{
  "$schema": "./adoption-evidence.schema.json",
  "model_version": "1.0.0",
  "updated_at": "2026-07-21",
  "methodology": "Only verified, publication-approved evidence may appear publicly. Merged upstream records are independently public evidence of acceptance, not proof of deployment, active use, or operational outcome.",
  "entries": [
    {
      "id": "misp-galaxy-pr-1227",
      "product": "Cyber Av3ngers threat-actor research",
      "evidence_type": "accepted-integration",
      "organization": "MISP Project",
      "visibility": "independently-public",
      "permission_status": "not-required-public-record",
      "verification_status": "verified",
      "source": "Public merged upstream pull request",
      "verified_at": "2026-07-21",
      "use_case": "Contribute a threat-actor record update to the MISP Galaxy knowledge base.",
      "outcome": "The upstream maintainers merged pull request 1227.",
      "limitations": "Merge proves upstream acceptance of the contribution; it does not measure downstream deployments or operational use.",
      "quote": null,
      "quote_approved": false,
      "supporting_url": "https://github.com/MISP/misp-galaxy/pull/1227",
      "publication_status": "published"
    },
    {
      "id": "awesome-detection-engineering-pr-28",
      "product": "Threat Matrix and CTI Analyst Field Manual",
      "evidence_type": "accepted-integration",
      "organization": "awesome-detection-engineering",
      "visibility": "independently-public",
      "permission_status": "not-required-public-record",
      "verification_status": "verified",
      "source": "Public merged upstream pull request",
      "verified_at": "2026-07-21",
      "use_case": "Submit detection-engineering and CTI resources for upstream review.",
      "outcome": "The upstream maintainers merged pull request 28.",
      "limitations": "The merge is curation evidence, not a claim that the resources are deployed in a production SOC.",
      "quote": null,
      "quote_approved": false,
      "supporting_url": "https://github.com/infosecB/awesome-detection-engineering/pull/28",
      "publication_status": "published"
    },
    {
      "id": "awesome-yara-pr-78",
      "product": "AIDebug",
      "evidence_type": "accepted-integration",
      "organization": "awesome-yara",
      "visibility": "independently-public",
      "permission_status": "not-required-public-record",
      "verification_status": "verified",
      "source": "Public merged upstream pull request",
      "verified_at": "2026-07-21",
      "use_case": "Submit an AI-assisted malware-analysis and YARA-oriented tool for upstream review.",
      "outcome": "The upstream maintainers merged pull request 78.",
      "limitations": "The merge demonstrates external curation only; it does not establish package usage or active users.",
      "quote": null,
      "quote_approved": false,
      "supporting_url": "https://github.com/pedramamini/awesome-yara/pull/78",
      "publication_status": "published"
    },
    {
      "id": "awesome-soc-pr-20",
      "product": "AdversaryGraph",
      "evidence_type": "accepted-integration",
      "organization": "awesome-soc",
      "visibility": "independently-public",
      "permission_status": "not-required-public-record",
      "verification_status": "verified",
      "source": "Public merged upstream pull request",
      "verified_at": "2026-07-21",
      "use_case": "Submit the CTI-to-detection platform for upstream SOC-resource review.",
      "outcome": "The upstream maintainers merged pull request 20.",
      "limitations": "The merge is third-party curation evidence; it is not evidence of a production AdversaryGraph deployment.",
      "quote": null,
      "quote_approved": false,
      "supporting_url": "https://github.com/cyb3rxp/awesome-soc/pull/20",
      "publication_status": "published"
    }
  ]
}
