version: "1"
policy: "docs/source-policy.md"
defaults:
  decision: "quarantine"
  max_age_days: 30
  retention: "snapshot-only; public output keeps minimum evidence"
  false_positive: "source-scoped assertion quarantines the row"
  actor_linkage: "unassigned"
  normalization: "observable-v1"
# Explicitly outside the observable source register. These inputs may provide
# prose or links only; they cannot publish an observable or actor relationship.
excluded_inputs:
  analyst-notes:
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "prohibited_as_automatic_observable_source"
    reason: "manual context requires separate review and must not overwrite source evidence"
  security-news-and-reference-fetchers:
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "prohibited_as_automatic_observable_source"
    reason: "article discovery and report indexes are not indicator evidence"
  raw-malware-samples:
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "prohibited"
    reason: "samples, payloads, and download material are outside the public defensive minimum"
sources:
  threatfox:
    name: "abuse.ch ThreatFox"
    url: "https://threatfox.abuse.ch/api/"
    supported_types: ["ip_address", "domain", "url", "md5", "sha1", "sha256"]
    terms: "abuse.ch terms; Auth-Key required for live API"
    license: "abuse.ch community data; verify current terms before redistribution"
    rate_limits: "API bounded to get_iocs days 1..7; honor HTTP 429 and documented limits"
    attribution_strength: "record-level IOC and malware references; actor is not asserted by default"
    normalization: "observable-v1; preserve ThreatFox IOC ID and report URL"
    freshness: "7 days"
    max_age_days: 7
    correction_contact: "https://threatfox.abuse.ch/contact/"
    retention: "dated snapshot and manifest; no raw payloads"
    false_positive: "quarantine source record; never delete corroborating evidence"
    actor_linkage: "malware-mediated or direct only with explicit reviewed mapping; name/tag coincidence prohibited"
    decision: "publish_conditional"
  urlhaus:
    name: "abuse.ch URLhaus"
    url: "https://urlhaus.abuse.ch/"
    supported_types: ["url", "domain", "ip_address", "sha256"]
    terms: "verify current abuse.ch terms and redistribution conditions"
    license: "verify before publication"
    rate_limits: "bulk export or documented API limits; bounded age window"
    attribution_strength: "URL/malware observation; no actor attribution"
    normalization: "observable-v1; defang only for display"
    freshness: "30 days; age-filter URLs"
    retention: "snapshot-only until terms review"
    false_positive: "quarantine and preserve source record"
    actor_linkage: "unassigned or malware-mediated; actor ownership prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "quarantine_deferred"
  malwarebazaar:
    name: "abuse.ch MalwareBazaar"
    url: "https://bazaar.abuse.ch/"
    supported_types: ["md5", "sha1", "sha256", "domain", "url", "ip_address"]
    terms: "verify fair-use, authentication, and redistribution terms"
    license: "verify before publication"
    rate_limits: "document API limits; bounded metadata queries only"
    attribution_strength: "sample/hash and malware metadata; no actor attribution"
    normalization: "observable-v1; hashes only, never samples"
    freshness: "30 days"
    retention: "metadata snapshot; never retain or publish samples"
    false_positive: "quarantine disputed hash"
    actor_linkage: "malware-mediated only after independently reviewed relationship; otherwise unassigned"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "quarantine_deferred"
  feodo-tracker:
    name: "abuse.ch Feodo Tracker"
    url: "https://feodotracker.abuse.ch/"
    supported_types: ["ip_address", "domain", "url"]
    terms: "verify current abuse.ch terms"
    license: "verify before publication"
    rate_limits: "bulk export with bounded polling"
    attribution_strength: "C2 observation and malware family; family is not actor proof"
    normalization: "observable-v1; expiry required for infrastructure"
    freshness: "7 days; expire infrastructure observations"
    retention: "dated snapshot and expiry metadata"
    false_positive: "quarantine until source correction/review"
    actor_linkage: "unassigned or malware-mediated; actor ownership prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "quarantine_deferred"
  mitre-attack:
    name: "MITRE ATT&CK"
    url: "https://attack.mitre.org/"
    supported_types: []
    terms: "MITRE permission notice and attack-stix-data terms"
    license: "MITRE permission notice"
    rate_limits: "versioned STIX snapshot; no live build fetch"
    attribution_strength: "canonical group and relationship identity, not IOC feed"
    normalization: "STIX snapshot plus observable-v1 where separately evidenced"
    freshness: "14 days"
    retention: "versioned snapshot/cache"
    false_positive: "revoke/deprecate STIX object; quarantine conflicting mapping"
    actor_linkage: "direct for explicit STIX relationships only"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  misp-galaxy:
    name: "MISP Galaxy"
    url: "https://github.com/MISP/misp-galaxy"
    supported_types: []
    terms: "repository license metadata"
    license: "CC0 where source metadata says so"
    rate_limits: "versioned snapshot"
    attribution_strength: "actor identity and references; not standalone IOC actor evidence"
    normalization: "source record plus observable-v1 when independently evidenced"
    freshness: "14 days"
    retention: "snapshot and provenance"
    false_positive: "quarantine conflicting cluster/member"
    actor_linkage: "direct identity only; IOC linkage requires record evidence"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  malpedia:
    name: "Malpedia / Fraunhofer FKIE"
    url: "https://malpedia.caad.fkie.fraunhofer.de/"
    supported_types: []
    terms: "Malpedia legal terms"
    license: "CC BY-NC-SA 3.0 when applicable"
    rate_limits: "documented/observed limits; snapshot only"
    attribution_strength: "malware-family metadata and reviewed relationships"
    normalization: "source record; observable-v1 for hashes only when explicitly published"
    freshness: "30 days"
    retention: "metadata snapshot"
    false_positive: "quarantine disputed family mapping"
    actor_linkage: "malware-mediated only; never automatic actor ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  etda-thaicert:
    name: "ETDA / ThaiCERT Threat Group Cards"
    url: "https://apt.etda.or.th/"
    supported_types: []
    terms: "public card terms; preserve publisher attribution"
    license: "not declared globally"
    rate_limits: "snapshot and bounded fetch"
    attribution_strength: "report/card actor and malware context"
    normalization: "source record; no IOC publication without explicit evidence"
    freshness: "30 days"
    retention: "snapshot and cited card"
    false_positive: "quarantine conflicting card claim"
    actor_linkage: "report-mediated/direct for explicit card claims; co-occurrence prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  aptnotes:
    name: "APTnotes"
    url: "https://github.com/aptnotes/data"
    supported_types: []
    terms: "repository terms; linked reports retain publisher rights"
    license: "report-index use only"
    rate_limits: "versioned CSV snapshot"
    attribution_strength: "report index, not report evidence"
    normalization: "source record URL and report citation"
    freshness: "30 days"
    retention: "index metadata only"
    false_positive: "remove/quarantine broken or misindexed citation"
    actor_linkage: "report-mediated only after reading cited report"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  ransomware-tool-matrix:
    name: "BushidoUK Ransomware Tool Matrix"
    url: "https://github.com/BushidoUK/Ransomware-Tool-Matrix"
    supported_types: []
    terms: "repository terms"
    license: "unknown; attribution required"
    rate_limits: "Git snapshot"
    attribution_strength: "secondary tradecraft reference"
    normalization: "source file and reviewed note"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine uncorroborated observation"
    actor_linkage: "prohibited from IOC actor ownership; report-mediated review only"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  ransomware-vulnerability-matrix:
    name: "BushidoUK Ransomware Vulnerability Matrix"
    url: "https://github.com/BushidoUK/Ransomware-Vulnerability-Matrix"
    supported_types: ["cve"]
    terms: "repository terms"
    license: "unknown; attribution required"
    rate_limits: "Git snapshot"
    attribution_strength: "secondary vulnerability reference"
    normalization: "observable-v1 CVE validation"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine disputed CVE relation"
    actor_linkage: "prohibited; vulnerability context is not actor IOC evidence"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "quarantine_actor_linkage"
  cisa-kev:
    name: "CISA Known Exploited Vulnerabilities Catalog"
    url: "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
    supported_types: ["cve"]
    terms: "public government catalog"
    license: "public government data; verify page terms"
    rate_limits: "bounded JSON feed"
    attribution_strength: "vulnerability exploitation status, not actor attribution"
    normalization: "observable-v1 CVE validation"
    freshness: "30 days"
    retention: "dated catalog snapshot"
    false_positive: "quarantine corrected CVE row"
    actor_linkage: "prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_enrichment_only"
  first-epss:
    name: "FIRST EPSS"
    url: "https://www.first.org/epss/"
    supported_types: ["cve"]
    terms: "FIRST terms"
    license: "verify current terms"
    rate_limits: "document API/bulk limits"
    attribution_strength: "risk score only"
    normalization: "observable-v1 CVE validation"
    freshness: "7 days"
    retention: "dated score snapshot"
    false_positive: "quarantine malformed/stale score"
    actor_linkage: "prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "quarantine_deferred"
  otx:
    name: "AlienVault OTX"
    url: "https://otx.alienvault.com/"
    supported_types: ["ip_address", "domain", "url", "email", "md5", "sha1", "sha256"]
    terms: "verify quotas, terms, and redistribution rights"
    license: "unknown until feed-specific review"
    rate_limits: "quotas and API limits must be documented"
    attribution_strength: "community pulse/indicator context"
    normalization: "observable-v1 only after feed review"
    freshness: "7 days"
    retention: "quarantine snapshot"
    false_positive: "quarantine source assertion"
    actor_linkage: "unassigned; actor ownership prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "research_only"
  opencti:
    name: "OpenCTI/community feeds"
    url: "https://docs.opencti.io/"
    supported_types: []
    terms: "feed-specific; no blanket permission"
    license: "unknown"
    rate_limits: "deployment/feed-specific"
    attribution_strength: "feed-specific"
    normalization: "not registered"
    freshness: "unknown"
    retention: "quarantine only"
    false_positive: "quarantine"
    actor_linkage: "prohibited until feed review"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "research_only"
  wiz-cloud-threat-landscape:
    name: "Wiz Cloud Threat Landscape"
    url: "https://www.wiz.io/api/feed/cloud-threat-landscape/stix.json"
    supported_types: []
    terms: "Wiz feed terms; verify redistribution"
    license: "not declared for all feed objects"
    rate_limits: "versioned STIX snapshot"
    attribution_strength: "actor/tool/technique metadata"
    normalization: "STIX source record; no IOC inference"
    freshness: "30 days"
    retention: "snapshot and provenance"
    false_positive: "quarantine disputed relationship"
    actor_linkage: "direct STIX relationship only; co-occurrence prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  aptmap:
    name: "APTmap"
    url: "https://github.com/andreacristaldi/APTmap"
    supported_types: []
    terms: "repository terms"
    license: "verify before redistribution"
    rate_limits: "versioned JSON snapshot"
    attribution_strength: "secondary actor/malware crosswalk"
    normalization: "source record; no IOC inference"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine unmatched or conflicting relation"
    actor_linkage: "reviewed crosswalk only; report-mediated otherwise"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  eternal-liberty:
    name: "EternalLiberty"
    url: "https://github.com/StrangerealIntel/EternalLiberty"
    supported_types: []
    terms: "repository terms"
    license: "verify before redistribution"
    rate_limits: "versioned JSON snapshot"
    attribution_strength: "secondary alias crosswalk"
    normalization: "source record"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine disputed alias"
    actor_linkage: "identity crosswalk only; no IOC ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  microsoft-threat-actor-list:
    name: "Microsoft Threat Actor List"
    url: "https://learn.microsoft.com/en-us/defender-xdr/microsoft-threat-actor-naming"
    supported_types: []
    terms: "Microsoft public documentation terms"
    license: "Microsoft content terms"
    rate_limits: "bounded workbook snapshot"
    attribution_strength: "naming/identity reference"
    normalization: "source record"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine naming conflict"
    actor_linkage: "direct naming reference only; no IOC ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  apt-groups-operations:
    name: "APT Groups & Operations"
    url: "https://apt.threattracking.com/"
    supported_types: []
    terms: "public spreadsheet terms"
    license: "secondary research aid"
    rate_limits: "bounded export snapshot"
    attribution_strength: "secondary crosswalk"
    normalization: "source row and citation"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine disputed crosswalk"
    actor_linkage: "reviewed crosswalk only; co-occurrence prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  rapid7-aba-detections:
    name: "Rapid7 ABA Detections"
    url: "https://docs.rapid7.com/insightidr/aba-detections/"
    supported_types: []
    terms: "documentation terms"
    license: "verify before redistribution"
    rate_limits: "bounded repository snapshot"
    attribution_strength: "detection/tradecraft reference"
    normalization: "source record"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine uncorroborated detection"
    actor_linkage: "prohibited from actor IOC ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  reddrip7-apt-digital-weapon:
    name: "RedDrip7 APT_Digital_Weapon"
    url: "https://github.com/RedDrip7/APT_Digital_Weapon"
    supported_types: ["md5", "sha1", "sha256"]
    terms: "repository terms"
    license: "verify before redistribution"
    rate_limits: "bounded GitHub API snapshot"
    attribution_strength: "secondary hash lead"
    normalization: "observable-v1 hashes only after review"
    freshness: "90 days"
    retention: "hash metadata only"
    false_positive: "quarantine disputed hash"
    actor_linkage: "unassigned or reviewed report-mediated; folder name is not proof"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "quarantine_actor_linkage"
  russian-apt-tool-matrix:
    name: "BushidoUK Russian APT Tool Matrix"
    url: "https://github.com/BushidoUK/Russian-APT-Tool-Matrix"
    supported_types: []
    terms: "repository terms"
    license: "unknown; attribution required"
    rate_limits: "Git snapshot"
    attribution_strength: "secondary tradecraft reference"
    normalization: "source file and reviewed note"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine uncorroborated observation"
    actor_linkage: "prohibited from IOC actor ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  bushido-breach-reports:
    name: "BushidoToken Breach Report Collection"
    url: "https://github.com/BushidoUK/Breach-Report-Collection"
    supported_types: []
    terms: "repository terms; linked reports retain publisher rights"
    license: "report-index use only"
    rate_limits: "Git snapshot"
    attribution_strength: "report index"
    normalization: "source URL and report citation"
    freshness: "90 days"
    retention: "index metadata only"
    false_positive: "quarantine broken/misindexed citation"
    actor_linkage: "report-mediated only after reviewing linked report"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  curated-intel-moveit-transfer:
    name: "Curated Intelligence MOVEit Transfer Tracking"
    url: "https://github.com/curated-intel/MOVEit-Transfer"
    supported_types: []
    terms: "repository terms; linked reports retain publisher rights"
    license: "event-index use only"
    rate_limits: "Git snapshot"
    attribution_strength: "campaign event index"
    normalization: "source citation"
    freshness: "90 days"
    retention: "index metadata"
    false_positive: "quarantine disputed event"
    actor_linkage: "report-mediated review only; no IOC inference"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  sophos-threat-profiles:
    name: "Sophos Threat Profiles"
    url: "https://www.sophos.com/en-us/threat-profiles"
    supported_types: []
    terms: "site terms and robots/access limits"
    license: "verify before redistribution"
    rate_limits: "bounded HTML snapshot"
    attribution_strength: "vendor profile reference"
    normalization: "source record"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine parser/profile conflict"
    actor_linkage: "direct profile identity only; no IOC ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  google-cloud-apt-groups:
    name: "Google Cloud APT Groups"
    url: "https://cloud.google.com/blog/topics/threat-intelligence/apt-groups"
    supported_types: []
    terms: "Google Cloud site terms"
    license: "attribution required; verify reuse"
    rate_limits: "bounded page snapshot"
    attribution_strength: "secondary actor profile"
    normalization: "source citation"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine profile conflict"
    actor_linkage: "report/profile-mediated only; co-occurrence prohibited"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  breach-hq-threat-actors:
    name: "BreachHQ Threat Actors"
    url: "https://breach-hq.com/threat-actors"
    supported_types: []
    terms: "site terms and access limits"
    license: "secondary index; verify reuse"
    rate_limits: "bounded HTML snapshot"
    attribution_strength: "secondary actor index"
    normalization: "source record"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine name/alias mismatch"
    actor_linkage: "identity matching only; no IOC ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  dragos-threat-groups:
    name: "Dragos Threat Groups"
    url: "https://www.dragos.com/threat-groups"
    supported_types: []
    terms: "site terms and access limits"
    license: "verify before redistribution"
    rate_limits: "bounded HTML snapshot"
    attribution_strength: "vendor actor profile"
    normalization: "source record"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine parser/profile conflict"
    actor_linkage: "direct profile identity only; no IOC ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
  unit42-threat-actor-groups:
    name: "Unit 42 Threat Actor Groups"
    url: "https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/"
    supported_types: []
    terms: "site terms and access limits"
    license: "verify before redistribution"
    rate_limits: "bounded HTML snapshot"
    attribution_strength: "vendor actor index"
    normalization: "source record"
    freshness: "90 days"
    retention: "snapshot metadata"
    false_positive: "quarantine alias conflict"
    actor_linkage: "identity matching only; no IOC ownership"
    correction_contact: "https://github.com/WellKnitTech/ThreatActor.info/issues"
    decision: "publish_metadata_only"
