Open-source and data attributions for Huntbase, including MITRE ATT&CK, CVE and NVD.
Last updated
Huntbase is built with open-source software and enriched with public security data. This page gives the attributions, copyright notices and licence terms that come with them.
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
ATT&CK® is a registered trademark of The MITRE Corporation. Used under the ATT&CK Terms of Use.
Copyright © 2007–2026, The MITRE Corporation. CAPEC and the CAPEC logo are trademarks of The MITRE Corporation.
The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use Common Attack Pattern Enumeration and Classification (CAPEC™) for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. See the CAPEC Terms of Use.
Copyright © 2006–2026, The MITRE Corporation. CWE and the CWE logo are trademarks of The MITRE Corporation.
The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use Common Weakness Enumeration (CWE™) for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. See the CWE Terms of Use.
Copyright © 1999–2026, The MITRE Corporation. CVE and the CVE logo are registered trademarks of The MITRE Corporation.
CVE records are used under the CVE Terms of Use, which grant a licence to reproduce and distribute CVE provided MITRE's copyright designation and the licence are reproduced.
This product uses data from the NVD API but is not endorsed or certified by the NVD.
| Source | Provider | Terms |
|---|---|---|
| Open Source Vulnerabilities (OSV) | OSV.dev | Aggregated from many sources, each under its own licence (many CC BY 4.0). |
| Exploit Prediction Scoring System (EPSS) | FIRST | EPSS scores courtesy of FIRST, used under FIRST's EPSS usage terms. |
| EU consolidated list of financial sanctions | European Commission | © European Union. Reused under Commission Decision 2011/833/EU on the reuse of Commission documents. |
| OFAC Specially Designated Nationals list | US Department of the Treasury | Public domain (US Government work). |
| Known Exploited Vulnerabilities catalog and Vulnrichment | CISA | CC0 1.0. |
| MITRE ATLAS™ | The MITRE Corporation | Apache License 2.0. |
| MITRE D3FEND™ | The MITRE Corporation | MIT License. |
Huntbase does not distribute SigmaHQ rules. Each customer organisation can retrieve the SigmaHQ rule set itself, after accepting the Detection Rule License (DRL) 1.1. Huntbase records that acceptance and keeps each rule's author and reference fields visible, as the DRL requires. Huntbase's own detection catalogue contains original rules.
Huntbase Endpoint Control works with osquery installed on your hosts, together with Huntbase's Scout extension. osquery is copyright The osquery Authors and is dual-licensed under the Apache License 2.0 or GPL 2.0; Huntbase uses it under the Apache License 2.0.
The Huntbase web application includes elkjs, unmodified, under the Eclipse Public License 2.0. Its source code is available from the linked repository.
The Huntbase platform uses many open-source components, almost all under permissive licences such as MIT, Apache 2.0, BSD and ISC. A full list of components and their licences is available on request from [email protected].
ATT&CK, ATLAS, CAPEC, CVE, CWE and D3FEND are trademarks or registered trademarks of The MITRE Corporation. Other product names and logos shown on this site and in Huntbase belong to their owners. Their use identifies compatible products and does not imply endorsement.
Questions about these notices: [email protected].