{
  "schema_version": "1.0.0",
  "updated": "2026-08-21",
  "publisher": "HECAVEX",
  "owner": "Deividas Lis",
  "catalogue_url": "https://labs.hecavex.com/data/",
  "manifest_url": "https://labs.hecavex.com/data/public-manifest.json",
  "licence_url": "https://labs.hecavex.com/licence/",
  "scope": "Deliberately public, source-linked datasets and static APIs published by HECAVEX. Private notes, submissions, credentials, malware samples and quarantined observations are excluded.",
  "publication_policy": "Default deny. Only files named in public-manifest.json are staged below /data/.",
  "licence_boundary": "HECAVEX-authored software is MIT licensed. Original curated data identified by the data terms is CC BY 4.0. Third-party records, trademarks and source material retain their own terms.",
  "datasets": [
    {
      "id": "baltic-threat-atlas",
      "name": "Baltic Threat Atlas",
      "status": "maintained",
      "schema_version": "0.2.0",
      "updated": "2026-08-14",
      "freshness": "The record set exposes a dataset update date; individual observations retain their own dates.",
      "update_policy": "Manual best-effort review when a cited source, correction or related HECAVEX investigation changes.",
      "media_type": "application/json",
      "content_url": "https://labs.hecavex.com/data/atlas/records.json",
      "landing_page": "https://labs.hecavex.com/baltic-threat-atlas/",
      "licence": "https://labs.hecavex.com/licence/#original-data",
      "scope": "Selected public-source cyber observations concerning Lithuania, Latvia and Estonia.",
      "limitation": "Not an exhaustive incident census, prevalence measure or live feed. Source terminology and attribution are preserved."
    },
    {
      "id": "pivot-case-library",
      "name": "Evidence Pivot case library",
      "status": "maintained",
      "schema_version": "1.0.0",
      "graph_schema_version": "2.0.0",
      "updated": "2026-08-14",
      "freshness": "The case index exposes its update date and each graph preserves observation and collection times.",
      "update_policy": "A case is reviewed when its released evidence, transformation or analytical boundary changes.",
      "media_type": "application/json",
      "content_url": "https://labs.hecavex.com/data/pivots/cases.json",
      "landing_page": "https://labs.hecavex.com/pivot-graph/",
      "licence": "https://labs.hecavex.com/licence/#original-data",
      "scope": "Published HECAVEX case graphs separating observations, derivations, assessments and limits.",
      "limitation": "Each case is time-bounded. Graph relationships do not establish actor identity beyond the stated evidence."
    },
    {
      "id": "attack-reference",
      "name": "Enterprise ATT&CK reference catalogue and official procedures",
      "status": "generated from upstream",
      "schema_version": "1.1",
      "framework_version": "19.2",
      "updated": "2026-08-20",
      "freshness": "Framework version and generation date identify the upstream snapshot represented by the files.",
      "update_policy": "Regenerated after a reviewed MITRE Enterprise ATT&CK version update; no real-time synchronization is promised.",
      "media_type": "application/json",
      "content_urls": [
        "https://labs.hecavex.com/data/attack/catalogue/enterprise.json",
        "https://labs.hecavex.com/data/attack/intelligence/official-actor-procedures.json"
      ],
      "landing_page": "https://labs.hecavex.com/attack-map/",
      "licence": "https://attack.mitre.org/resources/terms-of-use/",
      "scope": "A generated browser-ready subset of active Enterprise ATT&CK techniques, groups and official procedure relationships.",
      "limitation": "MITRE ATT&CK is the authoritative source. These generated files are reference material, not HECAVEX attribution."
    },
    {
      "id": "attack-reviewed-evidence",
      "name": "HECAVEX-reviewed ATT&CK evidence",
      "status": "maintained",
      "schema_version": "1.0",
      "updated": "2026-08-20",
      "freshness": "The dataset update date records the latest reviewed export from published APT Notes evidence.",
      "update_policy": "Rebuilt when a represented APT Notes profile, source relationship or ATT&CK mapping is substantively reviewed.",
      "media_type": "application/json",
      "content_url": "https://labs.hecavex.com/data/attack/intelligence/reviewed-evidence.json",
      "landing_page": "https://labs.hecavex.com/attack-map/",
      "licence": "https://labs.hecavex.com/licence/#reviewed-evidence",
      "scope": "Source-linked technique evidence selected from reviewed public APT Notes profiles.",
      "limitation": "A compact publication layer, not a substitute for the cited source and not evidence of defensive coverage."
    },
    {
      "id": "attack-operational-material",
      "name": "ATT&CK operational guides, detection packages and governance",
      "status": "maintained",
      "schema_version": "2.0",
      "updated": "2026-08-21",
      "freshness": "Each package carries lifecycle metadata; governance.json exposes review dates, due states and change history.",
      "update_policy": "Reviewed after relevant ATT&CK changes, validation findings or substantive guide and package revisions.",
      "media_type": "application/json",
      "content_urls": [
        "https://labs.hecavex.com/data/attack/operations/guides.json",
        "https://labs.hecavex.com/data/attack/detections/packages.json",
        "https://labs.hecavex.com/data/attack/governance/governance.json"
      ],
      "landing_page": "https://labs.hecavex.com/attack-map/",
      "licence": "https://labs.hecavex.com/licence/#original-data",
      "scope": "Product-neutral analyst guidance, engineering candidates, validation templates and publication governance.",
      "limitation": "Not deployable rules and not proof that any environment detects the mapped behaviour."
    },
    {
      "id": "osint-resources",
      "name": "OSINT Workbench resources",
      "status": "maintained",
      "schema_version": "1.0.0",
      "updated": "2026-08-14",
      "freshness": "The catalogue date records the last manual review, not continuous provider availability monitoring.",
      "update_policy": "Best-effort review after provider changes, corrections or a scheduled curation pass.",
      "media_type": "application/json",
      "content_url": "https://labs.hecavex.com/data/osint/resources.json",
      "landing_page": "https://labs.hecavex.com/osint-workbench/",
      "licence": "https://labs.hecavex.com/licence/#original-data",
      "scope": "A curated directory of free and free-tier public research resources with use and evidence cautions.",
      "limitation": "Provider access, terms and limits can change; inclusion is not endorsement."
    }
  ],
  "related_datasets": [
    {
      "id": "apt-notes-actors",
      "name": "APT Notes actor API",
      "publisher": "HECAVEX",
      "status": "maintained",
      "schema_version": "1.0.0",
      "freshness_source": "The API generated_at field records build time; each actor record carries last_reviewed.",
      "freshness": "Static build output with per-record review dates; no continuous update SLA.",
      "update_policy": "Republished on a successful APT Notes build after substantive record or source changes.",
      "media_type": "application/json",
      "content_url": "https://apt.hecavex.com/api/actors.json",
      "methodology": "https://apt.hecavex.com/about/methodology/",
      "licence": "https://apt.hecavex.com/licence/",
      "limitation": "Curated research records, not a live IOC feed or exhaustive actor directory."
    },
    {
      "id": "radar-live-signals",
      "name": "HECAVEX Radar live signals",
      "publisher": "HECAVEX",
      "status": "experimental, best effort",
      "schema_version": "1",
      "freshness_source": "The snapshot generatedAt field and coverage metadata report the successful publication and collector windows.",
      "freshness": "Scheduled best-effort snapshot; delayed, failed and sampled collection remain visible in the payload and methodology.",
      "update_policy": "The publisher replaces the snapshot only after schema, safety and sharp-drop checks; there is no continuous-monitoring SLA.",
      "media_type": "application/json",
      "content_url": "https://radar.hecavex.com/data/radar.json",
      "methodology": "https://radar.hecavex.com/methodology/",
      "licence": "https://radar.hecavex.com/docs/#data-terms",
      "limitation": "Potential phishing and impersonation signals are candidates, not maliciousness verdicts; source-specific rights still apply."
    }
  ]
}
