Source-reviewed practitioner knowledge base

Cybersecurity Knowledge Base and Practitioner Field Guides

A practitioner-oriented cybersecurity knowledge system connecting concepts, evidence, workflows, laboratories, and operational handoffs. Eleven connected disciplines take you from cybersecurity concepts to reviewable operational work.

Eleven domains · maintained practitioner guides

Last reviewed

Cross-domain knowledge tools

Shared module · ATT&CK Enterprise 19.1

MITRE ATT&CK Knowledge Mesh

Explore 697 techniques through official groups, mitigations, detection strategies, and analytics, then follow governed inline routes into the most relevant practitioner modules across all eleven domains.

Use it for: behavior-led learning, CTI pivots, detection planning, adversary emulation scoping, mitigation review, and evidence-aware cross-domain study.

Explore the matrix →

Domains

Each guide has one canonical purpose and links to the neighboring disciplines that consume or produce its evidence. Every page includes a table of contents, practical workflows, case studies or worked examples, labs, source links, AI-use boundaries, and acceptance criteria.

Domain 01

Cyber Threat Intelligence (CTI)

Turning raw data about adversaries into decisions: the intelligence cycle, ATT&CK, the Diamond Model, actor tracking, and how CTI feeds detection engineering.

10 modules ~55 min Foundation to practitioner Version 1.0 Reviewed 27 Jul 2026

For: Intelligence analysts, threat hunters, and detection engineers

  • intelligence requirements
  • ATT&CK
  • actor research
  • detection handoff
Practitioner guide live Open syllabus →
Domain 02

Red Team & Offensive Security

Adversary emulation, penetration testing, and exploit tradecraft: recon, initial access, privilege escalation, lateral movement, and reporting.

14 modules ~112 min Practitioner to advanced Version 1.0 Reviewed 27 Jul 2026

For: Authorised security testers, red teams, and purple teams

  • authorization
  • adversary emulation
  • validation
  • reporting
Practitioner guide live Open syllabus →
Domain 03

Blue Team & Defensive Security

SOC operations, detection engineering, threat hunting, and incident handling: the discipline of finding and stopping what red team simulates.

14 modules ~55 min Foundation to practitioner Version 1.0 Reviewed 27 Jul 2026

For: SOC analysts, detection engineers, and threat hunters

  • SOC operations
  • detection engineering
  • threat hunting
  • validation
Practitioner guide live Open syllabus →
Domain 04

Vulnerability Research & Exploit Development

Finding and understanding software flaws: fuzzing, memory corruption classes, static/dynamic analysis, and responsible disclosure.

14 modules ~44 min Practitioner to advanced Version 1.0 Reviewed 27 Jul 2026

For: Security researchers, exploit developers, and product-security teams

  • fuzzing
  • static analysis
  • exploitability
  • disclosure
Practitioner guide live Open syllabus →
Domain 05

Malware Analysis & Reverse Engineering

Static and dynamic triage, unpacking, disassembly, and behavioral analysis of malicious code, from first-look triage to full reverse engineering.

14 modules ~29 min Practitioner to advanced Version 1.0 Reviewed 27 Jul 2026

For: Malware analysts, reverse engineers, and incident responders

  • reverse engineering
  • debugging
  • YARA
  • defensive handoff
Practitioner guide live Open syllabus →
Domain 06

Secure Code & Application Security

Secure design, threat modeling, identity, authorization, API and browser controls, supply-chain assurance, AI-system boundaries, testing, release evidence, and remediation.

14 modules ~27 min Foundation to practitioner Version 1.0 Reviewed 27 Jul 2026

For: Application-security engineers, developers, and product teams

  • threat modeling
  • authorization
  • supply chain
  • secure delivery
Practitioner guide live Open syllabus →
Domain 07

Digital Forensics & Incident Response (DFIR)

Incident readiness, defensible evidence handling, endpoint, disk, memory, network, cloud, identity and malware forensics, timeline reconstruction, containment, recovery, reporting, labs, and controlled AI assistance.

14 modules ~32 min Practitioner to advanced Version 1.0 Reviewed 27 Jul 2026 Baseline: NIST SP 800-61 Rev. 3

For: Incident responders, forensic analysts, and SOC leads

  • evidence integrity
  • memory forensics
  • cloud evidence
  • incident response
Practitioner guide live Open syllabus →
Domain 08

Cloud Security

Shared responsibility, landing zones, human and workload IAM, network and data protection, IaC, containers, Kubernetes, multi-cloud detection and response, SaaS, suppliers, and AI workloads.

14 modules ~35 min Practitioner Version 1.0 Reviewed 27 Jul 2026

For: Cloud-security engineers, architects, and incident responders

  • IAM
  • Kubernetes
  • cloud detection
  • incident response
Practitioner guide live Open syllabus →
Domain 09

Governance, Risk & Compliance (GRC)

Cyber governance, scenario-based risk, frameworks, policy and control design, evidence and audit, legal and contractual obligations, suppliers, privacy, resilience, metrics, product assurance, and AI governance.

14 modules ~36 min Foundation to practitioner Version 1.0 Reviewed 27 Jul 2026

For: Security leaders, risk owners, auditors, and control operators

  • governance
  • risk assessment
  • control evidence
  • AI governance
Practitioner guide live Open syllabus →
Domain 10

OSINT & Reconnaissance

Authorized and ethical collection, search and archives, DNS/RDAP/certificates, internet exposure, applications, organizations, public code, media verification, threat infrastructure, automation, AI assistance, evidence, and reporting.

14 modules ~42 min Foundation to practitioner Version 1.0 Reviewed 27 Jul 2026

For: OSINT investigators, intelligence analysts, and security researchers

  • public-source collection
  • infrastructure
  • verification
  • evidence
Practitioner guide live Open syllabus →
Domain 11

AI Security

Securing the whole AI system: threat modeling, data and retrieval integrity, model supply chain, prompt injection, agents and MCP, adversarial testing, monitoring, incident response, and governance.

14 modules ~20 min Practitioner to advanced Version 1.0 Reviewed 27 Jul 2026 Baseline: NIST AI RMF, OWASP GenAI Security Project, MITRE ATLAS

For: AI engineers, application-security teams, security architects, red teams, defenders, and risk owners

  • AI threat modeling
  • prompt injection
  • agent security
  • AI assurance
Practitioner guide live Open syllabus →

Cross-domain learning and operational pathways

Cybersecurity work crosses team boundaries. These routes show which guide produces the evidence, decision, or control consumed by the next one.

Intelligence to detection

Requirement → context → tested analytic

CTI defines the question, OSINT collects attributable public evidence, and the Blue Team guide turns supported behavior into telemetry, hunting, and validation.

Exposure to remediation

Candidate surface → validated weakness → durable fix

OSINT identifies candidate external assets, Vulnerability Research establishes root cause and affected versions, and Application Security verifies the remediation and regression controls.

Adversary to evidence

Authorized simulation → detection → investigation

Red Team defines an authorized behavior and proof, Blue Team validates visibility, and DFIR with Malware Analysis preserves and explains the resulting evidence.

Architecture to assurance

Cloud design → secure delivery → governed evidence

Cloud Security assigns shared responsibilities, Secure Code integrates product and pipeline controls, and GRC connects objectives, risk, control ownership, testing, and evidence.

Start with the work you need to do

These routes connect selected chapters across multiple guides. They are practical starting points, not mandatory curricula.

How the eleven domains connect

This map is generated from cross-domain links in the field guides. Select an icon to open that domain; select a connection to follow one of the underlying routes.

11 practitioner domains45 unique relationships81 documented routes
Cyber Knowledge cross-domain relationship map Eleven color-coded security domain icons surround the Cyber Knowledge hub. Lines represent unique relationships derived from links in the field guides. A complete text equivalent follows the diagram. Cyber Threat Intelligence (CTI) ↔ AI Security Cyber Threat Intelligence (CTI) ↔ Red Team & Offensive Security Cyber Threat Intelligence (CTI) ↔ Blue Team & Defensive Security Cyber Threat Intelligence (CTI) ↔ OSINT & Reconnaissance Cyber Threat Intelligence (CTI) ↔ Governance, Risk & Compliance (GRC) Red Team & Offensive Security ↔ Blue Team & Defensive Security Red Team & Offensive Security ↔ OSINT & Reconnaissance Red Team & Offensive Security ↔ Governance, Risk & Compliance (GRC) Red Team & Offensive Security ↔ Vulnerability Research & Exploit Development Red Team & Offensive Security ↔ Secure Code & Application Security Red Team & Offensive Security ↔ Cloud Security Red Team & Offensive Security ↔ Digital Forensics & Incident Response (DFIR) Red Team & Offensive Security ↔ AI Security Blue Team & Defensive Security ↔ Vulnerability Research & Exploit Development Blue Team & Defensive Security ↔ Governance, Risk & Compliance (GRC) Blue Team & Defensive Security ↔ OSINT & Reconnaissance Blue Team & Defensive Security ↔ Cloud Security Blue Team & Defensive Security ↔ Digital Forensics & Incident Response (DFIR) Blue Team & Defensive Security ↔ Secure Code & Application Security Blue Team & Defensive Security ↔ AI Security Vulnerability Research & Exploit Development ↔ Malware Analysis & Reverse Engineering Vulnerability Research & Exploit Development ↔ Governance, Risk & Compliance (GRC) Vulnerability Research & Exploit Development ↔ Secure Code & Application Security Vulnerability Research & Exploit Development ↔ AI Security Malware Analysis & Reverse Engineering ↔ Secure Code & Application Security Malware Analysis & Reverse Engineering ↔ Digital Forensics & Incident Response (DFIR) Malware Analysis & Reverse Engineering ↔ Cyber Threat Intelligence (CTI) Malware Analysis & Reverse Engineering ↔ AI Security Secure Code & Application Security ↔ Digital Forensics & Incident Response (DFIR) Secure Code & Application Security ↔ Governance, Risk & Compliance (GRC) Secure Code & Application Security ↔ Cloud Security Secure Code & Application Security ↔ AI Security Digital Forensics & Incident Response (DFIR) ↔ Cloud Security Digital Forensics & Incident Response (DFIR) ↔ Governance, Risk & Compliance (GRC) Digital Forensics & Incident Response (DFIR) ↔ Cyber Threat Intelligence (CTI) Digital Forensics & Incident Response (DFIR) ↔ Vulnerability Research & Exploit Development Cloud Security ↔ Governance, Risk & Compliance (GRC) Cloud Security ↔ OSINT & Reconnaissance Cloud Security ↔ AI Security Governance, Risk & Compliance (GRC) ↔ OSINT & Reconnaissance Governance, Risk & Compliance (GRC) ↔ AI Security OSINT & Reconnaissance ↔ AI Security OSINT & Reconnaissance ↔ Secure Code & Application Security OSINT & Reconnaissance ↔ Digital Forensics & Incident Response (DFIR) AI Security ↔ Digital Forensics & Incident Response (DFIR) 01 · Cyber Threat Intelligence (CTI) 01 CTI 02 · Red Team & Offensive Security 02 Red Team 03 · Blue Team & Defensive Security 03 Blue Team 04 · Vulnerability Research & Exploit Development 04 Vulnerability R&D 05 · Malware Analysis & Reverse Engineering 05 Malware Analysis 06 · Secure Code & Application Security 06 Secure Code 07 · Digital Forensics & Incident Response (DFIR) 07 DFIR 08 · Cloud Security 08 Cloud Security 09 · Governance, Risk & Compliance (GRC) 09 GRC 10 · OSINT & Reconnaissance 10 OSINT 11 · AI Security 11 AI Security
Text equivalent: 81 cross-domain routes

Continue into the 1200km ecosystem

Move from the field guides into published research, browser-based ATT&CK exploration, hands-on labs, and the self-hosted AdversaryGraph platform.

Platform

AdversaryGraph

Product overview, deployment routes, documentation, and validation evidence.

Public workspace

Threat Matrix

Browse ATT&CK groups, techniques, comparisons, coverage leads, and Navigator layers.

Research

CTI research

Actor profiles, campaigns, detection research, and source-linked analysis.

Practice

Security labs

Controlled lab environments, validation walkthroughs, and reproducible evidence.

Writing

Article archive

Local, searchable versions of published long-form research and technical articles.

Evidence

External validation

Source-backed external contributions, references, and acceptance evidence.

Curated sources

Knowledge Sources

Search 165 assessed standards, research portals, tools, datasets, and learning resources by category, tag, audience, access, and quality.

Site-wide citations

References

Search the deduplicated external sources cited across maintained 1200km articles, guides, research, documentation, and labs.

Reference

Glossary

Source-linked terminology with direct routes back to the guide context.

Provenance

Source index

External sources grouped by class and the guides where each is used.

Governance

Editorial policy

Source selection, review, correction, versioning, and AI-assistance boundaries.

Helping materials and visual guides

Use study aids, lab notes, checklists, and concise infographic-supported explanations, then continue into the source-backed field guides, course learning records, research, and labs.

Study library

Cybersecurity helping materials

A single indexed collection of visual explainers, lab guides, study aids, and analyst references with topic, provenance, course, evidence, and lifecycle tags.