The core question is simple: what changed, why might it matter, and what evidence can I inspect next?Every product decision should make that chain easier to follow.

01Source-linked

Records point back to their original evidence.

02Time-bounded

Generation and enrichment timestamps stay visible.

03Limit-aware

Missing coverage is disclosed instead of filled with synthetic data.

Methodology

From source record to briefing

01

Collect

Published security material is retrieved from configured sources. A source record is an ingested record; it is not automatically a unique threat or incident.

02

Structure

Records are normalized into fields such as source ID, timestamp, tags, CVE associations, and stable record identifiers where the dataset provides them.

03

Enrich

Some records include AI-assisted summaries or predicted associations. Those transformations are context, not proof, and should be checked against the linked source.

04

Publish

Environment-specific snapshots are presented with their generation time. The public interface does not infer missing historical coverage or create substitute records.

Evidence language

What the labels mean

Source record
One record in a published dataset. Multiple records may describe the same underlying event.
Enriched record
A source record with additional machine-generated structure or summary. Enrichment is not independent verification.
Known exploited
A record tagged or sourced as known exploited in the published artifact. Follow the original authority for current status.
Predicted mapping
An ATT&CK relationship inferred during record review. It is not an official MITRE mapping.
Known limitations

What this product does not claim

  • Record counts are not threat, incident, prevalence, impact, or risk counts.
  • The curated incident library is not exhaustive or statistically representative.
  • Published coverage can differ by environment and date.
  • Source publication times may be unavailable even when retrieval time is known.
  • AI-assisted summaries and predicted mappings can be incomplete or wrong.
  • Always validate operational decisions against primary sources and your own environment.
Ownership

Human judgment remains accountable.

Bryan Oubaita created and owns Baitaphish and publishes its original security education and research. Baitaphish combines human judgment, research curation, repeatable selection rules, and machine-assisted enrichment. Automation can organize evidence; it does not own the consequences of a security decision.

Contact

Contact and corrections

A public reporting inbox is not yet configured. Baitaphish keeps that limitation visible instead of presenting a contact action that cannot be completed. The ownership page records editorial responsibility and the current contact status.

Read the ownership disclosure →