LiveActive security incident?Get immediate response
Open intelligence methodology

Reviewed CVE to MITRE ATT&CK mappings

A reproducible export of official and named-human-reviewed mappings. Raw model suggestions never enter this public dataset.

Scope and inclusion policy

The export includes mappings marked official or manual_reviewed. Each row identifies the CVE, ATT&CK technique, domain, mapping type, confidence, rationale, evidence, generation time, and review time where applicable.

Inferred mappings remain private until a named reviewer verifies the relationship against the displayed CVE and ATT&CK source versions. Absence from the dataset does not prove that no relationship exists.

Data dictionary

cveId
The canonical CVE Program identifier.
attackExternalId
The public ATT&CK identifier, such as T1059.
mappingType
official or manual_reviewed; unreviewed inference is excluded.
confidence
Low, medium, or high confidence in the documented relationship.
rationale / evidence
The bounded explanation and source evidence supporting the mapping.
generatedAt / reviewedAt
Machine-generation and named-review timestamps.

Attribution, versioning, and corrections

CVE facts remain subject to the CVE Program terms. ATT&CK material remains subject to the MITRE ATT&CK data license. Glexia-authored rationale is identified separately.

The JSON envelope carries a semantic schema version and latest material timestamp. Consumers should retain source identifiers and cite this methodology URL.

Report disputed mappings through the corrections process. Accepted material changes invalidate stale review state and flow into a later export.