Open source tools and public sources used
Current version: V1 — July 2026
English translation provided for convenience. In case of discrepancy, the French version shall prevail.
Cridenty products rely on open source software and, for behavioral qualification, on public cybersecurity sources. The cited trademarks, content, databases and components remain the property of their respective authors and are used under their licenses or terms of use.
Main open source components
The list below presents the main components used directly. Each product's technical manifests determine the versions that are actually integrated.
- .NET, ASP.NET Core and Entity Framework Core — foundation for services, APIs and desktop applications.
- SQLite — embedded local storage; SQLite is dedicated to the public domain by its authors.
- miniz — embedded compression distributed under the Unlicense / public domain.
- Avalonia — cross-platform desktop user interfaces.
- Dapper and YamlDotNet — data access and YAML catalog processing.
- OkHttp, Kotlin Coroutines and Kotlin Serialization — communications and processing in the Android application.
- ZXing Android Embedded — QR code scanning on Android.
- FIDO2 .NET Library and QRCoder — strong authentication and QR code generation.
- Bouncy Castle — cryptographic primitives and formats.
- Model Context Protocol C# SDK — MCP integrations for the relevant tools.
Cridenty Behavioral Database sources
The Behavioral Database combines Cridenty behavioral catalogs with data from the following sources. Each source retains its own access, reuse, attribution and distribution terms.
- LOLBAS — catalog of legitimate Windows binaries and scripts that may be misused.
- GTFOBins — catalog of Unix tools that may be used in abuse chains.
- URLhaus, ThreatFox, MalwareBazaar and YARAify / YARAhub — feeds operated by abuse.ch.
- Emerging Threats Open — open Suricata network rules.
- Sigma — generic detection rules maintained by SigmaHQ.
- MITRE ATT&CK — adversary tactics and techniques knowledge base.
- Local Cridenty or customer policies — private operator-provided data, not sourced from a public feed.
Commercial components and third-party services
Some products also use commercial components or platform services, including DevExpress and services provided by Microsoft, Apple and Google. They are not presented as open source software on this page and remain subject to their own agreements and terms.
Updates and notices
This inventory evolves with the products. To report a missing attribution or request details about a component and its version, contact contact@cridenty.com.