Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Network Security

3 sources

Network SecurityAssessment tier A

Wireshark

Wireshark Foundation

Visit source : Wireshark

Wireshark is a free, open-source network protocol analyzer for capturing traffic and interactively inspecting packets across hundreds of protocols. Its display filters, protocol dissectors, stream reconstruction, statistics, expert information, and command-line companion tools support troubleshooting, incident investigation, protocol research, and forensic review of packet captures. The project supplies user and developer guides, release notes, sample captures, community support, and training resources. Captures reflect only the monitored vantage point; encryption, offloading, packet loss, and asymmetric paths limit interpretation, while packet files can contain credentials or sensitive communications requiring controlled handling.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Wireshark is a free, open-source network protocol analyzer maintained by the Wireshark Foundation and project contributors. It captures or opens packet data and decodes hundreds of protocols through dissectors, display filters, stream reconstruction, conversation and endpoint statistics, expert information, graphs, and export functions. Command-line companions such as TShark support scripted processing. Network engineers use it to diagnose protocol and performance problems; incident responders inspect a bounded packet capture, filter on known hosts or sessions, reconstruct exchanges, and preserve packet numbers that support a finding. Zeek turns similar traffic into transaction logs, while Suricata evaluates signatures; Wireshark is especially useful for validating what the sensor received and how a protocol was interpreted. A capture represents one vantage point and time, not the complete network. Encryption hides payloads, asymmetric routing splits flows, packet loss removes evidence, checksum or segmentation offloading can create misleading artifacts, and dissectors may contain bugs or assumptions. Packet files contain credentials, tokens, personal information, or proprietary communications and may themselves exercise parser vulnerabilities. Capture only with authority, minimize scope, protect files and keys, use supported versions, preserve hashes and timestamps, and corroborate conclusions with endpoint and infrastructure evidence.

Strengths

  • Deep interactive decoding across a very broad protocol set
  • Powerful filtering, reconstruction, statistics, and command-line workflows
  • Extensible dissector ecosystem supports protocol and forensic research

Limitations

  • Packet visibility is constrained by capture position, encryption, and collection quality
  • Large captures are resource intensive and may contain highly sensitive data

Best for

  • packet-level troubleshooting
  • network forensics
  • protocol analysis
  • malware traffic examination

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Deep interactive decoding across a very broad protocol set; principal limitation: Packet visibility is constrained by capture position, encryption, and collection quality.

Audience

  • network engineers
  • SOC analysts
  • incident responders
  • protocol researchers

Formats

  • desktop software
  • command-line tools
  • documentation
  • sample captures
  • developer guides

Keywords

  • network-security
  • wireshark
  • packet-analysis
  • network-forensics
  • protocol-analysis
  • pcap
  • traffic-analysis
  • incident-response

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Network SecurityAssessment tier A

Suricata

Open Information Security Foundation

Visit source : Suricata

Suricata is the Open Information Security Foundation's high-performance, open-source engine for network intrusion detection, inline prevention, network security monitoring, and packet processing. It performs signature inspection, application-layer protocol parsing, file extraction, flow tracking, and structured EVE JSON logging, with rules commonly managed through the wider Suricata ecosystem. It supports sensors, gateways, and embedded integrations, but effective operation depends on representative traffic, correct capture architecture, suitable rules, and continuous tuning. Encryption, packet loss, noisy signatures, and inline performance constraints can create blind spots or operational impact.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Suricata is the Open Information Security Foundation's high-performance, open-source engine for network intrusion detection, inline prevention, network security monitoring, and packet processing. It combines signature evaluation with flow tracking, application-layer protocol parsing, file inspection or extraction, metadata generation, and structured EVE JSON output. Defenders deploy it on passive sensors to alert and enrich investigations or inline where reviewed rules can block traffic. A practical workflow validates capture quality, selects and manages rules, tests representative traffic, forwards EVE records to a SIEM, and tunes thresholds or suppressions with rationale. Security Onion can integrate the engine, Wireshark helps verify packet interpretation, and Zeek supplies complementary transaction-oriented telemetry. Suricata's alert is a rule match in observed traffic, not proof of compromise or attacker identity. Encryption limits content inspection, packet loss and asymmetric paths break context, stale or generic signatures create misses and noise, and protocol evasion can challenge parsing. Inline use adds latency and outage risk when rules or capacity are wrong. Operators should review provenance and licensing, stage updates, monitor drops and resource saturation, protect extracted files, restrict rule-writing privileges, maintain rollback procedures, and correlate alerts with endpoint and identity evidence.

Strengths

  • Combines signature detection, protocol parsing, file extraction, and structured logging
  • Supports passive IDS and inline IPS deployment models
  • Open rule and integration ecosystem fits broader monitoring pipelines

Limitations

  • Rule quality and tuning strongly affect false-positive and false-negative rates
  • Encryption, capture loss, and inline capacity can limit visibility or availability

Best for

  • network intrusion detection
  • inline threat prevention
  • network telemetry pipelines
  • packet and file inspection

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Combines signature detection, protocol parsing, file extraction, and structured logging; principal limitation: Rule quality and tuning strongly affect false-positive and false-negative rates.

Audience

  • network security engineers
  • SOC analysts
  • detection engineers
  • security platform teams

Formats

  • network engine
  • documentation
  • rules
  • eve-json telemetry
  • training

Keywords

  • network-security
  • suricata
  • ids
  • ips
  • network-security-monitoring
  • protocol-analysis
  • packet-inspection
  • detection-engineering

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Network SecurityAssessment tier A

Zeek

Zeek Project

Visit source : Zeek

Zeek is an open-source passive network monitor that converts observed traffic into rich, structured protocol and transaction logs, file events, notices, and customizable outputs. Its event-driven scripting language and community package ecosystem let defenders add protocol analysis, policy logic, enrichment, and behavioral detections without placing Zeek inline as a blocking control. The project provides current and long-term-support documentation, packages, a browser playground, webinars, and community resources. Encrypted traffic, asymmetric visibility, packet loss, and local network architecture constrain conclusions, while custom scripts require testing for correctness and performance.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Zeek is an open-source passive network-security monitor that interprets observed traffic and emits structured protocol, connection, transaction, file, certificate, and notice records. Rather than acting primarily as an inline blocker, its event engine and scripting language let defenders express protocol-aware policy, enrichment, behavioral observations, and site-specific analytics. SOC teams place sensors at meaningful network boundaries, forward logs to a search platform, pivot from an alert into DNS, HTTP, TLS, or connection histories, and use scripts or community packages to add context. Security Onion integrates Zeek operationally; Wireshark provides packet-level inspection, while Suricata adds signature-driven IDS or IPS decisions. The project maintains current and long-term-support documentation, package tooling, a browser playground, webinars, and community resources. Zeek records what its sensor could parse, not everything that occurred. Encryption hides application content, asymmetric routing separates conversations, packet loss degrades state, capture offloading can distort packets, and unsupported or evasive protocols reduce visibility. Custom scripts and packages can introduce logic, privacy, or performance problems. Validate sensor placement and packet health, test code on representative traffic, pin trusted dependencies, protect sensitive logs, and corroborate high-impact findings with endpoint, identity, or packet evidence.

Strengths

  • Produces high-fidelity structured metadata across many application protocols
  • Event-driven scripting and packages support deep customization
  • Passive design enables visibility without becoming an inline enforcement point

Limitations

  • Encryption, packet loss, asymmetric routing, and poor sensor placement reduce visibility
  • Operational scaling and custom script performance require engineering expertise

Best for

  • network security monitoring
  • protocol analytics
  • network forensics
  • custom behavioral detection

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Produces high-fidelity structured metadata across many application protocols; principal limitation: Encryption, packet loss, asymmetric routing, and poor sensor placement reduce visibility.

Audience

  • network defenders
  • SOC analysts
  • detection engineers
  • network forensic analysts

Formats

  • network monitor
  • structured logs
  • documentation
  • scripts
  • packages
  • webinars

Keywords

  • network-security
  • zeek
  • network-security-monitoring
  • protocol-analysis
  • network-forensics
  • structured-logs
  • threat-hunting
  • scripting

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Training

5 sources

TrainingAssessment tier A

CyberDefenders

CyberDefenders

Visit source : CyberDefenders

CyberDefenders is a blue-team training platform offering investigation labs and role-oriented learning across digital forensics, incident response, threat hunting, malware analysis, network traffic, endpoint artifacts, cloud, and SOC operations. Challenges commonly provide realistic files such as packet captures, memory images, logs, disk artifacts, or malware-related evidence for analysis with standard tools, while structured paths and certifications add progression. The datasets and questions are curated and access varies by plan; solving a lab demonstrates specific analytical skills but not full incident command, evidence governance, or production-scale monitoring competence.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

CyberDefenders is a blue-team training platform offering investigation labs and role-oriented learning across digital forensics, incident response, threat hunting, malware analysis, network traffic, endpoint artifacts, cloud, and SOC operations. Challenges commonly provide realistic files such as packet captures, memory images, logs, disk artifacts, or malware-related evidence for analysis with standard tools, while structured paths and certifications add progression. The datasets and questions are curated and access varies by plan; solving a lab demonstrates specific analytical skills but not full incident command, evidence governance, or production-scale monitoring competence. Learners can access a case, select tools, answer evidence-backed questions, and compare their process with solutions. The format builds tool fluency and hypothesis testing beyond a simulated console, especially when paired with LetsDefend workflows or Malware-Traffic-Analysis.net packet cases. Labs, paths, cloud environments, certifications, and walkthrough access differ between free and paid plans; confirm current requirements and permitted artifact use. Some evidence may contain malware, malicious documents, credentials, or sensitive-looking synthetic data, so isolate analysis, disable accidental execution, and follow handling instructions. Correct answers demonstrate selected observations; maintain separate notes on provenance, timelines, confidence, alternative explanations, and investigative gaps to develop transferable practice.

Strengths

  • Provides artifact-driven defensive labs using common forensic, malware, endpoint, and network evidence.
  • Covers a broad range of blue-team specializations with structured paths and practical challenges.
  • Supports portfolio-style skill practice without requiring learners to generate every dataset.

Limitations

  • Curated questions can encourage answer finding instead of open-ended investigative decision making.
  • Lab and certification access varies across free and subscription offerings.

Best for

  • DFIR practice
  • blue-team investigations
  • threat hunting exercises
  • forensic tool familiarity

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Provides artifact-driven defensive labs using common forensic, malware, endpoint, and network evidence; principal limitation: Curated questions can encourage answer finding instead of open-ended investigative decision making.

Audience

  • blue-team analysts
  • incident responders
  • forensics students
  • threat hunters

Formats

  • investigation labs
  • forensic datasets
  • learning paths
  • challenges
  • certifications

Keywords

  • security-training
  • blue-team
  • dfir
  • incident-response
  • threat-hunting
  • network-forensics
  • malware-analysis

Link validation: Automated access restricted · checked 2026-09-07 · HTTP 403

TrainingAssessment tier A

LetsDefend

LetsDefend

Visit source : LetsDefend

LetsDefend is a blue-team training platform built around a simulated security operations center where learners triage alerts, inspect endpoint and network evidence, investigate phishing and malware, and follow incident-handling workflows. Guided paths and challenge material cover SOC fundamentals, SIEM use, threat intelligence, detection, and digital forensics, with free and paid access tiers. The simulation helps develop investigation habits and case documentation, but its interface, telemetry, and expected answers are curated; learners should supplement it with raw-tool practice, primary incident-response guidance, and experience handling incomplete real-world evidence.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

LetsDefend is a blue-team training platform built around a simulated security operations center where learners triage alerts, inspect endpoint and network evidence, investigate phishing and malware, and follow incident-handling workflows. Guided paths and challenge material cover SOC fundamentals, SIEM use, threat intelligence, detection, and digital forensics, with free and paid access tiers. The simulation helps develop investigation habits and case documentation, but its interface, telemetry, and expected answers are curated; learners should supplement it with raw-tool practice, primary incident-response guidance, and experience handling incomplete real-world evidence. Entry-level analysts can practice opening a case, testing alert hypotheses, enriching indicators, reconstructing activity, deciding disposition, and recording findings without access to a production SOC. Focused paths can reinforce phishing, endpoint, network, or malware concepts before moving to open-ended CyberDefenders artifacts. Course availability, paths, certificates, quotas, and features vary by account and subscription, so verify the current catalog before building a training plan. Treat any downloadable sample or indicator as untrusted and use isolated analysis systems. Platform scores measure performance against a designed scenario, not evidence-preservation discipline, incident command, customer communication, detection engineering, or the ability to handle missing, contradictory, and high-volume production telemetry.

Strengths

  • Centers learning on alert triage and investigation within a simulated SOC workflow.
  • Provides guided defensive paths spanning phishing, malware, network, endpoint, and incident response.
  • Offers immediate practice and feedback without requiring learners to build an enterprise lab.

Limitations

  • Curated telemetry and answer paths simplify uncertainty, scale, and collaboration found in production SOCs.
  • Useful content and progression features are divided between free and paid tiers.

Best for

  • entry-level SOC practice
  • alert triage
  • incident investigation workflows
  • blue-team career preparation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Centers learning on alert triage and investigation within a simulated SOC workflow; principal limitation: Curated telemetry and answer paths simplify uncertainty, scale, and collaboration found in production SOCs.

Audience

  • aspiring SOC analysts
  • junior defenders
  • security students
  • incident response trainees

Formats

  • simulated SOC
  • interactive investigations
  • learning paths
  • challenges
  • progress tracking

Keywords

  • security-training
  • soc-training
  • blue-team
  • alert-triage
  • incident-response
  • cti
  • dfir

Link validation: Reachable · checked 2026-09-07 · HTTP 200

TrainingAssessment tier A

PentesterLab

PentesterLab

Visit source : PentesterLab

PentesterLab provides hands-on web application security exercises that emphasize understanding vulnerabilities in code and reproducing exploitation against purpose-built targets. Its badges and learning tracks cover foundations through advanced authentication, authorization, injection, deserialization, cryptography, APIs, and code review, with both free exercises and paid platform access. The compact labs are effective for focused repetition and developer-oriented analysis. They remain deliberately vulnerable teaching environments, so successful completion does not establish broad penetration-testing methodology, production judgment, reporting ability, or authorization to apply techniques elsewhere.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

PentesterLab provides hands-on web application security exercises that emphasize understanding vulnerabilities in code and reproducing exploitation against purpose-built targets. Its badges and learning tracks cover foundations through advanced authentication, authorization, injection, deserialization, cryptography, APIs, and code review, with both free exercises and paid platform access. The compact labs are effective for focused repetition and developer-oriented analysis. They remain deliberately vulnerable teaching environments, so successful completion does not establish broad penetration-testing methodology, production judgment, reporting ability, or authorization to apply techniques elsewhere. Learners can inspect vulnerable implementations, manipulate requests against supplied applications, and connect a successful test to the coding mistake that enabled it. This suits testers and developers practicing server-side code review beyond black-box scanning. Free exercises offer an entry point, while Pro content, badges, and delivery options have separate access terms; check the current catalog and prerequisites. Pair exercises with OWASP ASVS for requirements, WSTG for assessment structure, and Web Security Academy for additional technique coverage. Use only provided targets. A lab solution does not establish that the same payload is safe, legal, or relevant in a client environment, and remediation should be validated independently.

Strengths

  • Pairs vulnerable applications with code-oriented explanations and focused exploitation goals.
  • Provides structured badges that progress from foundations to advanced web and review topics.
  • Supports repeated practice on narrow concepts without extensive environment setup.

Limitations

  • Most structured content requires a paid subscription and focuses primarily on web applications.
  • Purpose-built exercises simplify reconnaissance, client constraints, remediation, and reporting.

Best for

  • web vulnerability practice
  • secure code review training
  • application penetration testing
  • developer security education

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Pairs vulnerable applications with code-oriented explanations and focused exploitation goals; principal limitation: Most structured content requires a paid subscription and focuses primarily on web applications.

Audience

  • application security engineers
  • web penetration testers
  • developers
  • security students

Formats

  • interactive exercises
  • vulnerable applications
  • learning badges
  • code review labs
  • technical explanations

Keywords

  • security-training
  • web-security
  • application-security
  • hands-on-labs
  • code-review
  • penetration-testing
  • secure-development

Link validation: Reachable · checked 2026-09-07 · HTTP 200

TrainingAssessment tier A

TryHackMe

TryHackMe Ltd

Visit source : TryHackMe

TryHackMe is a browser-based cybersecurity learning platform offering guided lessons, isolated machines, challenges, role-oriented paths, and competitions across fundamentals, penetration testing, SOC analysis, security engineering, cloud, web, and AI security. Its integrated attack environment and beginner-friendly sequencing reduce setup friction, while free and subscription content support individual and organizational learning. The platform is effective for structured practice but uses simplified scenarios and its own progression model; completion does not replace production experience, independent reading, or authorization to test systems outside provided labs.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

TryHackMe is a browser-based cybersecurity learning platform offering guided lessons, isolated machines, challenges, role-oriented paths, and competitions across fundamentals, penetration testing, SOC analysis, security engineering, cloud, web, and AI security. Its integrated attack environment and beginner-friendly sequencing reduce setup friction, while free and subscription content support individual and organizational learning. The platform is effective for structured practice but uses simplified scenarios and its own progression model; completion does not replace production experience, independent reading, or authorization to test systems outside provided labs. New learners can follow introductory paths with explanations and tasks, while developing practitioners can choose role or topic rooms and use attached virtual targets to practice commands and investigation steps. Progress tracking helps structure study, and CyberDefenders or LetsDefend can add deeper evidence-driven blue-team cases. Availability, path names, room quality, browser-machine quotas, and included content differ between free, subscription, and organizational plans, so check current access before adopting a syllabus. Use only platform-assigned targets, never reuse real credentials, and keep downloaded artifacts isolated. Badges and completion percentages show platform activity, not independent proof of judgment, reporting skill, teamwork, or production competence.

Strengths

  • Offers guided, hands-on learning with browser-accessible machines and minimal setup burden.
  • Provides broad role-based paths from complete beginner through intermediate specialist topics.
  • Combines explanations, questions, practical exercises, progress tracking, and community features.

Limitations

  • Important paths and labs require a subscription, and content depth varies across rooms.
  • Purpose-built scenarios cannot reproduce the ambiguity and operational constraints of production work.

Best for

  • cybersecurity beginners
  • guided role-based learning
  • hands-on fundamentals
  • entry-level SOC and pentest practice

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Offers guided, hands-on learning with browser-accessible machines and minimal setup burden; principal limitation: Important paths and labs require a subscription, and content depth varies across rooms.

Audience

  • beginners
  • career changers
  • junior analysts
  • security students

Formats

  • interactive labs
  • learning paths
  • browser virtual machines
  • challenges
  • certifications

Keywords

  • security-training
  • hands-on-labs
  • beginner-learning
  • penetration-testing
  • soc-training
  • cloud-security
  • ctf

Link validation: Reachable · checked 2026-09-07 · HTTP 200

TrainingAssessment tier B

OverTheWire

OverTheWire

Visit source : OverTheWire

OverTheWire hosts free security wargames that teach Linux command-line use, networking, web security, cryptography, and exploitation through progressively unlocked challenge levels. Bandit is a widely used introduction to shell fundamentals, while later games demand deeper analysis and independent problem solving. Each level gives a constrained objective and access details rather than a full lesson, encouraging experimentation and documentation reading. The platform is intentionally sparse, can be frustrating without prerequisites, and does not provide a complete modern security curriculum, formal assessment, or production-like defensive workflow.

Source type
Independent Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

OverTheWire hosts free security wargames that teach Linux command-line use, networking, web security, cryptography, and exploitation through progressively unlocked challenge levels. Bandit is a widely used introduction to shell fundamentals, while later games demand deeper analysis and independent problem solving. Each level gives a constrained objective and access details rather than a full lesson, encouraging experimentation and documentation reading. The platform is intentionally sparse, can be frustrating without prerequisites, and does not provide a complete modern security curriculum, formal assessment, or production-like defensive workflow. Learners connect to supplied hosts, recover the credential or flag for the next level, and build familiarity with shells, files, permissions, protocols, source inspection, and debugging. The best practice is to keep personal notes, consult manual pages, and explain the mechanism after solving rather than copy public solutions. Games are free, but availability, connection details, challenge assumptions, and software versions may change; consult each game's current page. Use only assigned hosts and follow community rules. OverTheWire pairs well with structured instruction from OpenSecurityTraining2 or TryHackMe, but its flags do not assess secure design, remediation, evidence handling, reporting, teamwork, or the ambiguity of operational incidents.

Strengths

  • Provides free, durable, progressively structured practice with real command-line interaction.
  • Encourages independent reasoning and primary documentation use rather than guided button clicking.
  • Bandit offers an effective bridge from basic Linux usage into security challenges.

Limitations

  • Minimal instruction and aging challenge assumptions can create barriers or require external research.
  • Wargames emphasize narrow challenge solving rather than comprehensive role readiness.

Best for

  • Linux command-line practice
  • introductory wargames
  • independent problem solving
  • CTF preparation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.6/5
  • Transparency 4/5

Provides free, durable, progressively structured practice with real command-line interaction; principal limitation: Minimal instruction and aging challenge assumptions can create barriers or require external research.

Audience

  • security beginners
  • students
  • CTF participants
  • self-directed learners

Formats

  • online wargames
  • remote challenge hosts
  • level instructions
  • community support

Keywords

  • security-training
  • wargames
  • linux-security
  • command-line
  • ctf
  • web-security
  • exploit-development

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.