Licences and attribution
Four upstream sources, four sets of terms. What each requires and how this site meets it.
| Source | Licence | Obligation | How it is met |
|---|---|---|---|
| MITRE ATT&CK® Terms of use |
Royalty-free licence, explicitly including commercial use, subject to the terms of use. | Attribution; reproduce the copyright notice; do not imply MITRE endorsement. | Every page derived from ATT&CK states the bundle version (v19.2). Notice below. ATT&CK is a registered trademark of The MITRE Corporation; this site is not affiliated with or endorsed by MITRE. |
| CISA Known Exploited Vulnerabilities cisagov/kev-data |
Work of the United States Government. CISA publishes no explicit licence statement for the catalogue; US Government works are generally not subject to domestic copyright (17 U.S.C. §105). Treated here as public domain on that basis, not on an assertion CISA has made. | None stated. | Attributed on every CVE page. Fields reproduced verbatim. |
| CTID Mappings Explorer center-for-threat-informed-defense/mappings-explorer |
Apache License 2.0 | Retain copyright and licence notices; state changes. | Mapping objects are reproduced with their comments and references, attributed to CTID on every page where they appear. Changes made: union across the published files, re-keyed by CVE, checked against ATT&CK v19.2. Copyright © The MITRE Corporation / Center for Threat-Informed Defense. |
| SigmaHQ rules SigmaHQ/sigma |
Detection Rule License (DRL) 1.1 | Permits use, modification, sale and sublicensing. Messages generated from a rule must retain identification of the author. Retain the licence notice. | Every rendering of a rule on this site, and every rule object in the published JSON, carries the rule's author field; the build refuses to run if a rule lacks one. Rule bodies are not reproduced — each rendering links to the rule at the exact commit (da9bb07d64). If you generate alerts from rules you found here, the author field travels with them; that is your obligation under DRL 1.1 as much as ours. |
| CAPEC (used on one page) mitre/cti |
MITRE terms of use, as for ATT&CK. | Attribution. | Attributed on that page. Copyright © The MITRE Corporation. |
Notices
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. ATT&CK® and CAPEC™ are trademarks of The MITRE Corporation.
Sigma rules © their respective authors, licensed under the Detection Rule License 1.1. Sigma is a project of SigmaHQ.
CTID mappings © The MITRE Corporation, Center for Threat-Informed Defense, licensed under the Apache License, Version 2.0.
This site
kevmap is free to use. The derived dataset under /data may be used under the upstream terms above. The site's own code is not published.