ContrastAPI aggregates vulnerability intelligence from the following sources:
| Source | License | Notes |
|---|---|---|
| NVD (National Vulnerability Database) | Public domain | NIST — U.S. government work |
| GHSA (GitHub Security Advisories) | CC-BY-4.0 | |
| OSV.dev | Apache-2.0 / various | Upstream advisories carry their own licenses |
| EPSS | CC-BY-4.0 | FIRST.org |
| KEV (CISA Known Exploited Vulnerabilities) | Public domain | CISA — U.S. government work |
| ExploitDB | GPL-2.0 | Metadata only (edb_id, author, type, platform, date, source URL). Exploit payloads are not stored or redistributed. |
| SigmaHQ rules | Detection Rule License (DRL) 1.1 | Sigma detection rule corpus served via /v1/sigma/* and sigma_rule_lookup MCP tool. Rules surfaced as-is with full attribution metadata (author, references, rule_id). |