THEORY is original work by Threatcraft, built from scratch. No existing repositories were forked. The following data sources, APIs, libraries, and tools made it possible.
MITRE ATT&CK The foundational framework THEORY is built around. TTP data, technique descriptions, actor profiles, campaigns, and malware relationships are sourced from the ATT&CK STIX bundle, published by The MITRE Corporation under the CC BY 4.0 license. THEORY is not affiliated with or endorsed by MITRE.
CISA Cybersecurity Advisories Advisories and actor attribution data from the U.S. Cybersecurity and Infrastructure Security Agency, a U.S. government agency. Content is in the public domain.
Malpedia Malware family database maintained by Fraunhofer FKIE. Used for malware descriptions, aliases, and YARA rule counts. Accessed via their public API.
AlienVault OTX Threat intelligence pulses and IOC data from AT&T Cybersecurity's Open Threat Exchange. Accessed via their free public API.
SigmaHQ Community detection rules mapped to ATT&CK techniques. Maintained by the Sigma project contributors. Published under the Detection Rule License (DRL) 1.1. THEORY clones the SigmaHQ repository locally and queries it offline — no Sigma rules are redistributed.
ThreatFox IOC database from abuse.ch. Used for malware-attributed indicators of compromise. Accessed via their free public API.
CyberMonitor APT Campaign Collection
Community-maintained collection of historical APT campaign reports. Used as an optional offline context source when --update-bundles is run. Published under Apache 2.0.
THEORY's vendor intelligence feature aggregates publicly available RSS feeds from security research blogs including Mandiant, Google TAG, Unit 42 (Palo Alto Networks), Microsoft MSTIC, CrowdStrike, Cisco Talos, Recorded Future, Kaspersky GReAT (Securelist), Check Point Research, SentinelOne Labs, Elastic Security Labs, Proofpoint, Wiz, Datadog Security Labs, Sophos, The DFIR Report, Red Canary, Krebs on Security, Bleeping Computer, and others.
All articles are fetched from their original sources and attributed by name and URL in every dossier. THEORY does not reproduce or redistribute article content — it generates original LLM syntheses with source attribution and links. All rights to original articles remain with their respective publishers.
| Library | Author / Maintainer | License | Use in THEORY |
|---|---|---|---|
| Rich | Will McGugan / Textualize | MIT | Terminal dossier rendering |
| requests | Kenneth Reitz / PSF | Apache 2.0 | HTTP feed fetching |
| python-dotenv | Saurabh Kumar | BSD-3-Clause | .env configuration loading |
| PyYAML | Kirill Simonov | MIT | feeds.yaml parsing |
| stix2 | OASIS Open | BSD-3-Clause | STIX 2.1 export |
Standard library modules (concurrent.futures, xml.etree, urllib, json, re, argparse, logging, and others) are part of the Python standard library, maintained by the Python Software Foundation under the PSF License.
THEORY's synthesis engine supports multiple LLM providers. None are required to run THEORY — they are optional for the vendor source and actor overview features.
- Anthropic Claude — via the Anthropic Messages API
- OpenAI — via the OpenAI Chat Completions API
- Ollama — for fully local, offline inference
THEORY was developed with assistance from Claude (Anthropic), which helped design the architecture, write and debug code across all phases, and draft documentation throughout the project.
Python — Python Software Foundation License pytest — MIT License ruff — MIT License git — GPL-2.0 git-filter-repo — MIT License — used to sanitize repository history before public release
THEORY was built in the spirit of the open-source security community — the analysts, researchers, and engineers who publish their work freely so that everyone can build better defenses. Special thanks to the maintainers of every data source and library listed above for keeping their work public and free.
THEORY is not affiliated with, endorsed by, or sponsored by any of the organizations listed above.