Methodology
How we verify — and why you can trust it
A threat-intelligence site is worth only as much as its sources and its honesty about its own uncertainty. This page explains, plainly, where the data comes from, how we verify it, and what we do when we get something wrong.
How we verify, in four steps
- 1Authoritative sources
Only agency advisories, reports from the vendors who ran the incident, MITRE pages and the CVE registry. At least two independent sources.
- 2Checked against the official registry
Every CVE is checked against the CVE Program registry: if it isn't PUBLISHED, we don't treat it as confirmed.
- 3Confirmed or rejected
The VulnFeed pipeline assigns each item a status and records the reason in an audit log. No valid status, no publication.
- 4Published with the sources
Primary sources are cited at the foot of every page and uncertainty is stated in the text. ATT&CK IDs are copied, never inferred.
Primary sources, always
Every dossier is built on verified primary sources: advisories from CISA, FBI, NCSC and ENISA; reports from the vendors who ran the incident response; official MITRE ATT&CK pages; records from the official CVE registry. The non-negotiable rule is at least two independent sources per dossier. If solid material isn't there, the dossier doesn't ship.
Every CVE is checked against the official registry
We don't trust a headline or an aggregator. Every cited CVE-ID is checked against the official CVE Program registry (cveawg.mitre.org): if it isn't PUBLISHED, we don't treat it as confirmed. This check is automated by VulnFeed, our internal pipeline, which assigns each item a status — confirmed, pre-disclosure, pending-registry, or rejected — and records the reason in an auditable log.
ATT&CK IDs are copied, not inferred
MITRE ATT&CK technique identifiers are copied from the advisories that list them. When a mapping is our own reasoned judgment, we say so explicitly in the text: we never pass a deduction off as an official fact.
Uncertainty is stated in the body
Disputed attribution, a single source, a CVSS not yet validated by NVD, diverging CNA scores: we write it inside the article. We prefer a dossier that admits what it doesn't know to one that fakes certainty.
Defensive, not offensive
We describe tactics and techniques at the same level of detail as a public advisory. We do not publish exploit code, payloads or step-by-step exploitation instructions.
Transparency about AI
Research and drafting are AI-assisted, and the video narration is synthetic — declared as such on TikTok too. Automation does not touch the rule above: every published fact is verified against the primary sources cited at the foot of the page. Editorial accountability stays human.
Authorized sources
Ingestion is allowed only from these sources.
| Source | Role |
|---|---|
| CISA KEV | Exploited in the wild |
| CISA / FBI / NCSC / ENISA | Official agency advisories |
| Registro CVE Program | Ground truth: official state of each CVE |
| NVD (NIST) | CVSS / CPE enrichment |
| EUVD (ENISA) | EU vulnerability database |
| GitHub Advisory / ZDI | Authoritative CNAs |
| Report dei vendor IR | Vendor incident-response reports |
| MITRE ATT&CK | Tactics & techniques mapping |
Correction policy
If a dossier changes after publication — a source retracts, a CVSS is revised, an attribution collapses — the correction is written into the dossier with its date, and the page shows “Updated on …”. The dateModified field in the structured data follows that date. We don't rewrite history quietly. Error reports are welcome by email.
Report an error. Found an inaccuracy or a better source? Email me: civiero.riccardo03@gmail.com