Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Application Security

3 sources

Application SecurityAssessment tier A

OSS-Fuzz

Google

Visit source : OSS-Fuzz

OSS-Fuzz is Google's continuous fuzzing service for eligible open-source projects, with documentation for project integration, build scripts, sanitizer use, fuzz-target design, coverage reporting, and vulnerability disclosure. It combines automated large-scale fuzzing infrastructure with ClusterFuzz tooling to find reliability and security defects over time. The resource is most authoritative for onboarding and operating within OSS-Fuzz, while its examples also teach practical fuzzing engineering. Eligibility, reproducible builds, supported toolchains, and maintainer effort constrain adoption; enrollment does not guarantee complete path coverage or absence of vulnerabilities.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

OSS-Fuzz is Google's continuous fuzzing service for eligible open-source projects, with documentation for project integration, build scripts, sanitizer use, fuzz-target design, coverage reporting, and vulnerability disclosure. It combines automated large-scale fuzzing infrastructure with ClusterFuzz tooling to find reliability and security defects over time. The resource is most authoritative for onboarding and operating within OSS-Fuzz, while its examples also teach practical fuzzing engineering. Eligibility, reproducible builds, supported toolchains, and maintainer effort constrain adoption; enrollment does not guarantee complete path coverage or absence of vulnerabilities. Maintainers can study existing project integrations, build local fuzz targets with supported engines and sanitizers, submit configuration for review, and use coverage or crash reports to improve harness reach and fix defects. Other engineers can learn corpus management, reproducibility, minimization, and disclosure workflow from the public documentation and examples. The service is free for accepted open-source projects, but requirements and supported environments evolve; pin integration dependencies and follow current policy. Crash access can expose embargoed vulnerabilities, so restrict artifacts and coordinate fixes. Pair fuzzing with code review, static analysis such as CodeQL, and protocol-aware tests because unreachable paths, logic flaws, and unsupported environments remain outside measured coverage.

Strengths

  • Provides sustained fuzzing infrastructure and issue workflows to qualifying open-source projects.
  • Documents practical integration with fuzzing engines, sanitizers, build systems, and coverage reports.
  • Supports continuous testing rather than one-time fuzzing campaigns.

Limitations

  • Hosted service eligibility is limited, and integration can require substantial engineering work.
  • Fuzzing effectiveness depends on harness quality, seed corpora, coverage, and observable sanitizers.

Best for

  • open-source continuous fuzzing
  • fuzz harness development
  • memory-safety defect discovery
  • coverage-guided testing

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Provides sustained fuzzing infrastructure and issue workflows to qualifying open-source projects; principal limitation: Hosted service eligibility is limited, and integration can require substantial engineering work.

Audience

  • open-source maintainers
  • security engineers
  • software testers
  • vulnerability researchers

Formats

  • service documentation
  • integration guides
  • build examples
  • open-source tooling
  • coverage reports

Keywords

  • application-security
  • fuzzing
  • continuous-testing
  • memory-safety
  • vulnerability-discovery
  • open-source-security
  • sanitizers

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Application SecurityAssessment tier A

CodeQL

GitHub

Visit source : CodeQL

CodeQL treats source code as a queryable database and provides language libraries, query suites, tutorials, and tooling documentation for semantic static analysis. Security researchers can trace data flow, control flow, and program relationships to detect vulnerability patterns, while GitHub code scanning operationalizes supported queries in repository workflows. The documentation is authoritative for the query language and analysis stack. Effective custom-query development requires programming-language and CodeQL modeling knowledge, and results depend on successful database extraction, framework models, query coverage, and disciplined alert triage.

Source type
Mixed License Tool
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

CodeQL treats source code as a queryable database and provides language libraries, query suites, tutorials, and tooling documentation for semantic static analysis. Security researchers can trace data flow, control flow, and program relationships to detect vulnerability patterns, while GitHub code scanning operationalizes supported queries in repository workflows. The documentation is authoritative for the query language and analysis stack. Effective custom-query development requires programming-language and CodeQL modeling knowledge, and results depend on successful database extraction, framework models, query coverage, and disciplined alert triage. Researchers can create a database, explore library predicates, run standard query suites, develop and test custom queries, then package reusable analysis for CI or coordinated research. Query-help pages explain individual alerts and remediation context, while public query repositories offer maintained examples. Availability and licensing differ between open-source research use, the CLI, and GitHub security features; consult current terms and supported-language documentation. Pin packs and tool versions for reproducibility, confirm that builds and generated code were captured, and test framework models against known cases. CodeQL complements Semgrep and manual review but cannot infer every business rule, runtime configuration, or dependency behavior.

Strengths

  • Enables deep semantic and data-flow analysis through a powerful query language.
  • Provides maintained standard libraries, security query suites, tutorials, and query-development tools.
  • Connects research-grade queries with scalable repository code-scanning workflows.

Limitations

  • Custom modeling and query development have a significant learning curve; MIT-licensed query libraries and the separately licensed CLI and code-scanning services have different usage terms.
  • Coverage depends on supported languages, build extraction, library models, and selected suites.

Best for

  • semantic code analysis
  • vulnerability variant analysis
  • custom security queries
  • repository code scanning

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Enables deep semantic and data-flow analysis through a powerful query language; principal limitation: Custom modeling and query development have a significant learning curve; MIT-licensed query libraries and the separately licensed CLI and code-scanning services have different usage terms.

Audience

  • security researchers
  • application security engineers
  • advanced developers
  • devsecops teams

Formats

  • language documentation
  • query reference
  • tutorials
  • query libraries
  • command-line tooling

Keywords

  • application-security
  • static-analysis
  • sast
  • code-querying
  • data-flow-analysis
  • variant-analysis
  • devsecops

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Application SecurityAssessment tier A

Semgrep

Semgrep, Inc.

Visit source : Semgrep

Semgrep is a static-analysis platform whose documentation covers an open-source rule engine, rule syntax, supported languages, CI integration, code scanning, secrets detection, and supply-chain analysis. Its pattern-oriented rules are comparatively approachable, making it useful for encoding organization-specific insecure constructs and delivering feedback in developer workflows. The documentation is the authoritative source for operating the tool, not a neutral comparison of static analyzers. Findings depend on language support, rule quality, data-flow capabilities, and build context, so triage and complementary testing remain necessary.

Source type
Open Core
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Semgrep is a static-analysis platform whose documentation covers an open-source rule engine, rule syntax, supported languages, CI integration, code scanning, secrets detection, and supply-chain analysis. Its pattern-oriented rules are comparatively approachable, making it useful for encoding organization-specific insecure constructs and delivering feedback in developer workflows. The documentation is the authoritative source for operating the tool, not a neutral comparison of static analyzers. Findings depend on language support, rule quality, data-flow capabilities, and build context, so triage and complementary testing remain necessary. Application-security engineers can prototype rules against examples, test them, scan repositories locally, and introduce selected checks into pull requests or CI. Community rules provide starting coverage, while custom rules can encode framework misuse or organization-specific policies that generic tools miss. Core and hosted capabilities, engines, licensing, and supported analyses differ, so confirm the edition and documentation version before designing a program. Tune severity and ignore behavior with code owners, preserve rule tests, and measure false positives and missed cases. Pair results with code review, dependency analysis, dynamic testing, and threat models; a syntactic match is not automatically exploitable, and no match is not evidence of safety.

Strengths

  • Uses readable, code-like patterns that lower the barrier to authoring custom static-analysis rules.
  • Integrates scanning and policy feedback into repositories and CI workflows.
  • Provides extensive rule-writing, deployment, and troubleshooting documentation.

Limitations

  • Detection depth and precision vary by language, engine capability, and rule implementation.
  • Documentation includes both open-source and commercial features that adopters must distinguish.

Best for

  • custom SAST rules
  • secure coding guardrails
  • CI code scanning
  • developer-focused remediation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Uses readable, code-like patterns that lower the barrier to authoring custom static-analysis rules; principal limitation: Detection depth and precision vary by language, engine capability, and rule implementation.

Audience

  • application security engineers
  • developers
  • devsecops teams
  • security researchers

Formats

  • product documentation
  • rule reference
  • tutorials
  • code examples
  • open-source software

Keywords

  • application-security
  • static-analysis
  • sast
  • secure-coding
  • devsecops
  • ci-cd
  • rule-authoring

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Cloud Security

4 sources

Cloud SecurityAssessment tier A

Cloud Security Alliance Cloud Controls Matrix

Cloud Security Alliance

Visit source : Cloud Security Alliance Cloud Controls Matrix

The Cloud Security Alliance Cloud Controls Matrix is a cloud-focused cybersecurity control framework paired with the Consensus Assessments Initiative Questionnaire. Its control objectives span governance, identity, data, infrastructure, logging, incident management, supply chain, and other cloud domains, with mappings to widely used standards and guidance on provider-versus-customer responsibility. Machine-readable releases support automation, while implementation and auditing guides support assurance work. CCM is not a cloud scanner or certification by itself; organizations must scope applicable controls, define evidence, and respect licensing terms for customization or commercial use.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Cloud Security Alliance Cloud Controls Matrix is a cloud-focused cybersecurity control framework paired with the Consensus Assessments Initiative Questionnaire. Its control objectives span governance, identity, data, infrastructure, logging, incident management, supply chain, and other cloud domains, with mappings to widely used standards and guidance on provider-versus-customer responsibility. Machine-readable releases support automation, while implementation and auditing guides support assurance work. CCM is not a cloud scanner or certification by itself; organizations must scope applicable controls, define evidence, and respect licensing terms for customization or commercial use. Cloud customers can use the matrix to build control inventories and responsibility assignments; providers can answer CAIQ questions to communicate their practices; assessors can connect evidence to control identifiers and external frameworks. This makes CCM a useful common layer above AWS, Azure, Google Cloud, Kubernetes, and SaaS-specific guidance. Public artifacts are versioned, so record the release, mappings, and permitted usage before importing them into governance systems. A provider response is self-described evidence, not independent proof, and a framework mapping does not establish control equivalence. Validate technical claims through configuration, telemetry, contracts, testing, and applicable audit reports, while documenting inherited, shared, and customer-operated responsibilities.

Strengths

  • Provides cloud-specific controls with explicit attention to shared supply-chain responsibilities.
  • Includes framework mappings, assessment questions, and machine-readable formats for assurance workflows.
  • Supports provider assessment, internal gap analysis, and audit preparation through related guidance.

Limitations

  • Controls require scoping, implementation details, and evidence criteria before they are testable.
  • Use in products, consulting, or customized distributions can require a CSA license.

Best for

  • cloud control assessments
  • provider due diligence
  • compliance mapping
  • shared responsibility analysis

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Provides cloud-specific controls with explicit attention to shared supply-chain responsibilities; principal limitation: Controls require scoping, implementation details, and evidence criteria before they are testable.

Audience

  • cloud security architects
  • governance teams
  • auditors
  • supplier risk teams

Formats

  • control matrix
  • assessment questionnaire
  • implementation guide
  • audit guide
  • machine-readable data

Keywords

  • cloud-security
  • control-framework
  • cloud-compliance
  • supplier-assurance
  • shared-responsibility
  • risk-assessment
  • control-mapping

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Cloud SecurityAssessment tier A

Google Cloud Security Best Practices

Google Cloud

Visit source : Google Cloud Security Best Practices

The Google Cloud Security Best Practices Center curates first-party guidance for designing, deploying, and operating protected Google Cloud environments. Its material spans enterprise foundations, identity, organization policies, networking, data protection, secrets, logging, threat detection, software supply chain, containers, and workload-specific architecture. It is useful both as an implementation reference and as a map to deeper product documentation and blueprints. Recommendations can assume particular Google Cloud services and organizational patterns, so teams should confirm applicability, cost, regional constraints, and actual enforcement in their own projects.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Google Cloud Security Best Practices Center curates first-party guidance for designing, deploying, and operating protected Google Cloud environments. Its material spans enterprise foundations, identity, organization policies, networking, data protection, secrets, logging, threat detection, software supply chain, containers, and workload-specific architecture. It is useful both as an implementation reference and as a map to deeper product documentation and blueprints. Recommendations can assume particular Google Cloud services and organizational patterns, so teams should confirm applicability, cost, regional constraints, and actual enforcement in their own projects. Platform architects can use enterprise-foundation material to structure organizations, folders, projects, identity, networking, and policy guardrails; service owners can follow linked guides for workload-specific configuration; defenders can map logging and detection recommendations to operational coverage. The pages are free, but cloud products, defaults, preview features, APIs, and pricing evolve, so retain the publication context and verify current product documentation. Compare the guidance with CSA CCM, regulatory requirements, and posture data from tools such as Prowler. Vendor blueprints express supported patterns, not an independent risk acceptance. Validate identity boundaries, data locations, organization policies, key ownership, telemetry retention, and recovery in the exact environment before claiming implementation.

Strengths

  • Centralizes official Google Cloud security architecture and configuration guidance across many domains.
  • Links strategic best practices to detailed product documentation, blueprints, and operational controls.
  • Covers preventive, detective, and response considerations for cloud workloads.

Limitations

  • Guidance is provider-specific and may assume products, organization structures, or licensing not in use.
  • Recommended architecture still requires independent risk assessment and configuration verification.

Best for

  • Google Cloud architecture
  • secure landing zones
  • cloud configuration reviews
  • security operations planning

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Centralizes official Google Cloud security architecture and configuration guidance across many domains; principal limitation: Guidance is provider-specific and may assume products, organization structures, or licensing not in use.

Audience

  • google cloud architects
  • cloud security engineers
  • platform teams
  • security operations teams

Formats

  • best-practice guides
  • architecture guidance
  • product documentation
  • blueprints
  • checklists

Keywords

  • cloud-security
  • google-cloud-security
  • security-architecture
  • cloud-identity
  • data-protection
  • security-operations
  • secure-configuration

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Cloud SecurityAssessment tier A

Microsoft Azure Security Documentation

Microsoft

Visit source : Microsoft Azure Security Documentation

Microsoft's Azure security documentation is the first-party hub for securing Azure and hybrid or multicloud workloads. It routes readers to shared responsibility, Zero Trust, identity, networking, encryption, ransomware protection, Defender for Cloud, Sentinel, architecture, migration, and service-specific guidance. The collection is valuable for configuration details and understanding how Microsoft security services fit together throughout adoption and operations. Its breadth can make navigation difficult, product names and interfaces change frequently, and vendor documentation should be paired with independent benchmarks, threat models, and validation in the exact tenant configuration.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Microsoft's Azure security documentation is the first-party hub for securing Azure and hybrid or multicloud workloads. It routes readers to shared responsibility, Zero Trust, identity, networking, encryption, ransomware protection, Defender for Cloud, Sentinel, architecture, migration, and service-specific guidance. The collection is valuable for configuration details and understanding how Microsoft security services fit together throughout adoption and operations. Its breadth can make navigation difficult, product names and interfaces change frequently, and vendor documentation should be paired with independent benchmarks, threat models, and validation in the exact tenant configuration. Cloud teams can follow architecture and service pages into prerequisites, permissions, deployment, monitoring, and troubleshooting. Microsoft Entra documentation supplies deeper identity detail, while CSA CCM or independent benchmarks can provide a provider-neutral control structure. Most documentation is free, but described capabilities may depend on tenant type, region, subscription, preview status, or paid Defender and Sentinel features; check dated notes and licensing. Test policies in staged scopes, preserve emergency access and rollback paths, and use actual resource inventory, logs, and configuration exports as evidence. A reference architecture or secure score is not proof that every workload is correctly protected.

Strengths

  • Provides authoritative, continuously updated guidance for Azure security features and configurations.
  • Connects foundational concepts to architecture, migration, protection, and security-operations documentation.
  • Covers Azure-native and hybrid security services from a single official entry point.

Limitations

  • The large documentation graph can obscure which recommendations apply to a specific service or licensing tier.
  • First-party guidance is not an independent assessment of control effectiveness.

Best for

  • Azure secure configuration
  • cloud architecture design
  • Azure security operations
  • service capability reference

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Provides authoritative, continuously updated guidance for Azure security features and configurations; principal limitation: The large documentation graph can obscure which recommendations apply to a specific service or licensing tier.

Audience

  • azure administrators
  • cloud security architects
  • security operations teams
  • devops engineers

Formats

  • vendor documentation
  • concept articles
  • how-to guides
  • architecture guidance
  • service reference

Keywords

  • cloud-security
  • azure-security
  • zero-trust
  • cloud-identity
  • security-operations
  • data-protection
  • secure-configuration

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Cloud SecurityAssessment tier B

AWS Security Best Practices

Amazon Web Services

Visit source : AWS Security Best Practices

The AWS Well-Architected Security Pillar presents first-party design principles and best practices for protecting workloads on AWS. It organizes guidance around security foundations, identity and access management, detection, infrastructure and data protection, incident response, and application security while applying the shared-responsibility model. The guide helps teams review architecture decisions and locate deeper service documentation. It is not a configuration benchmark or proof of secure implementation; recommendations require workload-specific threat modeling, service-level procedures, technical verification, and independent requirements appropriate to the organization’s risk and compliance context.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Periodic
Skill level
Beginner, Intermediate
Detailed assessment

Description

The AWS Well-Architected Security Pillar presents first-party design principles and best practices for protecting workloads on AWS. It organizes guidance around security foundations, identity and access management, detection, infrastructure and data protection, incident response, and application security while applying the shared-responsibility model. The guide helps teams review architecture decisions and locate deeper service documentation. It is not a configuration benchmark or proof of secure implementation; recommendations require workload-specific threat modeling, service-level procedures, technical verification, and independent requirements appropriate to the organization’s risk and compliance context. Architects and workload owners can use its questions and improvement guidance during design reviews, record risks and decisions, then follow links into IAM, logging, encryption, networking, backup, and incident-response implementation material. Operations teams can turn selected practices into observable checks and recovery exercises. The document is freely accessible, but AWS services, defaults, regions, quotas, interfaces, and pricing change; confirm each procedure against the current service documentation and deployed account structure. Pair it with independent benchmarks, Prowler findings, organizational policies, and evidence from CloudTrail or configuration state. Vendor guidance explains intended use but does not independently assess least privilege, data flows, or control effectiveness.

Strengths

  • Organizes first-party AWS security guidance into a coherent architecture-review framework.
  • Connects identity, detection, protection, incident response, and application-security decisions.
  • Links design principles to deeper AWS service and implementation documentation.

Limitations

  • The pillar is architectural guidance and does not provide complete service-level procedures or benchmark checks.
  • Vendor guidance must be supplemented with independent requirements and workload-specific risk analysis.

Best for

  • AWS security orientation
  • shared responsibility education
  • cloud architecture discussions
  • compliance context

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.6/5
  • Transparency 3.5/5

Organizes first-party AWS security guidance into a coherent architecture-review framework; principal limitation: The pillar is architectural guidance and does not provide complete service-level procedures or benchmark checks.

Audience

  • cloud architects
  • aws engineers
  • security teams
  • risk managers

Formats

  • vendor documentation
  • architecture guidance
  • well-architected pillar
  • reference links

Keywords

  • cloud-security
  • aws-security
  • shared-responsibility
  • cloud-compliance
  • identity-access-management
  • data-protection
  • security-architecture

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Kubernetes

1 source

KubernetesAssessment tier A

Kubernetes Security Documentation

Kubernetes project / Cloud Native Computing Foundation

Visit source : Kubernetes Security Documentation

The official Kubernetes security documentation explains security concepts and controls for clusters, workloads, and the Kubernetes API. It covers cloud-native security layers, authentication, authorization, admission control, Pod Security Standards, secrets, multi-tenancy, network policies, Linux kernel controls, certificates, audit logging, and security checklists. As project documentation, it is the authoritative source for how upstream mechanisms are intended to work. It does not secure a cluster automatically or capture every managed-service variation; readers must map guidance to their Kubernetes version, distribution, threat model, and surrounding cloud infrastructure.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

The official Kubernetes security documentation explains security concepts and controls for clusters, workloads, and the Kubernetes API. It covers cloud-native security layers, authentication, authorization, admission control, Pod Security Standards, secrets, multi-tenancy, network policies, Linux kernel controls, certificates, audit logging, and security checklists. As project documentation, it is the authoritative source for how upstream mechanisms are intended to work. It does not secure a cluster automatically or capture every managed-service variation; readers must map guidance to their Kubernetes version, distribution, threat model, and surrounding cloud infrastructure. Cluster operators can use the checklists and concept pages to review control-plane exposure and authorization, while workload teams can translate Pod Security, service-account, secret, image, and kernel guidance into deployment requirements. Security engineers can connect these mechanisms to CIS benchmark checks, Kubescape policies, or Trivy scans, then validate runtime behavior separately. Documentation is free and version-selectable; always read the page for the deployed release and consult distribution or cloud-provider overlays for managed components. Examples are starting configurations, not universal policies. Test admission changes and network restrictions before rollout, preserve recovery access, and verify audit collection, node hardening, tenant boundaries, and workload privileges with cluster evidence.

Strengths

  • Authoritatively documents upstream Kubernetes security primitives, boundaries, and recommended practices.
  • Covers control-plane, node, workload, identity, network, and data-protection concerns.
  • Versioned documentation helps teams align guidance with deployed releases.

Limitations

  • Managed distributions and add-ons can change control behavior and operational responsibilities.
  • Concept documentation must be converted into enforced policy, monitoring, and evidence.

Best for

  • Kubernetes security architecture
  • cluster hardening
  • workload security reviews
  • control behavior reference

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Authoritatively documents upstream Kubernetes security primitives, boundaries, and recommended practices; principal limitation: Managed distributions and add-ons can change control behavior and operational responsibilities.

Audience

  • kubernetes administrators
  • platform engineers
  • cloud security engineers
  • application teams

Formats

  • project documentation
  • concept guides
  • task guides
  • security checklists
  • reference documentation

Keywords

  • kubernetes-security
  • container-security
  • cluster-hardening
  • workload-security
  • rbac
  • network-policy
  • pod-security

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.