CI
CyberIntel
  • Dashboard
  • ⚡ Live Feed
  • MITRE ATT&CK
  • UEBA

Data Sources & Attribution

Last updated: January 1, 2026 · Resilient Privacy Inc.

CyberIntel™ aggregates publicly available threat intelligence from the sources listed below. We are deeply grateful to the organisations and researchers who make this data freely accessible for the betterment of global cybersecurity. All data is used in accordance with each provider's terms of service and applicable licenses.

CyberIntel does not claim ownership of any third-party data. All trademarks, copyrights, and intellectual property displayed on this platform belong to their respective owners.

⚖️ Legal notice: All third-party data displayed on CyberIntel is used under the respective terms of service, public domain declarations, Creative Commons licenses, or non-commercial use permissions of each provider. Where attribution is required, it is provided on this page and in the platform footer. If you believe your data is being used outside the scope of your license terms, please contact us at legal@resilientprivacy.com.

Government & Public Domain Sources

U.S. Gov National Vulnerability Database (NVD)

nvd.nist.gov

© National Institute of Standards and Technology (NIST), U.S. Department of Commerce. NVD data is a work of the U.S. Government and is in the public domain. CVE data is used to populate our vulnerability reports.

U.S. Gov CISA Known Exploited Vulnerabilities

cisa.gov/known-exploited-vulnerabilities-catalog

© Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Homeland Security. Public domain. The KEV catalog is used to surface actively exploited vulnerabilities requiring immediate attention.

Threat Intelligence Providers

ToS AbuseIPDB

abuseipdb.com

© AbuseIPDB LLC. Used under the AbuseIPDB Terms of Service. AbuseIPDB blacklist and check APIs power our live threat heatmap, attack feed, and IP reputation lookup. Attribution required for public displays.

Non-Commercial Abuse.ch (MalwareBazaar, ThreatFox, URLhaus)

abuse.ch · bazaar.abuse.ch · threatfox.abuse.ch · urlhaus.abuse.ch

© abuse.ch. Used for non-commercial threat intelligence purposes per abuse.ch terms. MalwareBazaar powers our malware samples feed, ThreatFox powers our IOC intelligence feed, and URLhaus powers our phishing/malware URL feed.

CC BY 4.0 MITRE ATT&CK®

attack.mitre.org

© 2015–2026 The MITRE Corporation. ATT&CK® is a registered trademark of The MITRE Corporation. ATT&CK framework data is licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). Used to map threat intelligence to adversary tactics and techniques.

Free SANS Internet Storm Center / DShield

isc.sans.edu · dshield.org

© SANS Internet Storm Center. DShield data including top attacking IPs, targeted ports, and the Infocon threat level is used under SANS ISC terms for informational and non-commercial use.

Open Data ransomware.live

ransomware.live

© ransomware.live contributors. An open-data project tracking ransomware groups and their victims. Used to power our Ransomware Tracker section. Data is publicly contributed by the security research community.

Free Feed OpenPhish

openphish.com

© OpenPhish. The OpenPhish community feed is used under OpenPhish Terms of Service for informational threat intelligence purposes. Phishing URLs are used in our Malware & Phishing Intel section.

ToS PhishTank

phishtank.com

© Cisco Talos / PhishTank. Used under PhishTank Terms of Service. PhishTank is a collaborative clearing house for data and information about phishing on the Internet. Powers one of our URL scanner engines.

ToS urlscan.io

urlscan.io

© urlscan.io GmbH. Used under urlscan.io Terms of Service (free tier). urlscan.io is a service to scan and analyse websites. Powers our URL scanner deep analysis engine including screenshot capability.

Google ToS Google Safe Browsing

developers.google.com/safe-browsing

© Google LLC. Used under Google APIs Terms of Service (free tier). The Safe Browsing API checks URLs against Google's continuously updated lists of unsafe web resources. Powers one of our four URL scanner engines.

ToS Shodan InternetDB

internetdb.shodan.io

© Shodan. Used under Shodan Terms of Service. The Shodan InternetDB provides fast IP lookups including open ports, known CVEs on services, and tags. Powers our IP/Domain Reputation Lookup tool.

News & Content Sources

RSS BleepingComputer

bleepingcomputer.com

© BleepingComputer. News summaries fetched via public RSS feed for threat intelligence news aggregation purposes.

RSS Krebs on Security

krebsonsecurity.com

© Brian Krebs / Krebs on Security. News summaries fetched via public RSS feed.

RSS The Hacker News

thehackernews.com

© The Hacker News Media. News summaries fetched via public RSS feed.

RSS Dark Reading

darkreading.com

© Informa Tech / Dark Reading. News summaries fetched via public RSS feed.

RSS SecurityWeek

securityweek.com

© Wired Business Media / SecurityWeek. News summaries fetched via public RSS feed.

RSS Naked Security (Sophos)

nakedsecurity.sophos.com

© Sophos Ltd. News summaries fetched via public RSS feed.

RSS Malwarebytes Labs

blog.malwarebytes.com

© Malwarebytes Inc. News summaries fetched via public RSS feed.

RSS Schneier on Security

schneier.com

© Bruce Schneier. Commentary and analysis summaries fetched via public Atom feed.

RSS Graham Cluley

grahamcluley.com

© Graham Cluley. News summaries fetched via public RSS feed.

U.S. Gov CISA Advisories

cisa.gov/cybersecurity-advisories

© CISA, U.S. Government. Public domain. Security advisories fetched via public RSS/XML feed.

RSS Cisco Talos Intelligence

blog.talosintelligence.com

© Cisco Systems / Talos Intelligence Group. Research summaries fetched via public RSS feed.

RSS Palo Alto Unit 42

unit42.paloaltonetworks.com

© Palo Alto Networks / Unit 42 Threat Research. Research summaries fetched via public RSS feed.

RSS Exploit-DB

exploit-db.com

© Offensive Security. Exploit entries fetched via public RSS feed under Offensive Security Terms.

RSS Packet Storm Security

packetstormsecurity.com

© Packet Storm Security. Security advisories and exploits fetched via public RSS feed.

Security Rules & Frameworks

DRL 1.1 SigmaHQ — Sigma Rules

github.com/SigmaHQ/sigma

© SigmaHQ Contributors. Sigma detection rules are used under the Detection Rule License (DRL) 1.1. Sample rules displayed on our MITRE ATT&CK page are adapted from SigmaHQ for educational and threat intelligence purposes.

Maps & UI Libraries

ODbL 1.0 OpenStreetMap

openstreetmap.org

© OpenStreetMap contributors. Map tiles and data are available under the Open Database Licence (ODbL). Used for our global threat heatmap. openstreetmap.org/copyright

BSD 2-Clause Leaflet.js

leafletjs.com

© 2010–2024 Vladimir Agafonkin. Leaflet is an open-source JavaScript library for interactive maps, licensed under BSD 2-Clause. Used for our interactive threat heatmap.

MIT Chart.js

chartjs.org

© 2014–2024 Chart.js Contributors. Licensed under the MIT License. Used for ransomware timelines, port charts, and UEBA analytics visualizations.

Google ToS Google Fonts

fonts.google.com

© Google LLC. Inter (© The Inter Project Authors) and JetBrains Mono (© JetBrains s.r.o.) are licensed under the SIL Open Font License 1.1. Served via Google Fonts CDN.

Contact for Attribution Issues

If you are a data provider and believe your content is being used outside the scope of your license or terms of service, please contact us immediately:

Email: legal@resilientprivacy.com
General: info@resilientprivacy.com
Resilient Privacy Inc.

We take attribution seriously and will respond within 5 business days.

© 2026 Resilient Privacy Inc. All rights reserved. CyberIntel™Privacy · Terms · Security · Cookies