for journalists + analysts

PRESSPress kit

Fact sheet for citing the SQUR cybersecurity knowledge base — built at squr.ai, authored by Adam Lundqvist, Founder at SQUR.

Fact sheet

Indexed nodes26,045across 14 frameworks + 16 entity types
Typed live edges55,000+corroborator-scored, evidence-cited
Compliance frameworks mapped14DORA / NIS2 / GDPR / ISO 27001 / NIST CSF / OWASP / CIS / PCI DSS / AI Act / CRA / TIBER-EU / ISO 27701 / OWASP API / OWASP LLM
MITRE ATT&CK techniques160 + 427 sub-techniquesEnterprise v14
CWE weaknesses970MITRE CWE 4.x XML
CVEs (NVD + CISA KEV + EPSS)17,8741,606 KEV-flagged
ATLAS adversarial-ML techniques101 + 69 sub-techniques16 tactics
D3FEND defensive techniques2717 defensive tactics
CAPEC attack patterns615Meta / Standard / Detailed abstraction
MISP-Galaxy threat actors99487% MITRE Group crosswalk
HIBP disclosed breaches978aggregate metadata only — no PII
LOL binaries (LOLBAS + GTFOBins)712function-category → ATT&CK mappings

How it’s built

SQUR uses the ODKE+ pipeline (Open Domain Knowledge Extraction +, arXiv:2509.04696) ported for cybersecurity sources. Each typed edge carries a deterministic ID (sha256(from|predicate|to)[:16]), a corroborator score (1 source → 0.65, 2 → 0.80, 3 → 0.95, 4+ → 1.0, authoritative-source override to 1.0), and an evidence-reference array citing the source URL + accessed date for every claim. Vertex Gemini 2.5 Flash with Google Search grounding verifies candidate edges; promotion threshold is 0.85.

Deterministic enrichers handle data quality (LOLBin function-category mapping, ThreatActor body templating, CAPEC structured-data footers, Software Group attribution joins). Every node carries a 0–100 schemaCompleteness score; nodes below 60 are tracked in a public healing-queue at /about/data-quality.

Citation-ready surfaces

Public API (JSON)

Seven read-only, unauthenticated, CORS-open JSON endpoints for assistants, dashboards, and citation tooling — no API key required. Every response carries schema_version: 1 (additive-only), generated_at, and base_url.

RouteQuery paramsReturns
/api/statsnonecorpus (total_nodes, by_type), edges (live/candidate/legacy_mitre_stix), compliance (frameworks, controls), freshness (sources_tracked, within_sla, breached, unknown), data_quality (weighted_avg_completeness, healing_queue_total)
/api/facetsnonetotal_nodes, facets.type[] and facets.framework[] — each a { value, count }[] sorted by count desc
/api/crosswalknone — global matrixframework_count, frameworks[], cells[] (the full compliance × control crosswalk)
/api/nodeslug (required)node, provenance (source_url, last_verified_at, confidence, freshness_status)
/api/edgesslug (required), direction=in|out|both (default both), predicate (csv), tier=live|candidate (default live), limit 1-200 (default 200)query (echoed params), count, edges[]
/api/graphslug (required), hops=1|2 (default 1), predicate (csv), limit 1-200 (default 60)query, focus, node_count, edge_count, total_edges, predicate_histogram, nodes[], edges[]
/api/searchq (required), type (csv), page (default 1), limit 1-50 (default 20), mode=keyword|hybrid (default keyword)query, total, matching, page_count, type_histogram, hits[]

Contact

For interviews, deep-dive briefings, or to flag corrections: press@squr.ai. For citation in academic work or regulatory submissions, prefer the live URL on this site over screenshots — the corpus refreshes weekly via the graph-fill orchestrator.

Licence: cs-graph editorial content is CC-BY-SA 4.0; embedded data retains its original source licence (MITRE ATT&CK / CWE: Apache 2.0; MISP-Galaxy: CC0; HIBP: aggregate metadata under HIBP terms; EUR-Lex: EU public sector licence).

All figures are SSR-rendered live from the canonical Firestore corpus at squr-aios-tooling/cs-graph; numbers above are session-stable snapshots. For citation prefer the live-data pages linked below.