Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

API Security

1 source

API SecurityAssessment tier A

OWASP API Security Project

OWASP Foundation

Visit source : OWASP API Security Project

The OWASP API Security Project publishes community guidance focused on risks that arise in modern APIs, including its API Security Top 10 and supporting documentation. It highlights authorization failures, authentication weaknesses, resource consumption, unsafe business flows, server-side request forgery, inventory problems, and insecure integration with third-party services. The project is a strong awareness and design-review entry point for REST and related interfaces. Its risk list is not a full verification standard, protocol specification, or substitute for endpoint-specific threat modeling and business-logic testing.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The OWASP API Security Project publishes community guidance focused on risks that arise in modern APIs, including its API Security Top 10 and supporting documentation. It highlights authorization failures, authentication weaknesses, resource consumption, unsafe business flows, server-side request forgery, inventory problems, and insecure integration with third-party services. The project is a strong awareness and design-review entry point for REST and related interfaces. Its risk list is not a full verification standard, protocol specification, or substitute for endpoint-specific threat modeling and business-logic testing. API designers, developers, testers, and program owners can use the categories to review object- and function-level authorization, identity flows, rate and resource controls, endpoint inventories, and trust in consumed APIs. Scenario and prevention sections provide starting questions that can be translated into design requirements or test cases. Publications are free and may be translated, but category identifiers and emphasis differ by edition; keep the cited release with findings and training. Combine the project with ASVS, WSTG, protocol documentation, API schemas, and observed authorization boundaries. Automated endpoint scanning alone will not establish whether business actions, tenant isolation, or data exposure are secure.

Strengths

  • Focuses attention on authorization and business-logic failures often missed by generic web checklists.
  • Provides concise, vendor-neutral risk explanations and mitigation direction.
  • Offers a shared vocabulary for API developers, architects, and testers.

Limitations

  • The Top 10 is an awareness taxonomy rather than exhaustive API test coverage.
  • Guidance must be adapted for protocol, identity model, data sensitivity, and business workflow.

Best for

  • API threat awareness
  • API design reviews
  • developer training
  • test-plan prioritization

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Focuses attention on authorization and business-logic failures often missed by generic web checklists; principal limitation: The Top 10 is an awareness taxonomy rather than exhaustive API test coverage.

Audience

  • api developers
  • application security teams
  • security architects
  • penetration testers

Formats

  • risk taxonomy
  • guidance pages
  • downloadable report
  • community documentation
  • translations

Keywords

  • api-security
  • application-security
  • authorization
  • authentication
  • business-logic
  • secure-api-design
  • owasp

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Application Security

3 sources

Application SecurityAssessment tier A

OWASP Cheat Sheet Series

OWASP Foundation

Visit source : OWASP Cheat Sheet Series

The OWASP Cheat Sheet Series is a large collection of concise, task-oriented guidance for implementing and reviewing application-security controls. Individual sheets cover authentication, authorization, sessions, input handling, cryptography, secrets, logging, APIs, cloud-native patterns, and many language or framework concerns, usually with practical examples and references. It is well suited to developers who need an actionable answer during design or implementation. Each sheet has its own scope and maturity, so advice should be checked against current platform documentation and an application's formal requirements and threat model.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The OWASP Cheat Sheet Series is a large collection of concise, task-oriented guidance for implementing and reviewing application-security controls. Individual sheets cover authentication, authorization, sessions, input handling, cryptography, secrets, logging, APIs, cloud-native patterns, and many language or framework concerns, usually with practical examples and references. It is well suited to developers who need an actionable answer during design or implementation. Each sheet has its own scope and maturity, so advice should be checked against current platform documentation and an application's formal requirements and threat model. Engineers can consult a focused sheet during a design review, turn recommendations into coding standards or pull-request checks, and follow its references when deeper rationale is needed. Security teams can connect sheets to ASVS requirements and use Semgrep or CodeQL to automate only the patterns that static analysis can observe. The collection and Markdown source are free, enabling review and contribution. Because sheets are maintained independently, verify revision history, language examples, library versions, and deployment assumptions. A generic snippet should never be copied without checking framework defaults, error handling, key management, operational monitoring, and compatibility with the application's architecture.

Strengths

  • Turns broad security principles into focused implementation and review guidance.
  • Covers a wide range of recurring application-security decisions in an accessible format.
  • Open contribution and source history make updates and technical review visible.

Limitations

  • Depth and update cadence vary between independently maintained cheat sheets.
  • Generic examples can require modification for current frameworks and organization-specific standards.

Best for

  • secure coding guidance
  • design review preparation
  • developer reference
  • control implementation

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Turns broad security principles into focused implementation and review guidance; principal limitation: Depth and update cadence vary between independently maintained cheat sheets.

Audience

  • developers
  • application security engineers
  • security reviewers
  • technical architects

Formats

  • cheat sheets
  • implementation guidance
  • code examples
  • reference links
  • markdown source

Keywords

  • application-security
  • secure-coding
  • developer-guidance
  • authentication
  • authorization
  • cryptography
  • security-logging
  • owasp

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Application SecurityAssessment tier A

OWASP ASVS

OWASP Foundation

Visit source : OWASP ASVS

The OWASP Application Security Verification Standard provides numbered, testable requirements for evaluating web-application technical security controls and guiding secure development. Its tiered verification levels let teams scale rigor to an application's risk, while stable requirement identifiers support contracts, test plans, defect tracking, and assurance reporting. ASVS is much more actionable than an awareness list, but it remains a requirements standard rather than a complete testing procedure. Teams must establish scope, select an appropriate level, interpret requirements for their architecture, and retain evidence of verification.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The OWASP Application Security Verification Standard provides numbered, testable requirements for evaluating web-application technical security controls and guiding secure development. Its tiered verification levels let teams scale rigor to an application's risk, while stable requirement identifiers support contracts, test plans, defect tracking, and assurance reporting. ASVS is much more actionable than an awareness list, but it remains a requirements standard rather than a complete testing procedure. Teams must establish scope, select an appropriate level, interpret requirements for their architecture, and retain evidence of verification. Security architects can derive design requirements; engineering teams can add acceptance criteria; assessors can map test evidence and exceptions back to identifiers. Its sections cover architecture, authentication, sessions, access control, validation, cryptography, communications, configuration, data protection, and related application controls. The standard is free, with downloadable and machine-readable forms, but identifiers and wording can change across versions; record the exact release in contracts and reports. Use WSTG for testing approaches and Cheat Sheets for implementation detail. A claimed verification level is meaningful only when scope, methods, evidence, exclusions, and reviewer independence are explicit.

Strengths

  • Supplies granular, uniquely identified security requirements suitable for verification and traceability.
  • Supports risk-based rigor through multiple verification levels.
  • Can anchor development criteria, procurement language, assessment plans, and assurance reporting.

Limitations

  • Requirements still require architectural interpretation and a documented verification method.
  • It focuses on application controls and does not cover every operational or infrastructure risk.

Best for

  • application security requirements
  • verification planning
  • secure procurement
  • control traceability

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Supplies granular, uniquely identified security requirements suitable for verification and traceability; principal limitation: Requirements still require architectural interpretation and a documented verification method.

Audience

  • application security engineers
  • developers
  • security testers
  • software buyers

Formats

  • verification standard
  • requirements catalog
  • downloadable document
  • machine-readable data
  • translations

Keywords

  • application-security
  • security-requirements
  • security-verification
  • secure-development
  • web-security
  • control-testing
  • owasp

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Application SecurityAssessment tier A

OWASP Top 10

OWASP Foundation

Visit source : OWASP Top 10

The OWASP Top 10 is a periodically updated awareness document that summarizes broad-consensus categories of critical web-application security risk. Each release explains the category, associated weakness patterns, example attack scenarios, and general prevention approaches, making it effective for executive communication, developer onboarding, and program prioritization. It is deliberately a compact awareness baseline, not a complete application-security standard, testing checklist, or statement of the ten vulnerabilities most likely in a particular system. Use ASVS and WSTG when measurable requirements or test procedures are needed.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Beginner, Intermediate
Detailed assessment

Description

The OWASP Top 10 is a periodically updated awareness document that summarizes broad-consensus categories of critical web-application security risk. Each release explains the category, associated weakness patterns, example attack scenarios, and general prevention approaches, making it effective for executive communication, developer onboarding, and program prioritization. It is deliberately a compact awareness baseline, not a complete application-security standard, testing checklist, or statement of the ten vulnerabilities most likely in a particular system. Use ASVS and WSTG when measurable requirements or test procedures are needed. Application-security leaders can use it to establish shared terminology, review broad risk themes, and start conversations with engineering and management; developers can follow its references into weakness definitions and defensive guidance. The material is free and translated, but category names, data inputs, and mappings change between releases, so policies and training should identify the edition they use. Do not turn rank order into a universal risk score. Pair the list with application threat models, asset and exposure data, ASVS requirements, WSTG procedures, and verified findings from the actual software.

Strengths

  • Provides a widely recognized vocabulary for communicating major web-application risk classes.
  • Combines community consensus and contributed vulnerability data with approachable explanations.
  • Offers a low-friction starting point for secure-development awareness.

Limitations

  • Its ten broad categories are not an exhaustive security requirements or testing program.
  • Rankings and categories should not replace application-specific threat and exposure analysis.

Best for

  • developer awareness
  • application risk communication
  • security program prioritization
  • introductory training

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Provides a widely recognized vocabulary for communicating major web-application risk classes; principal limitation: Its ten broad categories are not an exhaustive security requirements or testing program.

Audience

  • developers
  • application security teams
  • security leaders
  • students

Formats

  • awareness standard
  • risk taxonomy
  • guidance pages
  • downloadable report
  • translations

Keywords

  • application-security
  • web-security
  • secure-development
  • risk-awareness
  • vulnerability-classes
  • owasp
  • developer-training

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Network Security

1 source

Network SecurityAssessment tier A

Nmap Documentation

Nmap Project

Visit source : Nmap Documentation

Nmap's official documentation covers installation and nearly every command-line option for network discovery, port scanning, service and version detection, operating-system fingerprinting, timing, output, and the Lua-based Nmap Scripting Engine. The reference guide is updated with releases, complemented by an official book, NSE portal, protocol papers, examples, and translations. It is useful for both asset discovery and authorized security assessment, but scan results are observations from a particular path and time. Aggressive probes or scripts can disrupt services, trigger defenses, or exceed permission boundaries.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Nmap's official documentation is the primary reference for the Nmap Project's network-discovery and security-auditing tools. It explains host discovery, TCP and UDP port scanning, service and version detection, operating-system fingerprinting, timing, target and port selection, output formats, and the Lua-based Nmap Scripting Engine. The continuously maintained reference guide is complemented by an official book, NSE documentation, protocol papers, examples, and translations. Administrators use it to inventory assets from an approved vantage point, export structured results, compare changes over time, and investigate unexpected services; authorized assessors use carefully selected probes to validate exposure. Wireshark can inspect resulting traffic, while Zeek or Suricata can show how monitoring systems observe the activity. A scan reports responses seen from one network path and moment, not definitive ownership, reachability from every zone, vulnerability, or operating-system identity. Firewalls, rate limiting, proxies, load balancers, packet loss, and service emulation alter conclusions. NSE scripts vary from passive enrichment to intrusive checks. Define written scope, exclude fragile systems when required, review each script category and source, control rate and retries, coordinate monitoring, preserve commands and timestamps, and corroborate consequential findings through configuration or asset records.

Strengths

  • Comprehensive first-party reference for Nmap options and behavior
  • Documents discovery, fingerprinting, performance, output, and NSE extensibility
  • Examples and protocol papers explain how scan techniques work on the wire

Limitations

  • Results can be incomplete or misleading through firewalls, rate limits, and network paths
  • Intrusive scripts and aggressive scans require scope control and authorization

Best for

  • network asset discovery
  • service enumeration
  • authorized security audits
  • NSE script development

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Comprehensive first-party reference for Nmap options and behavior; principal limitation: Results can be incomplete or misleading through firewalls, rate limits, and network paths.

Audience

  • network administrators
  • penetration testers
  • SOC analysts
  • security engineers

Formats

  • reference guide
  • online book
  • script documentation
  • technical papers
  • translations

Keywords

  • network-security
  • nmap
  • network-discovery
  • port-scanning
  • service-detection
  • asset-inventory
  • nse
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Training

1 source

TrainingAssessment tier A

PortSwigger Web Security Academy

PortSwigger Ltd

Visit source : PortSwigger Web Security Academy

PortSwigger Web Security Academy is a free learning platform combining structured explanations with interactive labs on web vulnerabilities. Its curriculum covers foundational and advanced topics such as SQL injection, cross-site scripting, request smuggling, access control, authentication, deserialization, server-side request forgery, API testing, and newer browser or protocol research. Labs provide immediate, isolated practice and often reflect PortSwigger research. The Academy teaches exploitation and reasoning effectively, but it is not an organizational control standard and controlled labs do not reproduce every production architecture, defense, or legal constraint.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

PortSwigger Web Security Academy is a free learning platform combining structured explanations with interactive labs on web vulnerabilities. Its curriculum covers foundational and advanced topics such as SQL injection, cross-site scripting, request smuggling, access control, authentication, deserialization, server-side request forgery, API testing, and newer browser or protocol research. Labs provide immediate, isolated practice and often reflect PortSwigger research. The Academy teaches exploitation and reasoning effectively, but it is not an organizational control standard and controlled labs do not reproduce every production architecture, defense, or legal constraint. Learners can move through topic pages, examine worked examples, and solve purpose-built browser-accessible targets with manual requests or testing tools, making the resource useful from beginner concepts through specialist techniques. Practitioners can pair labs with PortSwigger Research to understand technique origins and with OWASP WSTG or ASVS to place them in a broader assessment method. Core learning content is free, although progress features may use an account and tooling editions differ. Perform these techniques only in Academy labs or explicitly authorized systems. Success demonstrates a specific concept, not complete engagement planning, secure coding competence, remediation quality, or production exploitability.

Strengths

  • Pairs high-quality technical explanations with numerous free, purpose-built interactive labs.
  • Covers both core web flaws and advanced techniques derived from current research.
  • Provides guided learning paths and measurable practical progress.

Limitations

  • Lab environments simplify production systems and should not be treated as engagement experience.
  • The curriculum centers web and API testing rather than full secure-development governance.

Best for

  • hands-on web security learning
  • penetration testing practice
  • vulnerability concept validation
  • advanced technique study

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Pairs high-quality technical explanations with numerous free, purpose-built interactive labs; principal limitation: Lab environments simplify production systems and should not be treated as engagement experience.

Audience

  • web security students
  • penetration testers
  • bug bounty researchers
  • application security engineers

Formats

  • interactive labs
  • learning paths
  • technical articles
  • video material
  • progress tracking

Keywords

  • web-security
  • application-security
  • hands-on-labs
  • penetration-testing
  • api-security
  • browser-security
  • vulnerability-research

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Web Security

2 sources

Web SecurityAssessment tier A

OWASP Web Security Testing Guide

OWASP Foundation

Visit source : OWASP Web Security Testing Guide

The OWASP Web Security Testing Guide is a community-maintained methodology and reference for testing web applications and web services. It organizes checks across information gathering, configuration, identity, authentication, authorization, sessions, input validation, cryptography, business logic, client-side behavior, and APIs, with objectives and testing approaches for each topic. The guide is valuable for building repeatable assessment coverage and teaching testing concepts. It is not an automated scanner or proof of complete coverage; testers must adapt procedures to technology, threat model, authorization, and application context.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The OWASP Web Security Testing Guide is a community-maintained methodology and reference for testing web applications and web services. It organizes checks across information gathering, configuration, identity, authentication, authorization, sessions, input validation, cryptography, business logic, client-side behavior, and APIs, with objectives and testing approaches for each topic. The guide is valuable for building repeatable assessment coverage and teaching testing concepts. It is not an automated scanner or proof of complete coverage; testers must adapt procedures to technology, threat model, authorization, and application context. Assessors can use its test identifiers to build engagement plans, record which checks were applicable, and connect observations to reproducible procedures. Developers and reviewers can use the same chapters to understand how controls fail under adversarial input. The online guide is free; stable and developing editions may coexist, so cite the precise version and check linked tool commands against current software. Pair it with ASVS for requirements, the API Security Project for API-specific prioritization, and controlled labs such as Web Security Academy for practice. Obtain written authorization, avoid destructive tests, and document coverage gaps, environmental constraints, and evidence rather than reporting checklist completion as assurance.

Strengths

  • Provides broad, structured coverage of web-security testing domains and test objectives.
  • Explains manual methodology in a vendor-neutral and openly maintained reference.
  • Pairs naturally with ASVS requirements and hands-on lab platforms.

Limitations

  • Procedures require adaptation and tester judgment for each architecture and engagement.
  • Following the guide does not guarantee exhaustive discovery or verified remediation.

Best for

  • web penetration test planning
  • manual testing methodology
  • assessment checklists
  • security tester education

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Provides broad, structured coverage of web-security testing domains and test objectives; principal limitation: Procedures require adaptation and tester judgment for each architecture and engagement.

Audience

  • web security testers
  • application security engineers
  • penetration testers
  • developers

Formats

  • testing guide
  • methodology
  • test cases
  • reference chapters
  • downloadable document

Keywords

  • web-security
  • application-security
  • penetration-testing
  • security-testing
  • test-methodology
  • manual-testing
  • owasp

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Web SecurityAssessment tier A

PortSwigger Research

PortSwigger Ltd

Visit source : PortSwigger Research

PortSwigger Research publishes original web-security research with detailed methodology, proof-of-concept techniques, tooling, and presentation material. Its work has introduced or advanced practical understanding of topics including HTTP request smuggling, web cache poisoning, browser behavior, parser discrepancies, and novel injection paths. The archive is particularly valuable for experienced testers seeking the reasoning behind emerging attack classes and for defenders translating findings into detection or hardening. It is selective research rather than a complete curriculum, and offensive techniques require controlled, authorized validation before operational use.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Advanced
Detailed assessment

Description

PortSwigger Research publishes original web-security research with detailed methodology, proof-of-concept techniques, tooling, and presentation material. Its work has introduced or advanced practical understanding of topics including HTTP request smuggling, web cache poisoning, browser behavior, parser discrepancies, and novel injection paths. The archive is particularly valuable for experienced testers seeking the reasoning behind emerging attack classes and for defenders translating findings into detection or hardening. It is selective research rather than a complete curriculum, and offensive techniques require controlled, authorized validation before operational use. A useful reading workflow is to identify the affected protocol assumptions, study the experimental setup and variants, reproduce behavior in an isolated lab, and then derive architecture-specific review or detection questions. Related Academy modules can provide safer guided practice, while OWASP WSTG supplies wider assessment coverage. Articles and presentations are publicly accessible, but techniques may rely on particular proxy chains, parser versions, browser behavior, timing, or cache configuration; record publication date and verify current applicability. Proofs of concept are evidence of a mechanism under stated conditions, not evidence that an arbitrary target is vulnerable. Testing production systems requires authorization, rate control, and impact-aware procedures.

Strengths

  • Publishes original, technically deep research with reproducible reasoning and supporting tools.
  • Frequently connects protocol edge cases to practical web exploitation.
  • Links discoveries to learning material and labs in Web Security Academy.

Limitations

  • The archive reflects selected research themes rather than comprehensive web-security coverage.
  • Techniques may depend on specific intermediaries, versions, and deployment conditions.

Best for

  • advanced web research
  • novel technique analysis
  • test methodology development
  • defensive control review

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Publishes original, technically deep research with reproducible reasoning and supporting tools; principal limitation: The archive reflects selected research themes rather than comprehensive web-security coverage.

Audience

  • advanced penetration testers
  • security researchers
  • application security engineers
  • web defenders

Formats

  • research papers
  • technical articles
  • conference presentations
  • proofs of concept
  • research tools

Keywords

  • web-security
  • vulnerability-research
  • http-security
  • browser-security
  • request-smuggling
  • web-cache-security
  • penetration-testing

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.