advisories aggregated across open-source ecosystems (npm, PyPI, Go, …), keyed to affected package versions.

Lizenz: Nutzungsbedingungen ↗Quelle ↗Noch nicht übernommen

Licensed per upstream record: e.g. GitHub Advisory Database entries are CC BY 4.0, RustSec is CC0 1.0. See google.github.io/osv.dev/data.

SigmaHQ Sigma

Wissensbasis

SigmaHQ Sigma rules — a generic, SIEM-agnostic signature format for detection rules, mapped to the ATT&CK techniques/groups/software and CVEs they detect.

Lizenz: DRL-1.1Quelle ↗Aktualisiert vor 5 Std.

Detection rules remain © their respective authors (retained per rule) under the Detection Rule License 1.1.