Collect
Retrieve structured records from recognised public security sources.
Sources are the starting point—not the finished page. We apply completeness checks, evidence labels and practitioner-focused analysis before a record is eligible for search indexing.
Every content type follows the same core controls, with stricter evidence requirements for claims that cannot be independently confirmed.
Retrieve structured records from recognised public security sources.
Clean identifiers, dates, affected products, sectors and source links.
Evaluate severity, completeness, exploitation and evidence strength.
Add actionable context without extending claims beyond the source data.
Index useful records; keep incomplete and weak pages out of search.
NVD records are combined with CVSS, affected-product ranges, CWE, EPSS and CISA KEV status when available.
NVD · FIRST EPSS · CISA KEVHave I Been Pwned catalogue data is supplemented with exposure analysis based on account volume and reported data classes.
Have I Been Pwnedransomware.live entries reproduce attacker-controlled leak-site claims. A listing is never presented as independent confirmation of a breach.
ransomware.live · leak-site evidenceCommunity feeds such as URLhaus and Feodo Tracker provide time-bound observations, not proof that an indicator remains malicious.
abuse.ch community feedsShellCodeX does not generate text for every database row. A single shared daily budget is used only for records likely to add meaningful search and reader value.
Default cap: 5 records per day. The hard application ceiling is 10. Failed calls also count toward the cap to prevent accidental token overspend.
AI-assisted analyst notes are constrained to supplied structured facts and labelled on the page. Original long-form articles are researched separately and always saved as unpublished drafts.