How we build the intelligence picture
The portal aggregates only public information useful for defence. Every item keeps its source, date and confidence level, even when it is turned into an editorial update.
Technical sources
ACN and CSIRT Italia provide national advisories and communications. CISA Known Exploited Vulnerabilities highlights vulnerabilities known to be exploited. NIST NVD provides CVE data and severity. CERT-AGID and CERT-EU add institutional bulletins.
This product uses data from the NVD API but is not endorsed or certified by the NVD.
Historical coverage
The NVD history is updated progressively until it covers the last five years. The CISA KEV catalogue is acquired in full and keeps the entry date of each vulnerability. For communications and sources that only expose recent items, we show only the content actually available: we do not reconstruct missing dates or records.
EudorIA Radar
Radar requires proof of domain control via DNS. Only after verification does it observe public SPF, DMARC, MX, CAA, DNSSEC records, any declared DKIM selectors and the TLS certificate exposed on the standard port. It does not enumerate ports, directories or services and does not attempt to exploit vulnerabilities. Intelligence correlation uses only the domain, company and technologies declared by the user.
Intelligence shared via MISP
For supported MISP feeds we retain acquired technical IOCs in a separate store, with value, source reference, date and retention expiry. STIX publication includes only supported indicators authorised for sharing, after checking event, object and attribute markings and restrictions. Confidential data, credentials and stolen content are not published.
Correlazione con OpenCTI
OpenCTI è la piattaforma con cui consolidiamo e mettiamo in relazione le fonti pubbliche di threat intelligence, come indici ransomware, feed MISP TLP:CLEAR, cataloghi CVE e vittimologia per paese, in un unico grafo di conoscenza. Gli osservabili e le correlazioni che arrivano al portale derivano da qui e conservano fonte, data e livello di confidenza. OpenCTI tratta esclusivamente informazioni pubbliche e non contiene dati dei sistemi del cliente. Per il monitoraggio di caselle e domini, la correlazione confronta i valori dichiarati dal cliente con gli osservabili pubblici presenti in piattaforma, senza esporre indicatori grezzi soggetti a restrizioni.
From source to newsletter
Every issue separates five levels: original news, summary, possible impact, actions to evaluate and applicable measure. Solution benefits are described as expected results, for example reduced exposure, greater visibility, shorter response times or better operational continuity. They are not presented as guarantees.
Evidence and proposal stay separate
A solution is linked to a news item only when there is an understandable technical connection. Any commercial proposal still requires context analysis, a shared perimeter and customer approval.
Ransomware reports
Public ransomware indexes are used only for minimal metadata: named organisation, group attributed by the source, country, dates and public domain. The portal does not expose stolen data, samples or victim content. Every claim stays marked as unverified until it is confirmed by independent sources.
Limits
A report from open sources does not prove an incident. The portal does not replace vulnerability management, incident response or a legal assessment. Operational decisions require independent verification and knowledge of the customer's context.
Separation from the SOC
During informational access EudorIA does not collect data from the customer's systems and does not run scans. Sensors, logging, retention periods, on-call availability and response are defined only under a contracted SOC service.