MITRE
The not-for-profit that maintains ATT&CK, which it started in 2013 from internal research and now revises twice a year from public threat intelligence and incident reporting (source: its own FAQ).
Its position in the field is unusual and worth stating plainly: MITRE publishes the taxonomy that vendors describe their products in, and also runs the evaluations those vendors are measured by. The spoke holds a first-party account of the taxonomy and a peer-reviewed, independent study of how the taxonomy is used in practice (endpoint-detection-attack-coverage) — the evaluations programme itself is unread here, so nothing is claimed about it.