Sources & licenses
ThreatDossier aggregates the sources below, with attribution. Government and openly-licensed feeds are used in full; copyrighted, non-commercial, or author-owned sources are shown as headline + link only under commercial use. The "Commercial use" column reflects behavior when the site runs in commercial (ad-supported / paid) mode. This page is generated from source metadata and is not legal advice.
Government / CERTs
| Source | License / terms | Commercial use |
|---|
| CISA Advisories | Public domain (U.S. Government work, 17 U.S.C. §105) | Full |
| FBI National Press Releases | Public domain (U.S. Government work, 17 U.S.C. §105) | Full |
| DOJ Justice News | Public domain (U.S. Government work, 17 U.S.C. §105) | Full |
| NCSC UK | Open Government Licence v3.0 (attribution) | Full |
| CERT-FR (France) | Licence Ouverte / Etalab 2.0 (attribution) | Full |
| CERT-UA (Ukraine) | No published reuse terms — permission advised | Headline + link only |
Security press
| Source | License / terms | Commercial use |
|---|
| Krebs on Security | © Krebs on Security — all rights reserved | Headline + link only |
| The Record | © The Record / Recorded Future — all rights reserved | Headline + link only |
| The Hacker News | © The Hacker News — all rights reserved | Headline + link only |
| SANS Internet Storm Center | CC BY-NC-SA 4.0 (non-commercial, share-alike) | Headline + link only |
Social
| Source | License / terms | Commercial use |
|---|
| infosec.exchange #threatintel | Author copyright (Mastodon) — no blanket licence | Headline + link only |
| mastodon.social #threatintel | Author copyright (Mastodon) — no blanket licence | Headline + link only |
Dark-web OSINT
| Source | License / terms | Commercial use |
|---|
| Ransomware.live — recent victims | Non-commercial T&C (commercial use prohibited) | Excluded |
| Ransomware.live — recent cyberattacks | Non-commercial T&C (commercial use prohibited) | Excluded |
| RansomLook — recent posts | CC BY 4.0 (attribution) | Full |
| Ransomfeed (ransomfeed.it) | CC BY 4.0 (attribution) | Full |
Vulnerability enrichment
CVEs in the feed and the daily brief are cross-referenced against two open datasets, used with attribution:
- CISA Known Exploited Vulnerabilities (KEV) — U.S. Government public-domain catalog of actively-exploited CVEs. Source: CISA.
- EPSS (Exploit Prediction Scoring System) — probability of exploitation in the next 30 days. Scores are produced by the EPSS SIG at FIRST.org and are free to use with attribution to FIRST.