# basicsecurity.net > The open, cited, lab-proof threat-record evidence layer for the known-exploited vulnerability — every claim traces to a named public source. basicsecurity.net turns the CISA KEV catalogue and its cited advisories into a discoverable, machine-readable record of what each known-exploited flaw actually lets an attacker do. It runs cite-or-die: no fabricated claims, and nothing ships that cannot be traced back to a named source in the underlying record. Every number on the site is recomputed deterministically from that cited corpus per build. ## Key surfaces - [Threat records](https://basicsecurity.net/) — 1,662 known-exploited-vulnerability record pages, one per CVE, each with per-clause citations. Index/exploitability map at the homepage. - [Attacker outcomes](https://basicsecurity.net/outcomes/) — editorial stories and the five canonical attacker-outcome narratives (front door, keys to the kingdom, lateral reach, data at risk, lights out). - [Threat actors](https://basicsecurity.net/actors/) — cited actor cards (MITRE ATT&CK intrusion sets), advisory-backed attribution only. - [Contributors](https://basicsecurity.net/contributors/) — the CNAs and named finders behind the records, as discoverable profiles with stats recomputed from the corpus. - [KEV / exploitability map](https://basicsecurity.net/) — the homepage: every record broken out by exploitability, ransomware association, attack surface, and weakness class. ## Machine-readable index - [Sitemap](https://basicsecurity.net/sitemap.xml) — every rendered page, with `lastmod` dates. - [Atom feed](https://basicsecurity.net/feed.xml) — published editorial stories, newest first. ## Structured data Every threat-record page embeds schema.org JSON-LD in its ``: an `Article` on every record, plus a `ClaimReview` wherever a confirmed, cited actor attribution exists (the attributing advisory is the claim author; basicsecurity.net is the reviewer). Story and outcome pages carry `NewsArticle`, actor and contributor pages carry `Article`, and the homepage carries `Organization` + `WebSite`. This JSON-LD, together with the Atom feed and sitemap, is the citable, machine-readable facts surface — no separate data dump is needed; the facts live on the pages, next to their citations. ## How to cite - Cite the specific page URL (e.g. `https://basicsecurity.net/threat/.html` for a record, or the `/outcomes/story//` URL for a story) AND the underlying named advisory source linked on that page. Every assertion is backed by a cited source — cite both the record and its source, not basicsecurity.net alone. - The corpus currently covers 1,662 known-exploited-vulnerability records (compiled 2026-08-10). - Actor attribution is advisory-backed (confirmed-tier) only; reported or inferred links are surfaced as coverage findings, never asserted as attribution. Do not cite an inferred link as confirmed.