Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

AI Security

6 sources

AI SecurityAssessment tier A

garak

NVIDIA

Visit source : garak

garak is NVIDIA's open-source vulnerability scanner for large language models and related interfaces. It runs probe suites against model generators and uses detectors to identify behaviors such as prompt injection, data leakage, unsafe generation, hallucination, and known attack-pattern responses. Its plugin architecture and machine-readable results make it useful for exploratory testing and regression baselines across supported targets. Coverage depends on selected probes, detectors, configuration, and stochastic model behavior; a finding is a lead for investigation, not by itself proof of exploitability or business impact.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

garak is NVIDIA's open-source vulnerability scanner for large language models and related interfaces. It runs probe suites against model generators and uses detectors to identify behaviors such as prompt injection, data leakage, unsafe generation, hallucination, and known attack-pattern responses. Its plugin architecture and machine-readable results make it useful for exploratory testing and regression baselines across supported targets. Coverage depends on selected probes, detectors, configuration, and stochastic model behavior; a finding is a lead for investigation, not by itself proof of exploitability or business impact. Researchers can select generator adapters, probe families, detectors, and reporting options to test local models or supported services, then preserve outputs for triage or comparison after a change. It complements orchestration frameworks such as PyRIT and application-level suites such as Promptfoo by emphasizing broad probe coverage. The project is free and versioned on GitHub; pin releases, document model parameters, and repeat runs because model responses vary. Testing may consume paid APIs or produce harmful content, so use authorized endpoints, isolated output handling, rate limits, and human-reviewed success criteria.

Strengths

  • Offers a broad, extensible catalog of probes, model interfaces, and response detectors.
  • Supports repeatable command-line testing and machine-readable result analysis.
  • Makes common LLM attack patterns accessible for baseline and exploratory evaluation.

Limitations

  • Detector false positives and negatives require manual review and context-specific success criteria.
  • Probe coverage cannot represent every application workflow, guardrail, or downstream consequence.

Best for

  • LLM vulnerability exploration
  • model safety regression testing
  • attack-surface discovery
  • research comparisons

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Offers a broad, extensible catalog of probes, model interfaces, and response detectors; principal limitation: Detector false positives and negatives require manual review and context-specific success criteria.

Audience

  • ai security engineers
  • model evaluators
  • red teams
  • researchers

Formats

  • open-source software
  • command-line tool
  • documentation
  • plugins
  • scan reports

Keywords

  • ai-security
  • llm-security
  • vulnerability-scanning
  • adversarial-testing
  • prompt-injection
  • model-evaluation
  • red-team

Link validation: Reachable · checked 2026-09-07 · HTTP 200

AI SecurityAssessment tier A

PyRIT

Microsoft

Visit source : PyRIT

PyRIT, the Python Risk Identification Tool for generative AI, is Microsoft's open-source framework for orchestrating repeatable red-team and risk-identification workflows against generative-AI systems. It supports reusable datasets, prompt transformations, target connectors, scoring components, memory, and multi-turn attack orchestration rather than offering a single vulnerability scan. The project helps specialists build documented evaluation pipelines and compare defenses. It requires Python, model-access configuration, careful scoping, and human interpretation; successful prompts demonstrate observed behavior in a tested target, not universal model weakness or production impact.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

PyRIT, the Python Risk Identification Tool for generative AI, is Microsoft's open-source framework for orchestrating repeatable red-team and risk-identification workflows against generative-AI systems. It supports reusable datasets, prompt transformations, target connectors, scoring components, memory, and multi-turn attack orchestration rather than offering a single vulnerability scan. The project helps specialists build documented evaluation pipelines and compare defenses. It requires Python, model-access configuration, careful scoping, and human interpretation; successful prompts demonstrate observed behavior in a tested target, not universal model weakness or production impact. Red-teamers and evaluation engineers can compose seed prompts, converters, orchestrators, targets, and scorers into experiments that preserve conversations and results for review. This makes PyRIT useful for reproducing abuse cases, comparing guardrail changes, and generating evidence for an AI risk register. The code and documentation are public, but connectors, APIs, and dependencies change, so pin versions and protect model credentials and stored conversations. Use only authorized targets, control cost and harmful-output exposure, review scorer error, and pair results with threat models such as ATLAS plus manual validation of application-level consequences.

Strengths

  • Provides composable primitives for repeatable, multi-turn generative-AI security evaluations.
  • Preserves prompts, responses, scores, and workflow state for analysis and reporting.
  • Supports multiple targets, transformations, and scoring approaches through an extensible Python framework.

Limitations

  • Effective use requires coding, target credentials, responsible authorization, and domain-specific evaluation design.
  • Automated scores and attack success require human validation before drawing risk conclusions.

Best for

  • LLM red-team automation
  • repeatable adversarial evaluations
  • prompt attack orchestration
  • evaluation evidence collection

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Provides composable primitives for repeatable, multi-turn generative-AI security evaluations; principal limitation: Effective use requires coding, target credentials, responsible authorization, and domain-specific evaluation design.

Audience

  • ai red teams
  • security engineers
  • ai assurance teams
  • researchers

Formats

  • open-source software
  • python library
  • documentation
  • examples
  • notebooks

Keywords

  • ai-security
  • llm-security
  • red-team
  • adversarial-testing
  • prompt-injection
  • python
  • evaluation-framework

Link validation: Reachable · checked 2026-09-07 · HTTP 200

AI SecurityAssessment tier A

CSA AI Controls Matrix

Cloud Security Alliance

Visit source : CSA AI Controls Matrix

The Cloud Security Alliance AI Controls Matrix is a control framework for assessing and managing risks in AI systems and the cloud environments supporting them. It translates governance, lifecycle, data, model, infrastructure, security, and operational concerns into control objectives that organizations can map to other frameworks and assurance activities. The matrix is useful for control inventories, gap assessments, procurement, and audit preparation. It is a broad governance artifact rather than a technical testing guide, and implementation quality depends on scoped responsibilities, evidence requirements, and organization-specific interpretation.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Cloud Security Alliance AI Controls Matrix is a control framework for assessing and managing risks in AI systems and the cloud environments supporting them. It translates governance, lifecycle, data, model, infrastructure, security, and operational concerns into control objectives that organizations can map to other frameworks and assurance activities. The matrix is useful for control inventories, gap assessments, procurement, and audit preparation. It is a broad governance artifact rather than a technical testing guide, and implementation quality depends on scoped responsibilities, evidence requirements, and organization-specific interpretation. Security, risk, compliance, and supplier-assurance teams can filter its control set, identify accountable parties, define evidence, and connect AI obligations to the broader CSA Cloud Controls Matrix. It also provides a useful bridge to NIST AI RMF and architecture guidance such as SAIF, but crosswalks do not prove equivalence. The artifact is free to download, although CSA’s resource page presents a login or account-creation flow; record the exact release because identifiers and mappings can change, and review applicable use terms. Controls should be tailored to the system boundary and validated through configuration review, logging evidence, model evaluation, and operational testing rather than scored from policy statements alone.

Strengths

  • Provides a structured control inventory spanning AI governance, technology, data, and operations.
  • Supports cross-framework mapping and assurance discussions in cloud-dependent AI environments.
  • Helps translate general AI risks into assignable organizational control objectives.

Limitations

  • Control statements require tailoring, implementation guidance, and evidence definitions before assessment.
  • The matrix does not replace hands-on adversarial testing or product-specific secure configuration.

Best for

  • AI control gap assessments
  • governance mapping
  • supplier assurance
  • audit preparation

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Provides a structured control inventory spanning AI governance, technology, data, and operations; principal limitation: Control statements require tailoring, implementation guidance, and evidence definitions before assessment.

Audience

  • governance teams
  • cloud security architects
  • auditors
  • ai risk managers

Formats

  • control matrix
  • framework
  • spreadsheet
  • mapping guidance
  • assurance resource

Keywords

  • ai-security
  • ai-governance
  • control-framework
  • cloud-security
  • risk-assessment
  • compliance-mapping
  • supplier-assurance

Link validation: Reachable · checked 2026-09-07 · HTTP 200

AI SecurityAssessment tier A

NCSC AI Security Guidance

UK National Cyber Security Centre

Visit source : NCSC AI Security Guidance

The NCSC Guidelines for Secure AI System Development provide government-backed recommendations for providers of AI systems across secure design, development, deployment, and operation and maintenance. The guidance emphasizes ownership of security outcomes, threat modeling, supply-chain controls, asset protection, incident management, logging, and secure defaults. It is concise enough to use as a lifecycle checklist and was developed with international partners. It does not define exhaustive technical tests or regulatory compliance, so teams should pair it with platform standards, control catalogs, and adversarial evaluation.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The NCSC Guidelines for Secure AI System Development provide government-backed recommendations for providers of AI systems across secure design, development, deployment, and operation and maintenance. The guidance emphasizes ownership of security outcomes, threat modeling, supply-chain controls, asset protection, incident management, logging, and secure defaults. It is concise enough to use as a lifecycle checklist and was developed with international partners. It does not define exhaustive technical tests or regulatory compliance, so teams should pair it with platform standards, control catalogs, and adversarial evaluation. Product owners, engineers, security architects, and suppliers can turn each guideline into review questions, contractual expectations, accountable owners, and evidence requests across the lifecycle. The document is particularly useful when procurement and engineering teams need common language for model provenance, deployment protections, monitoring, updates, and responsible release. Access is free, but users should note the published edition and check partner or NCSC updates. Pair it with NIST AI RMF for risk governance, OWASP or ATLAS for concrete threat hypotheses, and platform-specific hardening. A checklist response without architecture evidence or testing is not assurance.

Strengths

  • Organizes security responsibilities across the complete AI system lifecycle.
  • Carries public-sector authority and reflects collaboration among multiple international agencies.
  • Emphasizes secure-by-design ownership, supply-chain risk, monitoring, and incident response.

Limitations

  • Recommendations are intentionally high level and do not provide detailed test cases.
  • The document is guidance, not evidence of compliance or system assurance.

Best for

  • secure AI lifecycle reviews
  • supplier requirements
  • security architecture checklists
  • policy development

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.6/5
  • Transparency 5/5

Organizes security responsibilities across the complete AI system lifecycle; principal limitation: Recommendations are intentionally high level and do not provide detailed test cases.

Audience

  • ai system providers
  • security architects
  • engineering leaders
  • procurement teams

Formats

  • government guidance
  • lifecycle checklist
  • principles
  • implementation recommendations

Keywords

  • ai-security
  • secure-by-design
  • ai-lifecycle
  • supply-chain-security
  • threat-modeling
  • incident-response
  • government-guidance

Link validation: Reachable · checked 2026-09-07 · HTTP 200

AI SecurityAssessment tier A

Google Secure AI Framework

Google

Visit source : Google Secure AI Framework

Google's Secure AI Framework, or SAIF, presents a conceptual framework and implementation resources for protecting AI systems using security foundations adapted to AI-specific risks. The site covers model and data protection, detection and response, automated defenses, risk contextualization, agent security, and a self-assessment workflow. It is useful for architecture discussions and program planning, particularly in organizations already applying secure-by-design practices. SAIF remains vendor-authored guidance rather than an independent standard, and teams must translate its principles into product-specific requirements and measurable controls.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Google's Secure AI Framework, or SAIF, presents a conceptual framework and implementation resources for protecting AI systems using security foundations adapted to AI-specific risks. The site covers model and data protection, detection and response, automated defenses, risk contextualization, agent security, and a self-assessment workflow. It is useful for architecture discussions and program planning, particularly in organizations already applying secure-by-design practices. SAIF remains vendor-authored guidance rather than an independent standard, and teams must translate its principles into product-specific requirements and measurable controls. Architects can use the framework to structure design reviews across training data, models, applications, infrastructure, supply chains, and operations, while maturity material helps identify owners and improvement priorities. Its agent guidance is relevant where systems can invoke tools or take consequential actions. Public resources can be mapped to NIST AI RMF, NCSC lifecycle guidance, or CSA controls, but mappings require interpretation. Confirm publication dates because recommendations evolve quickly. SAIF does not demonstrate that a Google or third-party product is secure; validate configurations, abuse cases, telemetry, and recovery procedures in the deployed environment.

Strengths

  • Connects established security practices with risks specific to models, data pipelines, and agents.
  • Provides architecture-oriented guidance and self-assessment material beyond a simple risk list.
  • Frames AI security across development, deployment, monitoring, and response.

Limitations

  • The framework is vendor-authored and is not a certification or independent assurance standard.
  • Principles still need system-specific control definitions, ownership, and validation criteria.

Best for

  • AI security architecture
  • program maturity assessment
  • agent security reviews
  • secure AI lifecycle planning

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Connects established security practices with risks specific to models, data pipelines, and agents; principal limitation: The framework is vendor-authored and is not a certification or independent assurance standard.

Audience

  • security architects
  • ai platform teams
  • risk managers
  • engineering leaders

Formats

  • framework
  • implementation guidance
  • self-assessment
  • architecture resources
  • case examples

Keywords

  • ai-security
  • secure-ai-framework
  • agentic-ai
  • security-architecture
  • ai-risk-management
  • secure-design
  • defense-in-depth

Link validation: Reachable · checked 2026-09-07 · HTTP 200

AI SecurityAssessment tier A

Promptfoo

Promptfoo

Visit source : Promptfoo

Promptfoo is an evaluation and red-team framework for testing prompts, models, agents, and AI application workflows from configuration-driven test suites. Its documentation covers assertions, datasets, providers, CI integration, attack plugins, graders, and result comparison, allowing functional quality and security cases to run together. It is practical for development teams that want repeatable tests close to delivery pipelines. Results remain dependent on test design, evaluator quality, model variability, and target instrumentation, while hosted enterprise features differ from the open-source command-line project.

Source type
Open Core
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Promptfoo is an evaluation and red-team framework for testing prompts, models, agents, and AI application workflows from configuration-driven test suites. Its documentation covers assertions, datasets, providers, CI integration, attack plugins, graders, and result comparison, allowing functional quality and security cases to run together. It is practical for development teams that want repeatable tests close to delivery pipelines. Results remain dependent on test design, evaluator quality, model variability, and target instrumentation, while hosted enterprise features differ from the open-source command-line project. Developers can define providers, prompts, variables, expected properties, and adversarial plugins in source-controlled configurations, review comparative outputs, and enforce selected thresholds in CI. That supports release regression checks and reproducible investigation across model or guardrail changes. The documentation and core tooling are publicly available, but provider calls may cost money and hosted or enterprise capabilities require separate evaluation. Pin versions and preserve configuration, seeds where supported, evaluator details, and raw evidence. Never equate a passing suite with complete security: complement it with OWASP or ATLAS threat modeling, PyRIT or garak coverage, manual abuse testing, and application telemetry.

Strengths

  • Combines AI quality evaluation and adversarial testing in reproducible, configuration-driven workflows.
  • Integrates with varied providers, application endpoints, graders, and CI pipelines.
  • Supports side-by-side result inspection useful for regression analysis.

Limitations

  • Coverage and conclusions are only as strong as the selected assertions, plugins, and evaluators.
  • Open-source and commercial capabilities must be distinguished when planning adoption.

Best for

  • AI application regression tests
  • LLM red teaming
  • prompt and model comparison
  • CI security gates

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Combines AI quality evaluation and adversarial testing in reproducible, configuration-driven workflows; principal limitation: Coverage and conclusions are only as strong as the selected assertions, plugins, and evaluators.

Audience

  • ai application developers
  • security engineers
  • quality engineers
  • red teams

Formats

  • open-source software
  • command-line tool
  • documentation
  • configuration examples
  • test reports

Keywords

  • ai-security
  • llm-security
  • red-team
  • model-evaluation
  • regression-testing
  • ci-cd
  • prompt-testing

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Identity Security

1 source

Identity SecurityAssessment tier A

Microsoft Entra Documentation

Microsoft

Visit source : Microsoft Entra Documentation

Microsoft Entra documentation is the first-party technical reference for the Entra identity product family, including identity and access management, authentication, Conditional Access, identity protection, governance, workload identities, application integration, external identities, permissions, hybrid identity, and monitoring. It is the authoritative source for supported features, configuration procedures, APIs, limitations, and licensing notes. The collection changes with the service and can be difficult to navigate; administrators must confirm tenant licensing and rollout state, test policy interactions, preserve break-glass access, and supplement vendor guidance with independent threat and posture assessment.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Microsoft Entra documentation is the first-party technical reference for the Entra identity product family, including identity and access management, authentication, Conditional Access, identity protection, governance, workload identities, application integration, external identities, permissions, hybrid identity, and monitoring. It is the authoritative source for supported features, configuration procedures, APIs, limitations, and licensing notes. The collection changes with the service and can be difficult to navigate; administrators must confirm tenant licensing and rollout state, test policy interactions, preserve break-glass access, and supplement vendor guidance with independent threat and posture assessment. Architects, administrators, developers, and defenders can use its architecture, procedure, API, and telemetry references. Azure security documentation provides the wider cloud context, while BloodHound, Purple Knight, and SpecterOps research can surface attack-path questions for validation. Documentation is free, but feature names, portals, Microsoft Graph interfaces, defaults, preview status, regional availability, and license tiers change continuously. Record tenant state and test dates. Roll out Conditional Access and privilege changes gradually with report-only or scoped testing where available, exclude emergency accounts carefully, and verify observed enforcement. First-party documentation describes supported behavior, not the correctness of a specific tenant.

Strengths

  • Provides current first-party configuration and conceptual guidance for Microsoft cloud identity services.
  • Covers users, workloads, applications, governance, protection, hybrid integration, and operational monitoring.
  • Documents APIs, prerequisites, licensing, and feature-specific behavior needed for implementation.

Limitations

  • Rapid product evolution, renaming, and licensing differences can make guidance tenant-specific.
  • Official documentation explains supported controls but does not independently assess a tenant's exposure.

Best for

  • Entra ID configuration
  • cloud identity architecture
  • Conditional Access design
  • identity governance implementation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Provides current first-party configuration and conceptual guidance for Microsoft cloud identity services; principal limitation: Rapid product evolution, renaming, and licensing differences can make guidance tenant-specific.

Audience

  • identity administrators
  • cloud security architects
  • application developers
  • security operations teams

Formats

  • vendor documentation
  • concept articles
  • how-to guides
  • api reference
  • architecture guidance

Keywords

  • identity-security
  • microsoft-entra
  • cloud-identity
  • conditional-access
  • identity-governance
  • workload-identity
  • hybrid-identity

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

SOC

1 source

SOCAssessment tier A

Security Onion

Security Onion Solutions

Visit source : Security Onion

Security Onion is a free, open platform that integrates network visibility, host telemetry, intrusion detection, log management, hunting, dashboards, cases, and selected analysis tools into a defender-focused distribution. Its stack combines components such as Suricata, Zeek, Elastic Agent, osquery, Strelka, and OpenCanary with Security Onion interfaces for alerts and investigations. It is valuable for SOC labs and operational monitoring, but it is a platform to engineer rather than an appliance that creates coverage automatically. Sensor placement, storage, tuning, access control, updates, and analyst workflows determine its effectiveness.

Source type
Open Core
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Security Onion is a defender-focused security-monitoring platform from Security Onion Solutions that integrates network visibility, host telemetry, intrusion detection, log management, hunting, dashboards, cases, and investigation interfaces. Its distribution orchestrates components such as Suricata, Zeek, Elastic Agent, osquery, Strelka, and OpenCanary into a deployable sensor and analysis stack. Teams use it to build labs, place network sensors, ingest endpoint data, triage alerts, pivot into protocol and session records, preserve cases, and develop SOC workflows. The native Zeek and Suricata documentation remains essential for understanding their distinct logs and rule behavior; Wireshark supports packet-level verification when captures are available. Security Onion reduces integration work but is not an appliance that produces complete coverage after installation. Visibility depends on network topology, taps or span ports, encrypted traffic, endpoint enrollment, data retention, rule selection, parsing, and analyst staffing. A poorly sized or exposed deployment can lose packets, exhaust storage, leak sensitive traffic, or overwhelm analysts. Architects should model throughput and retention, secure management access, separate roles, tune detections, monitor sensor health, document upgrades, and test evidence paths. Alert counts and dashboards must be interpreted against actual collection quality and local threat hypotheses.

Strengths

  • Integrates network, endpoint, alert, hunting, and case workflows
  • Supports packet, protocol, file, event-log, and honeypot evidence
  • Scales from analyst labs to distributed monitoring grids

Limitations

  • Deployment, retention, sensor placement, and tuning require sustained engineering
  • Bundled tools and default detections do not guarantee complete visibility or coverage

Best for

  • SOC analyst labs
  • network security monitoring
  • threat-hunting platforms
  • integrated incident investigation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Integrates network, endpoint, alert, hunting, and case workflows; principal limitation: Deployment, retention, sensor placement, and tuning require sustained engineering.

Audience

  • SOC analysts
  • network defenders
  • threat hunters
  • security platform engineers

Formats

  • security distribution
  • web interfaces
  • documentation
  • detections
  • case-management platform

Keywords

  • soc
  • network-security-monitoring
  • intrusion-detection
  • threat-hunting
  • case-management
  • packet-capture
  • endpoint-telemetry
  • siem

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.