BLAST·RADIUS

Attribution and third-party notices

BLAST RADIUS is built on four external frameworks, all of which permit redistribution and adaptation. This file records what is used, under which terms, and what each licence requires of us.

BLAST RADIUS is not affiliated with, sponsored by, or endorsed by The MITRE Corporation, MITRE Engenuity, NIST, or the National Cyber Security Centre.


Summary

Source Licence Adaptation permitted Used for
MITRE ATT&CK® v19.1 MITRE terms of use, royalty-free Yes, with copyright designation Technique cards
MITRE ATLAS™ Public release, distribution unlimited Yes ATLAS expansion
NIST SP 800-53 Rev 5 US Government work, public domain Yes, unrestricted Control cards
CTID 800-53 → ATT&CK mappings Apache License 2.0 Yes, with notice The detection mechanic
NCSC CAF v4.0 Open Government Licence v3.0 Yes, with attribution Debrief scoring

Everything the project ships is redistributable. There are no carve-outs, no verbatim-only constraints, and no files that must be kept out of the repository for licensing reasons.


MITRE ATT&CK®

Technique identifiers, names and descriptions on technique cards come from MITRE ATT&CK Enterprise v19.1.

© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

ATT&CK® and MITRE ATT&CK® are registered trademarks of The MITRE Corporation. Per MITRE's branding requirements the first written reference is "MITRE ATT&CK®" and subsequent references are "ATT&CK" — capitalised, unhyphenated, unabbreviated. The mark does not appear in this project's name, logo or domain.

https://attack.mitre.org/resources/legal-and-branding/terms-of-use/

MITRE ATLAS™

Technique content in the ATLAS expansion comes from MITRE ATLAS.

© 2026 The MITRE Corporation. Approved for public release; distribution unlimited.

https://atlas.mitre.org/

NIST SP 800-53 Rev 5

Control identifiers, names and text on control cards derive from NIST Special Publication 800-53 Revision 5.

NIST SP 800-53 Rev. 5 is a work of the U.S. Government and is in the public domain under 17 U.S.C. §105.

No licence restrictions apply. Card text is written to fit the card rather than reproduced verbatim, and the control identifier on every card lets players trace it back to the source.

https://csrc.nist.gov/projects/risk-management/sp800-53-controls

CTID NIST 800-53 to ATT&CK mappings

The control-to-technique relationship that drives detection in this game comes from the MITRE Engenuity Center for Threat-Informed Defense.

NIST 800-53 to ATT&CK mappings © MITRE Engenuity Center for Threat-Informed Defense. Licensed under the Apache License, Version 2.0. http://www.apache.org/licenses/LICENSE-2.0

Apache 2.0 permits redistribution and derivative works provided the licence and notice are retained, which they are in every generated data file.

https://ctid.mitre.org/projects/nist-800-53-control-mappings/

NCSC Cyber Assessment Framework v4.0

The debrief scoring sheet uses CAF objective, principle and contributing outcome identifiers and titles.

Contains public sector information licensed under the Open Government Licence v3.0. © Crown copyright. https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/

OGL v3.0 permits copying, adapting and commercial exploitation with attribution. The evidence prompts and scoring guidance attached to each principle are original to this project.

https://www.ncsc.gov.uk/collection/caf


Version reconciliation

CTID publishes mappings against ATT&CK 16.1; the technique cards are built from ATT&CK v19.1. data/build/extract.py reconciles the two and reports how many mapping edges point at techniques retired or restructured since 16.1. Retired edges are excluded from play and the count is printed on every build, so drift between releases is visible rather than silent.


Original content

The following are original to this project and licensed under LICENSE.md:


Source files are not redistributed

sources/ is git-ignored. Download the frameworks from their publishers — see the README for the current list and the expected filenames.


This file sets out a considered reading of five licences. It is not legal advice and was not written by a lawyer. Every source permits redistribution, so the position is a straightforward one, but a solicitor's review before public launch remains sensible.

← Back to overview