Data

Public data catalogue

Data with its boundaries attached.

Only deliberately public, source-linked HECAVEX datasets and static APIs appear here. Schema, freshness, licence and limitations travel with each entry.

CATALOGUE 1.0.0 · UPDATED 21 AUG 2026

Labs publications

Curated and generated datasets

Catalogue JSON →

Schema 0.2.0 · 14 Aug 2026

Baltic Threat Atlas

Maintained

Selected public-source observations concerning Lithuania, Latvia and Estonia.

Freshness: manual review after source, correction or related-research changes; individual observations retain their dates.

Boundary: not an exhaustive incident census, prevalence measure or live feed.

Schema 1.0.0 / graphs 2.0.0 · 14 Aug 2026

Evidence Pivot case library

Maintained

Published case graphs separating observations, reproducible derivations, assessments and limitations.

Freshness: reviewed when released evidence, transformations or analytical boundaries change.

Boundary: time-bounded cases; relationships do not establish actor identity beyond the stated evidence.

Schema 1.1 · ATT&CK 19.2 · 20 Aug 2026

Enterprise ATT&CK reference

Generated upstream

Browser-ready active techniques, groups and official group-to-technique procedure relationships.

Freshness: regenerated after a reviewed upstream version update; not synchronized in real time.

Boundary: MITRE ATT&CK remains authoritative; these records are reference material, not HECAVEX attribution.

Schema 1.0 · 20 Aug 2026

HECAVEX-reviewed ATT&CK evidence

Maintained

Source-linked technique evidence selected from reviewed public APT Notes profiles.

Freshness: rebuilt after substantive APT Notes evidence or ATT&CK mapping review.

Boundary: a compact publication layer, not a substitute for cited sources or evidence of defensive coverage.

Schemas 1.0–2.0 · 21 Aug 2026

ATT&CK operational material

Maintained

Product-neutral analyst guides, engineering candidates, validation templates and publication governance.

Freshness: lifecycle and review-due state are published in governance and package records.

Boundary: not deployable rules and not proof that an environment detects the mapped behaviour.

Schema 1.0.0 · 14 Aug 2026

OSINT Workbench resources

Maintained

Selected free and free-tier research resources with practical use and evidence cautions.

Freshness: the date records manual review, not continuous provider monitoring.

Boundary: provider access, terms and limits can change; inclusion is not endorsement.

Across HECAVEX

Schema 1.0.0 · static build

APT Notes actor API

Curated actor research records with sources, confidence and review dates. generated_at records build time and every actor carries last_reviewed; there is no continuous update SLA.

Actor index JSON ↗ · Methodology ↗ · CC BY 4.0 boundary ↗

Schema 1 · scheduled best effort

HECAVEX Radar signals

Potential Lithuanian phishing and impersonation candidates. generatedAt and coverage metadata expose publication and sampled-collector freshness; failed or delayed collection is not a benign verdict.

Live JSON ↗ · Methodology ↗ · Source-specific data terms ↗

Publication boundary. This catalogue intentionally excludes private notes, credentials, malware samples, victim data, submissions and quarantined observations. Deployment is default-deny: only paths in the validated public manifest are staged, and every distribution must map to a catalogue entry and licence boundary. Report an exposure through the Labs security policy.