Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Cloud Security

2 sources

Cloud SecurityAssessment tier A

Stratus Red Team

Datadog Security Labs

Visit source : Stratus Red Team

Stratus Red Team is Datadog's open-source command-line tool for emulating documented adversary techniques in cloud and identity environments. Its catalog includes AWS, Azure, Google Cloud, Microsoft Entra ID, and Kubernetes scenarios mapped to MITRE ATT&CK, with commands to prepare, detonate, inspect, revert, and clean up resources. It helps detection engineers produce known telemetry and validate alerts without building every simulation manually. Techniques perform real actions, may create costs or destructive effects, and must run only in authorized, isolated environments with reviewed permissions and cleanup plans.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Advanced
Detailed assessment

Description

Stratus Red Team is Datadog's open-source command-line tool for emulating documented adversary techniques in cloud and identity environments. Its catalog includes AWS, Azure, Google Cloud, Microsoft Entra ID, and Kubernetes scenarios mapped to MITRE ATT&CK, with commands to prepare, detonate, inspect, revert, and clean up resources. It helps detection engineers produce known telemetry and validate alerts without building every simulation manually. Techniques perform real actions, may create costs or destructive effects, and must run only in authorized, isolated environments with reviewed permissions and cleanup plans. A detection team can choose a technique, inspect prerequisites and source code, provision the required state, execute it at a set time, and trace resulting control-plane or workload telemetry through collection, rule logic, alerting, and response. Reversion aids repeatability, but operators must verify every resource and side effect. The project is free and versioned; pin the binary and technique definition because cloud APIs, ATT&CK mappings, and behavior change. Use disposable accounts or subscriptions, least-privileged test credentials, budgets, approvals, and independent cleanup checks. A successful emulation validates only the tested path and conditions, not comprehensive detection coverage or safe behavior in production.

Strengths

  • Packages cloud attack behaviors into repeatable, documented, and reversible emulation workflows.
  • Maps scenarios to ATT&CK and exposes exact cloud actions useful for detection validation.
  • Supports multiple major cloud platforms and programmatic execution.

Limitations

  • Scenarios execute real API actions and can create cost, exposure, or disruption if poorly scoped.
  • Technique coverage is selective and successful emulation does not validate the full response process.

Best for

  • cloud detection validation
  • purple-team exercises
  • security control testing
  • telemetry generation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Packages cloud attack behaviors into repeatable, documented, and reversible emulation workflows; principal limitation: Scenarios execute real API actions and can create cost, exposure, or disruption if poorly scoped.

Audience

  • cloud detection engineers
  • purple teams
  • cloud security engineers
  • incident responders

Formats

  • open-source software
  • command-line tool
  • technique catalog
  • documentation
  • attack mappings

Keywords

  • cloud-security
  • adversary-emulation
  • detection-validation
  • purple-team
  • mitre-attack
  • security-testing
  • cloud-telemetry
  • identity-security
  • kubernetes

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Cloud SecurityAssessment tier A

Prowler

Prowler

Visit source : Prowler

Prowler is an open-source cloud security assessment platform with a command-line scanner, self-hosted components, a public library of checks, and commercial managed offerings. Current documentation covers major cloud providers, Kubernetes, container images, infrastructure as code, and several SaaS platforms, mapping checks to security and compliance frameworks with remediation guidance. It is useful for repeatable posture reviews and evidence collection across accounts. Users must distinguish product editions and provider support, validate check applicability and credentials, and avoid treating automated pass counts as proof of effective risk reduction.

Source type
Open Core
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Prowler is an open-source cloud security assessment platform with a command-line scanner, self-hosted components, a public library of checks, and commercial managed offerings. Current documentation covers major cloud providers, Kubernetes, container images, infrastructure as code, and several SaaS platforms, mapping checks to security and compliance frameworks with remediation guidance. It is useful for repeatable posture reviews and evidence collection across accounts. Users must distinguish product editions and provider support, validate check applicability and credentials, and avoid treating automated pass counts as proof of effective risk reduction. Teams can select providers, regions, or checks; run assessments with read-oriented roles; export results; and compare snapshots for drift. Check definitions and remediation notes can be reviewed against AWS, Azure, Google Cloud, or Kubernetes documentation before changes are approved. The open-source CLI is free, while hosted and enterprise workflows have separate terms and features; record release, provider plugin, credential scope, and scan options. Protect outputs containing account topology and findings. Investigate failures, exceptions, and unavailable checks individually, and confirm risky changes in staged environments. Prowler complements control frameworks and threat models but does not evaluate application logic, all runtime paths, or organizational process effectiveness.

Strengths

  • Offers a large, versioned library of cloud checks with remediation and framework mappings.
  • Supports multiple infrastructure, Kubernetes, SaaS, and code-related providers from consistent interfaces.
  • Provides open-source CLI and self-hosting paths alongside managed product options.

Limitations

  • Provider, interface, and feature support differ across open-source and commercial product families.
  • Automated checks require applicability review and cannot prove control operation or business impact.

Best for

  • cloud posture assessment
  • multi-account security reviews
  • compliance evidence collection
  • configuration drift detection

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Offers a large, versioned library of cloud checks with remediation and framework mappings; principal limitation: Provider, interface, and feature support differ across open-source and commercial product families.

Audience

  • cloud security engineers
  • auditors
  • platform teams
  • devsecops teams

Formats

  • open-source software
  • command-line tool
  • web application
  • check library
  • documentation

Keywords

  • cloud-security
  • cloud-posture-management
  • configuration-audit
  • cloud-compliance
  • multi-cloud
  • security-automation
  • devsecops

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Container Security

1 source

Container SecurityAssessment tier A

Trivy

Aqua Security

Visit source : Trivy

Trivy is an open-source security scanner for container images, filesystems, repositories, infrastructure-as-code, Kubernetes, and software artifacts. It can identify known package vulnerabilities, configuration problems, exposed secrets, license concerns, and generate software bills of materials through command-line and CI workflows. Its documentation makes it a practical general-purpose scanner for development and container pipelines. Results depend on vulnerability databases, package identification, configuration checks, and scan settings; findings require triage, while absence of findings does not cover runtime behavior, business logic, or unknown vulnerabilities.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Trivy is an open-source security scanner for container images, filesystems, repositories, infrastructure-as-code, Kubernetes, and software artifacts. It can identify known package vulnerabilities, configuration problems, exposed secrets, license concerns, and generate software bills of materials through command-line and CI workflows. Its documentation makes it a practical general-purpose scanner for development and container pipelines. Results depend on vulnerability databases, package identification, configuration checks, and scan settings; findings require triage, while absence of findings does not cover runtime behavior, business logic, or unknown vulnerabilities. Developers and platform teams can scan source or build outputs locally, produce machine-readable reports and SBOMs, and apply explicit severity or policy gates in CI. Cluster scans and misconfiguration checks complement upstream Kubernetes guidance and broader posture tools such as Kubescape. The core tool and documentation are free, but database freshness, enabled scanners, cache state, target platform, and Trivy version must be captured for reproducibility. Protect reports because discovered packages and secrets may be sensitive. Validate package reachability, vendor status, VEX or suppression rationale, and remediation availability before prioritizing. Trivy should be one signal within dependency management, image provenance, admission control, runtime defense, and manual application review.

Strengths

  • Combines vulnerability, misconfiguration, secret, license, and SBOM capabilities in one tool.
  • Scans multiple artifact types and integrates readily with local and CI workflows.
  • Provides maintained documentation, databases, output formats, and policy options.

Limitations

  • Accuracy depends on upstream advisory data, package metadata, policies, and scan configuration.
  • Static artifact findings do not establish exploitability or runtime exposure.

Best for

  • container image scanning
  • software composition analysis
  • infrastructure-as-code checks
  • CI security gates

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Combines vulnerability, misconfiguration, secret, license, and SBOM capabilities in one tool; principal limitation: Accuracy depends on upstream advisory data, package metadata, policies, and scan configuration.

Audience

  • devsecops teams
  • container engineers
  • cloud security engineers
  • developers

Formats

  • open-source software
  • command-line tool
  • documentation
  • vulnerability database
  • scan reports

Keywords

  • container-security
  • vulnerability-scanning
  • software-composition-analysis
  • sbom
  • infrastructure-as-code
  • secret-scanning
  • devsecops

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Kubernetes

2 sources

KubernetesAssessment tier A

Kubescape

Kubescape project / Cloud Native Computing Foundation

Visit source : Kubescape

Kubescape is an open-source Kubernetes security platform created by ARMO and maintained as a CNCF incubating project. It scans manifests, Helm charts, images, and live clusters for misconfigurations and vulnerabilities; applies built-in or custom policy controls; checks network-policy and seccomp posture; and can add runtime detection. Output supports console, JSON, JUnit XML, HTML, and PDF workflows. Its breadth is useful for continuous cluster posture management, but enabled components, permissions, control frameworks, and underlying scanners determine coverage, and automated compliance mappings still require human scoping and validation.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Kubescape is an open-source Kubernetes security platform created by ARMO and maintained as a CNCF incubating project. It scans manifests, Helm charts, images, and live clusters for misconfigurations and vulnerabilities; applies built-in or custom policy controls; checks network-policy and seccomp posture; and can add runtime detection. Output supports console, JSON, JUnit XML, HTML, and PDF workflows. Its breadth is useful for continuous cluster posture management, but enabled components, permissions, control frameworks, and underlying scanners determine coverage, and automated compliance mappings still require human scoping and validation. Platform teams can run checks before deployment against manifests or Helm charts, assess a cluster against selected frameworks, export findings to CI, and use scans to detect posture drift. Security engineers can compare results with CIS recommendations, upstream Kubernetes documentation, and Trivy artifact findings rather than duplicate them blindly. The open-source components are free; hosted services, storage, and integrations may have different access terms, and capabilities vary by release. Review requested cluster permissions, protect exported topology and vulnerability data, and test custom controls. A framework score does not establish compliance, while runtime alerts require baselining and investigation before they become evidence of malicious activity.

Strengths

  • Covers development-time manifests, live-cluster posture, image risk, policy, and optional runtime signals.
  • Maps controls to common Kubernetes frameworks and supports custom policies through Open Policy Agent.
  • Integrates with developer tools and CI while offering multiple machine-readable report formats.

Limitations

  • Feature coverage varies by deployment mode, enabled components, permissions, and external data sources.
  • Compliance labels and scanner findings require contextual review and do not prove workload security.

Best for

  • Kubernetes posture management
  • manifest policy checks
  • cluster vulnerability assessment
  • CI policy enforcement

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Covers development-time manifests, live-cluster posture, image risk, policy, and optional runtime signals; principal limitation: Feature coverage varies by deployment mode, enabled components, permissions, and external data sources.

Audience

  • kubernetes administrators
  • platform engineers
  • cloud security teams
  • devsecops teams

Formats

  • open-source software
  • command-line tool
  • operator
  • documentation
  • scan reports

Keywords

  • kubernetes-security
  • container-security
  • posture-management
  • policy-as-code
  • configuration-scanning
  • runtime-security
  • devsecops

Link validation: Reachable · checked 2026-09-07 · HTTP 200

KubernetesAssessment tier A

CIS Kubernetes Benchmark

Center for Internet Security

Visit source : CIS Kubernetes Benchmark

The CIS Kubernetes Benchmark provides prescriptive hardening recommendations and assessment procedures for Kubernetes components and selected distributions. Recommendations address API server, controller manager, scheduler, etcd, worker nodes, policies, logging, authentication, authorization, and related configuration, with profiles and rationale that support repeatable reviews. It is valuable for baseline audits and compliance evidence when matched to the correct benchmark version. It is not a complete Kubernetes threat model, and some controls may be inapplicable or provider-managed in hosted services, requiring documented scoping and compensating controls.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

The CIS Kubernetes Benchmark provides prescriptive hardening recommendations and assessment procedures for Kubernetes components and selected distributions. Recommendations address API server, controller manager, scheduler, etcd, worker nodes, policies, logging, authentication, authorization, and related configuration, with profiles and rationale that support repeatable reviews. It is valuable for baseline audits and compliance evidence when matched to the correct benchmark version. It is not a complete Kubernetes threat model, and some controls may be inapplicable or provider-managed in hosted services, requiring documented scoping and compensating controls. Platform and assurance teams can review each recommendation, run its audit procedure where applicable, record observed configuration, and plan remediation using the rationale and impact notes. Automated tools may accelerate collection, but their interpretation must match the benchmark and distribution. Access to benchmark documents is free subject to CIS terms; retain the Kubernetes or managed-service edition, version, profile, and assessment date because component flags and recommendations change. Pair the benchmark with upstream Kubernetes documentation, workload threat modeling, image scanning, admission policies, and runtime monitoring. A numerical pass rate can hide high-impact exceptions, unmanaged cloud components, application-level risk, or compensating controls, so reports should preserve scope and evidence.

Strengths

  • Offers testable hardening recommendations with rationale, audit steps, and remediation guidance.
  • Supports repeatable baseline assessments and common compliance workflows.
  • Provides variants for upstream Kubernetes and multiple managed or vendor distributions.

Limitations

  • Benchmark and cluster versions must match, and managed services can make checks inapplicable.
  • Passing configuration checks does not establish workload, application, or runtime security; commercial use and automation tooling can require CIS licensing or membership.

Best for

  • Kubernetes baseline audits
  • cluster hardening
  • compliance evidence
  • configuration review

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Offers testable hardening recommendations with rationale, audit steps, and remediation guidance; principal limitation: Benchmark and cluster versions must match, and managed services can make checks inapplicable.

Audience

  • kubernetes administrators
  • security assessors
  • cloud security engineers
  • auditors

Formats

  • security benchmark
  • configuration checks
  • audit procedures
  • remediation guidance
  • downloadable document

Keywords

  • kubernetes-security
  • security-benchmark
  • cluster-hardening
  • configuration-audit
  • cloud-compliance
  • secure-configuration
  • cis-benchmark

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Mobile Security

3 sources

Mobile SecurityAssessment tier A

Android Security

Android Open Source Project / Google

Visit source : Android Security

Android's official security documentation explains the platform security model and the controls implemented in the Android Open Source Project. Topics include the application sandbox, permissions, signing, verified boot, encryption, authentication, hardware-backed security, updates, exploit mitigations, privacy, and guidance for platform implementers and application developers. It is the primary reference for intended Android behavior and supported security APIs. Actual protections vary with Android version, device hardware, vendor modifications, patch level, and application configuration, so deployed-device testing and app-specific review remain essential.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Android's official security documentation explains the platform security model and the controls implemented in the Android Open Source Project. Topics include the application sandbox, permissions, signing, verified boot, encryption, authentication, hardware-backed security, updates, exploit mitigations, privacy, and guidance for platform implementers and application developers. It is the primary reference for intended Android behavior and supported security APIs. Actual protections vary with Android version, device hardware, vendor modifications, patch level, and application configuration, so deployed-device testing and app-specific review remain essential. Application engineers can use the documentation to choose platform APIs and understand permission, component, storage, network, and credential boundaries; device builders and security researchers can follow architecture and implementation material into AOSP details. Assessors can connect these mechanisms to MASVS requirements and MASTG test cases, then confirm behavior with manifests, code, and controlled runtime observation. Access is free, but pages may describe Android rather than older supported devices, and separate security bulletins communicate patch-specific issues. Record API level, build, vendor image, security patch level, hardware capabilities, and policy state. Documentation describes intended upstream behavior; it does not establish that an OEM implementation, application, or fleet configuration correctly enforces every control.

Strengths

  • Authoritatively documents Android platform security architecture, APIs, and implementation expectations.
  • Covers defenses from hardware and boot integrity through sandboxing, permissions, data, and updates.
  • Separates guidance relevant to platform builders, device partners, and application developers.

Limitations

  • OEM modifications, device hardware, patch cadence, and Android release differences affect real behavior.
  • Platform documentation does not assess the security of a particular application or backend.

Best for

  • Android security architecture
  • secure app implementation
  • platform control research
  • device security review

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Authoritatively documents Android platform security architecture, APIs, and implementation expectations; principal limitation: OEM modifications, device hardware, patch cadence, and Android release differences affect real behavior.

Audience

  • android developers
  • mobile security engineers
  • device manufacturers
  • mobile testers

Formats

  • platform documentation
  • architecture guides
  • developer guidance
  • implementation requirements
  • security bulletins

Keywords

  • mobile-security
  • android-security
  • platform-security
  • application-sandboxing
  • verified-boot
  • mobile-cryptography
  • secure-development

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Mobile SecurityAssessment tier A

OWASP MASTG

OWASP Foundation

Visit source : OWASP MASTG

The OWASP Mobile Application Security Testing Guide is a detailed knowledge base and test methodology for Android and iOS applications. It explains platform internals, mobile attack surfaces, testing techniques, tools, concrete test cases, best practices, and links to MASVS requirements; crackmes and demonstrations provide controlled practice. The guide helps testers move from a requirement to repeatable static and dynamic analysis. It is not an automated assessment or guarantee of coverage, and procedures must be adapted for application frameworks, platform versions, backend behavior, authorization, and engagement scope.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

The OWASP Mobile Application Security Testing Guide is a detailed knowledge base and test methodology for Android and iOS applications. It explains platform internals, mobile attack surfaces, testing techniques, tools, concrete test cases, best practices, and links to MASVS requirements; crackmes and demonstrations provide controlled practice. The guide helps testers move from a requirement to repeatable static and dynamic analysis. It is not an automated assessment or guarantee of coverage, and procedures must be adapted for application frameworks, platform versions, backend behavior, authorization, and engagement scope. Testers can begin with a MASVS requirement, study the relevant Android or iOS mechanism, identify static and runtime evidence, and use tools such as MobSF or Frida where appropriate. Developers can use the same cases to reproduce findings and confirm fixes on supported devices. The guide is free and continuously maintained; cite the version or page revision, and verify commands against current tool and operating-system releases. Crackmes are suitable authorized practice targets, unlike arbitrary production applications. A thorough assessment must also examine server APIs, business workflows, third-party SDKs, build and signing processes, privacy behavior, and device-specific conditions that isolated test cases cannot fully represent.

Strengths

  • Combines platform knowledge, practical test cases, tools, and security requirements in one open reference.
  • Provides substantial Android and iOS coverage for both static and dynamic analysis.
  • Links tests to MASVS controls and purpose-built practice applications.

Limitations

  • The guide's breadth requires testers to select and adapt cases to each architecture and risk profile.
  • Mobile front-end tests alone do not cover every server-side API or business-process risk.

Best for

  • mobile penetration testing
  • Android and iOS analysis
  • test-case development
  • mobile security training

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Combines platform knowledge, practical test cases, tools, and security requirements in one open reference; principal limitation: The guide's breadth requires testers to select and adapt cases to each architecture and risk profile.

Audience

  • mobile penetration testers
  • application security engineers
  • mobile developers
  • reverse engineers

Formats

  • testing guide
  • test cases
  • platform knowledge base
  • tool references
  • practice applications

Keywords

  • mobile-security
  • mobile-testing
  • android-security
  • ios-security
  • dynamic-analysis
  • static-analysis
  • reverse-engineering
  • penetration-testing

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Mobile SecurityAssessment tier A

OWASP MASVS

OWASP Foundation

Visit source : OWASP MASVS

The OWASP Mobile Application Security Verification Standard defines security requirements for native mobile applications across storage, cryptography, authentication and authorization, network communication, platform interaction, code quality, resistance to reverse engineering, and privacy. Stable identifiers make MASVS useful for development requirements, assessment scope, procurement, and traceable assurance, while linked weakness entries add context. It is a verification standard rather than a testing recipe or certification result; teams must select applicable controls, account for Android and iOS architecture, and document how each requirement was tested.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The OWASP Mobile Application Security Verification Standard defines security requirements for native mobile applications across storage, cryptography, authentication and authorization, network communication, platform interaction, code quality, resistance to reverse engineering, and privacy. Stable identifiers make MASVS useful for development requirements, assessment scope, procurement, and traceable assurance, while linked weakness entries add context. It is a verification standard rather than a testing recipe or certification result; teams must select applicable controls, account for Android and iOS architecture, and document how each requirement was tested. Mobile architects can turn identifiers into design and acceptance requirements, developers can trace defects to expected properties, and assessors can record scope, evidence, and exceptions consistently. The companion MASTG links requirements to platform concepts and testing approaches, while Android Security and Apple Platform Security explain the underlying controls. MASVS is free and versioned; requirement groups, identifiers, and mappings can change, so retain the exact release in contracts and reports. Apply controls to the actual app, backend dependencies, distribution channel, and risk profile. Claims of conformance should name the tested build, devices, operating-system versions, test methods, exclusions, and reviewer, because a checklist alone cannot prove secure runtime behavior.

Strengths

  • Provides structured, uniquely identified mobile security requirements across major control groups.
  • Supports consistent scoping and traceability between development, testing, and assurance activities.
  • Connects requirements with mobile weakness and testing-guide resources in the same project.

Limitations

  • Requirements need platform-specific test procedures, applicability decisions, and retained evidence.
  • A claimed level or checklist completion is not equivalent to independent certification.

Best for

  • mobile security requirements
  • assessment scoping
  • secure mobile development
  • assurance traceability

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Provides structured, uniquely identified mobile security requirements across major control groups; principal limitation: Requirements need platform-specific test procedures, applicability decisions, and retained evidence.

Audience

  • mobile developers
  • application security engineers
  • mobile penetration testers
  • software buyers

Formats

  • verification standard
  • requirements catalog
  • weakness mappings
  • downloadable document
  • translations

Keywords

  • mobile-security
  • application-security
  • security-requirements
  • security-verification
  • android-security
  • ios-security
  • privacy

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.