Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Identity Security

5 sources

Identity SecurityAssessment tier A

BloodHound

SpecterOps

Visit source : BloodHound

BloodHound is an identity attack-path management platform that collects and models relationships in Active Directory and supported cloud identity environments as a graph. Analysts query paths connecting users, groups, computers, sessions, permissions, and control relationships to identify how an attacker could reach high-value assets. Community Edition provides an open operational foundation, while commercial capabilities extend management and remediation workflows. Graph edges represent modeled possibilities based on collected data, not proof of compromise; collection scope, privileges, freshness, and sensitive graph storage require careful governance.

Source type
Open Core
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

BloodHound is an identity attack-path management platform that collects and models relationships in Active Directory and supported cloud identity environments as a graph. Analysts query paths connecting users, groups, computers, sessions, permissions, and control relationships to identify how an attacker could reach high-value assets. Community Edition provides an open operational foundation, while commercial capabilities extend management and remediation workflows. Graph edges represent modeled possibilities based on collected data, not proof of compromise; collection scope, privileges, freshness, and sensitive graph storage require careful governance. Authorized identity defenders can collect directory and session relationships with supported collectors, define high-value assets, investigate shortest or unusual paths, and prioritize changes that break multiple routes. Red teams can use the same model to test exposure hypotheses, while SpecterOps research and Microsoft documentation explain edge semantics and underlying controls. Editions, collectors, schemas, and queries evolve, so document exact versions and collection methods. Use least-privileged collection identities where supported, obtain approval for session or cloud data, encrypt exports, restrict graph access, and delete stale copies according to policy. Recollect after remediation and validate effective permissions directly; an apparent path may be stale, constrained, or missing prerequisite context.

Strengths

  • Makes complex identity relationships and multi-step privilege paths visible through graph analysis.
  • Supports both offensive path discovery and defensive prioritization of identity exposures.
  • Benefits from mature collectors, query patterns, documentation, and specialist research.

Limitations

  • Results are only as complete and current as collection coverage and modeled edge semantics.
  • The graph contains sensitive identity intelligence and must be tightly protected and interpreted.

Best for

  • Active Directory attack-path analysis
  • identity exposure prioritization
  • red-team planning
  • privilege relationship review

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Makes complex identity relationships and multi-step privilege paths visible through graph analysis; principal limitation: Results are only as complete and current as collection coverage and modeled edge semantics.

Audience

  • identity security teams
  • red teams
  • active directory administrators
  • security consultants

Formats

  • open-source software
  • graph interface
  • data collectors
  • query documentation
  • training material

Keywords

  • identity-security
  • active-directory
  • attack-paths
  • graph-analysis
  • privilege-escalation
  • cloud-identity
  • red-team

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Identity SecurityAssessment tier A

PingCastle

PingCastle / Netwrix

Visit source : PingCastle

PingCastle is an Active Directory security assessment tool centered on a health-check report that identifies risky configurations and relationships, groups findings into established risk themes, and provides prioritized remediation context. Additional analysis can map trusts and support broader domain review, making the tool useful for rapid baselining across mature or inherited estates. It is a vendor-maintained scanner with community and commercial usage considerations, not proof that an issue is exploitable. Collection privileges, rule transparency, version, environmental exceptions, and independent validation affect the reliability of conclusions.

Source type
Open Core
Access
Freemium
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

PingCastle is an Active Directory security assessment tool centered on a health-check report that identifies risky configurations and relationships, groups findings into established risk themes, and provides prioritized remediation context. Additional analysis can map trusts and support broader domain review, making the tool useful for rapid baselining across mature or inherited estates. It is a vendor-maintained scanner with community and commercial usage considerations, not proof that an issue is exploitable. Collection privileges, rule transparency, version, environmental exceptions, and independent validation affect the reliability of conclusions. Authorized administrators can run a point-in-time collection, review findings by risk category, trace supporting objects, and compare later reports after remediation. Trust analysis can reveal cross-domain dependencies that deserve architectural review, while BloodHound or direct directory checks can test specific attack-path hypotheses. Features and use differ by edition, so verify licensing, supported domains, and collection requirements. Reports contain sensitive identity topology and weaknesses; store them as security data, limit access, and avoid uploading them to unapproved services. Risk scores are prioritization aids rather than probabilities. Validate every material finding, assess business dependencies, stage directory changes, and preserve recovery access before remediation.

Strengths

  • Produces a fast, structured Active Directory risk baseline with prioritized findings and remediation context.
  • Surfaces configuration, privilege, trust, and hygiene issues that are difficult to inventory manually.
  • Supports repeat assessment and comparison across directory environments.

Limitations

  • Risk scores simplify context and require manual validation before remediation priority is accepted.
  • Licensing and available capabilities differ by usage scenario and product edition.

Best for

  • Active Directory health checks
  • identity risk baselining
  • trust mapping
  • remediation prioritization

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Produces a fast, structured Active Directory risk baseline with prioritized findings and remediation context; principal limitation: Risk scores simplify context and require manual validation before remediation priority is accepted.

Audience

  • active directory administrators
  • identity security teams
  • security consultants
  • auditors

Formats

  • assessment software
  • health-check reports
  • risk scoring
  • documentation
  • trust maps

Keywords

  • identity-security
  • active-directory
  • configuration-audit
  • identity-posture
  • privileged-access
  • trust-analysis
  • risk-assessment

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Identity SecurityAssessment tier A

Purple Knight

Semperis

Visit source : Purple Knight

Purple Knight is Semperis's free assessment tool for Active Directory and Microsoft Entra ID security posture. It checks indicators of exposure and compromise across identity configuration, privileged access, account hygiene, Kerberos, delegation, policies, and hybrid identity, then presents a score and remediation guidance. The tool can accelerate an initial review and provide a repeatable snapshot without deploying a permanent platform. It remains vendor-produced, requires registration and suitable directory access, and its scores or findings must be validated against business context rather than treated as certification or evidence of breach.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Purple Knight is Semperis's free assessment tool for Active Directory and Microsoft Entra ID security posture. It checks indicators of exposure and compromise across identity configuration, privileged access, account hygiene, Kerberos, delegation, policies, and hybrid identity, then presents a score and remediation guidance. The tool can accelerate an initial review and provide a repeatable snapshot without deploying a permanent platform. It remains vendor-produced, requires registration and suitable directory access, and its scores or findings must be validated against business context rather than treated as certification or evidence of breach. Identity teams can use a baseline report to identify investigation themes, assign owners, validate individual objects or policies, and rerun the assessment after approved changes. Compare it with PingCastle, BloodHound, Entra documentation, and manual evidence. Confirm the current download, supported directory and tenant configurations, license, data handling, and minimum privileges before use. Assessment output can reveal high-value accounts, trust relationships, and configuration weaknesses, so handle it as sensitive. An indicator of exposure is not necessarily exploitable, and an indicator of compromise is not incident confirmation; correlate it with logs, timelines, endpoint evidence, and known administrative activity before escalating.

Strengths

  • Provides a broad, quick posture assessment for on-premises and cloud Microsoft identity environments.
  • Pairs detected indicators with prioritized remediation guidance and readable reporting.
  • Can establish a low-friction baseline before a deeper identity-security program.

Limitations

  • Vendor-defined checks and scoring require contextual review and do not constitute independent assurance.
  • Access, registration, collection scope, and environment support can limit repeatable use.

Best for

  • identity posture snapshots
  • Active Directory exposure review
  • Entra ID assessment
  • remediation planning

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Provides a broad, quick posture assessment for on-premises and cloud Microsoft identity environments; principal limitation: Vendor-defined checks and scoring require contextual review and do not constitute independent assurance.

Audience

  • identity administrators
  • security assessment teams
  • active directory defenders
  • risk managers

Formats

  • assessment software
  • posture report
  • risk scoring
  • remediation guidance
  • vendor documentation

Keywords

  • identity-security
  • active-directory
  • microsoft-entra
  • identity-posture
  • configuration-audit
  • hybrid-identity
  • risk-assessment

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Identity SecurityAssessment tier B

SpecterOps Research

SpecterOps

Visit source : SpecterOps Research

The SpecterOps Resource Center collects original and practitioner-oriented material on identity attack paths, Active Directory, Microsoft cloud identity, Kerberos, tradecraft, BloodHound, detection, and adversary simulation. Publications, white papers, webinars, and conference-style material often explain the underlying mechanics behind tools and exposure models, making the archive valuable for advanced identity defenders and red teams. It is vendor-produced and selective rather than a neutral standards library; readers should separate durable protocol research from product guidance and corroborate high-impact defensive decisions with Microsoft documentation and testing.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

The SpecterOps Resource Center collects original and practitioner-oriented material on identity attack paths, Active Directory, Microsoft cloud identity, Kerberos, tradecraft, BloodHound, detection, and adversary simulation. Publications, white papers, webinars, and conference-style material often explain the underlying mechanics behind tools and exposure models, making the archive valuable for advanced identity defenders and red teams. It is vendor-produced and selective rather than a neutral standards library; readers should separate durable protocol research from product guidance and corroborate high-impact defensive decisions with Microsoft documentation and testing. Identity teams can use research articles to understand graph relationships, privilege primitives, attack prerequisites, and telemetry before interpreting BloodHound paths or designing detections. Presentations explain new techniques, while linked tools support controlled validation. Most material is freely accessible, but publication dates, product editions, and Microsoft platform versions matter; record them and follow cited primary references. Offensive examples belong only in authorized labs or assessments and may expose credentials or directory data. A technique described by the vendor is not evidence that it exists in a particular tenant. Confirm effective permissions, configuration, logs, and mitigations directly, and distinguish product capabilities from generally applicable identity research.

Strengths

  • Provides technically deep identity and attack-path research from specialists who build widely used tooling.
  • Connects offensive mechanics with defensive exposure management and detection considerations.
  • Offers multiple formats suitable for both conceptual study and operational application.

Limitations

  • Content reflects a vendor's research priorities and product ecosystem rather than comprehensive identity guidance.
  • Older tradecraft must be checked against current Microsoft platform behavior and mitigations.

Best for

  • identity attack research
  • Active Directory defense
  • BloodHound methodology
  • advanced red and blue team education

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Provides technically deep identity and attack-path research from specialists who build widely used tooling; principal limitation: Content reflects a vendor's research priorities and product ecosystem rather than comprehensive identity guidance.

Audience

  • identity security specialists
  • red teams
  • detection engineers
  • active directory defenders

Formats

  • research articles
  • white papers
  • webinars
  • conference presentations
  • technical guides

Keywords

  • identity-security
  • active-directory
  • cloud-identity
  • attack-paths
  • kerberos
  • red-team
  • detection-engineering

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Identity SecurityAssessment tier B

ADSecurity.org

Sean Metcalf

Visit source : ADSecurity.org

ADSecurity.org is Sean Metcalf's specialist knowledge archive on Microsoft Active Directory and Entra identity attack methods, security architecture, PowerShell, privileged access, credential theft, Kerberos, and defensive hardening. Long-form articles and presentation material are valued for explaining how enterprise identity abuse works and translating red-team observations into administrative controls. The site is an expert-authored secondary and original-practice resource, not official Microsoft documentation or a maintained benchmark. Publication dates matter because Windows defaults, cloud identity features, attack tooling, and recommended mitigations evolve.

Source type
Independent Technical
Access
Free
Evidence use
Mixed
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

ADSecurity.org is Sean Metcalf's specialist knowledge archive on Microsoft Active Directory and Entra identity attack methods, security architecture, PowerShell, privileged access, credential theft, Kerberos, and defensive hardening. Long-form articles and presentation material are valued for explaining how enterprise identity abuse works and translating red-team observations into administrative controls. The site is an expert-authored secondary and original-practice resource, not official Microsoft documentation or a maintained benchmark. Publication dates matter because Windows defaults, cloud identity features, attack tooling, and recommended mitigations evolve. Defenders can use an article to identify a privilege or protocol assumption, derive audit questions, and then validate it through current Microsoft documentation, directory queries, BloodHound relationships, or controlled testing. The archive is particularly useful for understanding why legacy practices, delegation, service accounts, or administrative tiers create attack paths. Access is free, but navigation spans material written across many platform generations; verify dates, referenced tools, operating-system support, and later corrections before applying advice. Commands and attack descriptions are dual-use and should run only under explicit authorization. Treat recommendations as expert analysis, not universal policy: assess operational dependencies, staged rollout, recovery access, telemetry, and compensating controls before changing production identity systems.

Strengths

  • Explains Active Directory attack and defense mechanics with substantial practitioner depth.
  • Connects protocol behavior, administrative design, and real attack paths rather than listing generic controls.
  • Preserves useful presentation and reference material from extensive identity-security field work.

Limitations

  • Update cadence is periodic and older recommendations require version-specific revalidation.
  • It is an expert publication, not an official product reference or comprehensive control standard.

Best for

  • Active Directory defense research
  • identity attack education
  • privileged access reviews
  • Kerberos security study

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 4/5

Explains Active Directory attack and defense mechanics with substantial practitioner depth; principal limitation: Update cadence is periodic and older recommendations require version-specific revalidation.

Audience

  • active directory administrators
  • identity security engineers
  • red teams
  • security architects

Formats

  • technical articles
  • conference presentations
  • security guidance
  • powershell examples
  • reference material

Keywords

  • identity-security
  • active-directory
  • kerberos
  • privileged-access
  • credential-security
  • powershell
  • identity-hardening

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Mobile Security

3 sources

Mobile SecurityAssessment tier A

Frida

Frida project

Visit source : Frida

Frida is an open-source dynamic instrumentation toolkit that lets analysts inject scripts into running processes and inspect or change function calls, memory, objects, and application behavior across Android, iOS, Windows, macOS, Linux, and other supported targets. Its APIs, command-line tools, language bindings, and examples make it central to mobile reversing, runtime testing, debugging, and security research. Frida is a powerful dual-use capability rather than a scanner: meaningful work requires platform internals and scripting knowledge, and use on third-party software or devices requires explicit authorization.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Advanced
Detailed assessment

Description

Frida is an open-source dynamic instrumentation toolkit that lets analysts inject scripts into running processes and inspect or change function calls, memory, objects, and application behavior across Android, iOS, Windows, macOS, Linux, and other supported targets. Its APIs, command-line tools, language bindings, and examples make it central to mobile reversing, runtime testing, debugging, and security research. Frida is a powerful dual-use capability rather than a scanner: meaningful work requires platform internals and scripting knowledge, and use on third-party software or devices requires explicit authorization. Analysts can attach to or spawn a test process, load JavaScript instrumentation, trace functions, inspect arguments and returns, and test hypotheses that static analysis or MobSF reports cannot resolve. MASTG supplies defensible testing contexts, while platform documentation explains the APIs and protections being observed. Frida tools, bindings, server, and target components must be version-compatible; operating-system protections, architecture, entitlements, root or jailbreak state, and application anti-instrumentation can materially change results. Scripts may alter state or expose credentials and personal data, so use isolated test devices, minimal privileges, controlled logging, and approved builds. An observed hook demonstrates that runtime condition, not a universal bypass or exploitable production weakness.

Strengths

  • Provides flexible runtime observation and modification across many operating systems and architectures.
  • Offers scriptable APIs, command-line tools, bindings, and an established extension ecosystem.
  • Enables analysis of behaviors that static inspection alone cannot expose.

Limitations

  • Effective instrumentation requires reverse-engineering, platform, and scripting expertise.
  • Targets can detect or resist instrumentation, and unauthorized use creates legal and ethical risk.

Best for

  • mobile dynamic analysis
  • runtime instrumentation
  • reverse engineering
  • security control bypass testing

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Provides flexible runtime observation and modification across many operating systems and architectures; principal limitation: Effective instrumentation requires reverse-engineering, platform, and scripting expertise.

Audience

  • mobile security researchers
  • reverse engineers
  • malware analysts
  • penetration testers

Formats

  • open-source software
  • dynamic instrumentation toolkit
  • api documentation
  • command-line tools
  • code examples

Keywords

  • mobile-security
  • dynamic-analysis
  • runtime-instrumentation
  • reverse-engineering
  • android-security
  • ios-security
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Mobile SecurityAssessment tier A

MobSF

Mobile Security Framework project

Visit source : MobSF

Mobile Security Framework, or MobSF, is an open-source platform for automated static and dynamic analysis of mobile applications. It can inspect Android and iOS packages, source archives, manifests, code, certificates, permissions, network behavior, and other artifacts through a web interface, REST APIs, Docker deployment, and CI integrations. MobSF is useful for rapid triage, repeatable baseline checks, and analyst workflow support. Automated findings can be incomplete or noisy, dynamic analysis needs a suitable test environment, and expert manual testing is still required for business logic, runtime context, and exploitability.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Mobile Security Framework, or MobSF, is an open-source platform for automated static and dynamic analysis of mobile applications. It can inspect Android and iOS packages, source archives, manifests, code, certificates, permissions, network behavior, and other artifacts through a web interface, REST APIs, Docker deployment, and CI integrations. MobSF is useful for rapid triage, repeatable baseline checks, and analyst workflow support. Automated findings can be incomplete or noisy, dynamic analysis needs a suitable test environment, and expert manual testing is still required for business logic, runtime context, and exploitability. A tester can submit an authorized build, review metadata and flagged patterns, export a report, then investigate material findings dynamically. Teams can map confirmed observations to MASVS and follow MASTG procedures for deeper manual verification. The software and documentation are free, but formats, engines, signatures, and runtime setup vary by release; pin the version. Treat uploaded applications, source, keys, URLs, and reports as sensitive, especially in shared deployments. Run untrusted packages only in isolated devices or emulators, limit network access, and never convert a severity label directly into risk without confirming reachability, behavior, data exposure, and business impact.

Strengths

  • Combines broad mobile static and dynamic analysis in a reproducible, self-hostable workflow.
  • Supports web, API, container, and CI usage for both analysts and development pipelines.
  • Produces centralized reports useful for triage and repeat assessments.

Limitations

  • Automated rules can yield false positives, miss context-dependent flaws, or overstate severity.
  • Dynamic capabilities require correctly configured devices or emulators and safe sample handling.

Best for

  • mobile application triage
  • automated mobile scanning
  • CI security checks
  • assessment preparation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Combines broad mobile static and dynamic analysis in a reproducible, self-hostable workflow; principal limitation: Automated rules can yield false positives, miss context-dependent flaws, or overstate severity.

Audience

  • mobile security testers
  • application security teams
  • mobile developers
  • malware analysts

Formats

  • open-source software
  • web application
  • rest api
  • documentation
  • analysis reports

Keywords

  • mobile-security
  • android-security
  • ios-security
  • static-analysis
  • dynamic-analysis
  • application-scanning
  • devsecops

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Mobile SecurityAssessment tier A

Apple Platform Security

Apple

Visit source : Apple Platform Security

Apple Platform Security is Apple's official guide to the security architecture of its hardware, operating systems, applications, and services. It documents the hardware root of trust, secure boot, system integrity, encryption and Data Protection, biometrics, app code signing and sandboxing, keychain services, network protections, account security, and device management across supported Apple platforms. The guide is authoritative for intended platform mechanisms but is not an independent assessment or mobile-app testing manual. Behavior and available controls depend on hardware generation, operating-system version, deployment mode, and configuration.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

Apple Platform Security is Apple's official guide to the security architecture of its hardware, operating systems, applications, and services. It documents the hardware root of trust, secure boot, system integrity, encryption and Data Protection, biometrics, app code signing and sandboxing, keychain services, network protections, account security, and device management across supported Apple platforms. The guide is authoritative for intended platform mechanisms but is not an independent assessment or mobile-app testing manual. Behavior and available controls depend on hardware generation, operating-system version, deployment mode, and configuration. Architects and administrators can use it to understand trust boundaries and select enrollment, authentication, key, application-distribution, and data-protection policies; mobile developers and testers can use it to interpret platform guarantees before applying MASVS and MASTG requirements. The guide is freely available online and as updated publications, so record the edition and verify feature availability for each device and OS release. Pair design claims with configuration profiles, entitlement and signing review, application tests, and observed fleet state. Apple descriptions explain supported architecture but cannot prove a third-party app, MDM policy, recovery process, or deployed device is correctly secured, and some implementation details remain intentionally abstract.

Strengths

  • Provides first-party technical detail across Apple hardware, operating-system, application, and service security.
  • Explains how roots of trust, cryptography, code signing, sandboxing, identity, and management interoperate.
  • Maintains a centralized, versioned reference suitable for architecture and assurance work.

Limitations

  • As vendor-authored documentation, it does not independently validate implementation effectiveness.
  • Exact behavior varies across hardware generations, operating systems, and management configurations.

Best for

  • Apple security architecture
  • iOS application design
  • device assurance reviews
  • enterprise deployment planning

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Provides first-party technical detail across Apple hardware, operating-system, application, and service security; principal limitation: As vendor-authored documentation, it does not independently validate implementation effectiveness.

Audience

  • ios developers
  • mobile security engineers
  • enterprise administrators
  • security architects

Formats

  • platform security guide
  • architecture documentation
  • web reference
  • downloadable document
  • deployment guidance

Keywords

  • mobile-security
  • ios-security
  • apple-security
  • platform-security
  • secure-boot
  • data-protection
  • application-sandboxing

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.