Before the vulnerability record
Threat Activity
Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.
Official-source intelligence
Evidence, not prediction.
Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.
Threat activity is unavailable
The intelligence service could not complete the request.