Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Academic

1 source

AcademicAssessment tier A

USENIX Security Symposium

USENIX Association

Visit source : USENIX Security Symposium

The USENIX Security Symposium is an annual research venue for security and privacy of computer systems and networks. Its archive links each year’s program, formally reviewed papers, open proceedings, presentations, and often research artifacts, spanning systems, software, networks, privacy, hardware, usable security, and machine learning. It is a high-quality source for original methods and empirical studies, with papers freely available after publication. Individual results can still have narrow datasets, assumptions, or reproducibility limits and should not be converted directly into production guidance without validation and follow-up research.

Source type
Academic
Access
Free
Evidence use
Peer Reviewed Primary
Maintenance
Periodic
Skill level
Advanced
Detailed assessment

Description

The USENIX Security Symposium is an annual research venue for security and privacy of computer systems and networks. Its archive links each year’s program, formally reviewed papers, open proceedings, presentations, and often research artifacts, spanning systems, software, networks, privacy, hardware, usable security, and machine learning. It is a high-quality source for original methods and empirical studies, with papers freely available after publication. Researchers should read the threat model, related work, methodology, dataset, evaluation, ethics discussion, and limitations before adopting a result. Presentations can accelerate orientation, while released code and artifacts enable controlled replication and comparison with later work. Practitioners can translate a paper into hypotheses or design questions, then validate them against current platforms and operational constraints rather than treating publication as deployment guidance. Cross-check preprint revisions, artifact evaluations, follow-up papers, and disclosed conflicts where relevant. Individual results can still have narrow datasets, assumptions, or reproducibility limits and should not be converted directly into production guidance without validation and follow-up research.

Strengths

  • Long-running refereed venue for original, technically deep security and privacy research
  • Open proceedings and individual papers provide durable access to primary research
  • Artifact policies improve transparency and provide opportunities for reproducibility review

Limitations

  • Peer review does not guarantee that every result generalizes or reproduces outside its studied conditions
  • Research papers are advanced and may not include production-ready mitigations or current operational context

Best for

  • Advanced security literature review
  • Finding peer-reviewed methods and measurements
  • Research replication and artifact study
  • Tracking emerging systems-security topics

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.9/5
  • Transparency 5/5

Long-running refereed venue for original, technically deep security and privacy research; principal limitation: Peer review does not guarantee that every result generalizes or reproduces outside its studied conditions.

Audience

  • security researchers
  • graduate students
  • advanced practitioners
  • security engineers
  • educators

Formats

  • peer-reviewed papers
  • conference proceedings
  • research artifacts
  • presentation videos
  • slides
  • bibliographic records

Keywords

  • academic
  • peer-reviewed-research
  • security-research
  • privacy
  • systems-security
  • open-access
  • research-artifacts
  • conference

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Datasets

2 sources

DatasetsAssessment tier A

Stratosphere IPS Datasets

Stratosphere Laboratory, Czech Technical University in Prague

Visit source : Stratosphere IPS Datasets

The Stratosphere Laboratory publishes network-security datasets derived from controlled captures and research projects, including botnet, malware, normal, Internet-of-Things, and mixed traffic. Dataset pages commonly provide scenario descriptions, labels, capture files or flows, timing, and citation or licensing information, enabling reproducible intrusion-detection, traffic-analysis, and machine-learning experiments. The collection is valuable because provenance and malicious scenarios are documented by the producing laboratory. Researchers must still inspect each dataset's labeling method, balance, age, privacy treatment, license, and environment before claiming that experimental performance generalizes to production networks.

Source type
Academic
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Stratosphere Laboratory publishes network-security datasets derived from controlled captures and research projects, including botnet, malware, normal, Internet-of-Things, and mixed traffic. Dataset pages commonly provide scenario descriptions, labels, capture files or flows, timing, and citation or licensing information, enabling reproducible intrusion-detection, traffic-analysis, and machine-learning experiments. The collection is valuable because provenance and malicious scenarios are documented by the producing laboratory. Researchers must still inspect each dataset's labeling method, balance, age, privacy treatment, license, and environment before claiming that experimental performance generalizes to production networks. Analysts can select a scenario, retain its metadata, inspect packets or flows, reproduce published features, and test a detection or model against known activity. Educators can use captures for exercises; comparing UNB CIC datasets shows how collection design changes results. Formats, labels, and licenses vary; cite the individual dataset and version, not only the overview. Treat captures as potentially hostile and analyze them in isolated tooling. Prevent train-test leakage by splitting on scenarios or time where appropriate, report class balance and preprocessing, and evaluate on independent contemporary traffic before making operational claims. Document missing packets, ambiguous ground truth, and environmental artifacts as limitations.

Strengths

  • Provides original, scenario-documented network captures with malicious and benign traffic labels.
  • Supports reproducible IDS, traffic classification, malware behavior, and machine-learning research.
  • Publishes per-dataset context, attribution, and access information from the producing laboratory.

Limitations

  • Controlled traffic, class balance, capture age, and labeling choices can create unrealistic model performance.
  • Licenses, formats, features, and documentation quality vary across individual datasets.

Best for

  • network intrusion research
  • malware traffic analysis
  • machine-learning experiments
  • dataset benchmarking

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Provides original, scenario-documented network captures with malicious and benign traffic labels; principal limitation: Controlled traffic, class balance, capture age, and labeling choices can create unrealistic model performance.

Audience

  • security researchers
  • data scientists
  • network defenders
  • students

Formats

  • packet captures
  • network flows
  • labeled datasets
  • scenario documentation
  • research publications

Keywords

  • security-datasets
  • network-security
  • intrusion-detection
  • malware-traffic
  • botnet
  • machine-learning
  • packet-analysis

Link validation: Reachable · checked 2026-09-07 · HTTP 200

DatasetsAssessment tier A

UNB CIC Datasets

Canadian Institute for Cybersecurity, University of New Brunswick

Visit source : UNB CIC Datasets

The Canadian Institute for Cybersecurity at the University of New Brunswick publishes academic datasets for intrusion detection, network traffic, malware, botnets, Android, Internet-of-Things, VPN and Tor analysis, and related security research. Well-known collections such as CICIDS and CSE-CIC-IDS provide labeled traffic or derived features used in teaching and comparative machine-learning studies. They are convenient benchmarks, not faithful samples of every production environment. Users must examine generation methodology, known labeling or feature issues, class leakage, licensing, dates, and existing critiques before treating model accuracy as operational evidence.

Source type
Academic
Access
Free
Evidence use
Primary Operational
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Canadian Institute for Cybersecurity at the University of New Brunswick publishes academic datasets for intrusion detection, network traffic, malware, botnets, Android, Internet-of-Things, VPN and Tor analysis, and related security research. Well-known collections such as CICIDS and CSE-CIC-IDS provide labeled traffic or derived features used in teaching and comparative machine-learning studies. They are convenient benchmarks, not faithful samples of every production environment. Users must examine generation methodology, known labeling or feature issues, class leakage, licensing, dates, and existing critiques before treating model accuracy as operational evidence. Researchers should use each dataset page and paper to record topology, schedule, labels, features, preprocessing, and permitted use before reproducing a baseline. Instructors can use selected records to teach classification and evaluation, while Stratosphere datasets provide alternative scenarios and provenance. Downloads and conditions differ across collections; cite the exact release and preserve hashes where possible. Analyze packet captures and malware-related content in isolated environments. Use time-, host-, or scenario-aware splits instead of random rows when leakage is plausible, compare against simple baselines, and report precision, recall, class distribution, and external validation. High benchmark accuracy alone does not demonstrate useful production detection.

Strengths

  • Offers numerous documented, labeled datasets spanning widely studied cybersecurity problems.
  • Supports reproducible academic experiments, teaching, and comparison with published research.
  • Provides both raw or processed artifacts and methodological context for many collections.

Limitations

  • Synthetic environments, duplicated records, feature leakage, and labeling issues can bias evaluation.
  • Dataset age and attack selection limit claims about current production detection performance.

Best for

  • academic security research
  • intrusion-detection experiments
  • machine-learning education
  • benchmark replication

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 5/5

Offers numerous documented, labeled datasets spanning widely studied cybersecurity problems; principal limitation: Synthetic environments, duplicated records, feature leakage, and labeling issues can bias evaluation.

Audience

  • academic researchers
  • data scientists
  • security students
  • intrusion-detection engineers

Formats

  • labeled datasets
  • packet captures
  • derived network features
  • dataset documentation
  • research papers

Keywords

  • security-datasets
  • intrusion-detection
  • network-security
  • machine-learning
  • malware-research
  • iot-security
  • academic-research

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Network Security

1 source

Network SecurityAssessment tier A

SANS Internet Storm Center

SANS Technology Institute

Visit source : SANS Internet Storm Center

The SANS Internet Storm Center combines practitioner-written handler diaries, podcasts, DShield sensor data, port and scanning trends, threat-feed views, and a public API. Volunteer handlers interpret current malicious traffic and emerging operational problems, giving defenders a useful field perspective between formal advisories and long-form research. Individual diary entries vary in depth and are not peer reviewed, while DShield represents sampled contributed telemetry rather than the entire internet. Corroborate observations before turning them into attribution, prevalence claims, or permanent blocking policy.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The SANS Internet Storm Center is a free, community-driven operational-security service within the SANS Technology Institute. It publishes daily handler diaries and podcasts and uses the DShield distributed sensor and log-sharing system to summarize unwanted internet traffic, port activity, scanning behavior, and emerging attack trends. SOC analysts can use diaries for rapid orientation, then follow cited samples, commands, packet details, or external advisories to build time-bounded hunting and detection hypotheses. Network defenders can compare a local spike with DShield trends or use the API and public summaries as supporting context during triage. The source is especially effective for understanding what experienced practitioners are seeing now, but each diary reflects an individual handler's evidence and interpretation rather than a uniform editorial or peer-review process. DShield is based on voluntary, unevenly distributed observations and cannot establish global prevalence or whether a specific organization was targeted or compromised. Preserve the diary date, distinguish observed traffic from inference, and corroborate important claims with vendor advisories, national CERT reporting, packet evidence, and local telemetry before blocking infrastructure or escalating attribution.

Strengths

  • Provides frequent practitioner analysis of current malicious traffic and operational security events
  • Combines human interpretation with DShield sensor data, trend views, feeds, and API access
  • Maintains a long-running public archive useful for historical and contemporary comparison

Limitations

  • Handler diaries vary in depth and are not a consistently peer-reviewed research series
  • DShield telemetry is a contributed sample and cannot establish global prevalence or local compromise

Best for

  • Daily SOC awareness
  • Internet scanning and port-trend context
  • Network threat hunting
  • Rapid corroboration during incident triage

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Provides frequent practitioner analysis of current malicious traffic and operational security events; principal limitation: Handler diaries vary in depth and are not a consistently peer-reviewed research series.

Audience

  • SOC analysts
  • network defenders
  • incident responders
  • threat hunters
  • security students

Formats

  • technical articles
  • podcasts
  • web interfaces
  • indicator data
  • api

Keywords

  • network-security
  • threat-research
  • threat-feeds
  • network-security-monitoring
  • intrusion-analysis
  • alert-triage
  • community
  • api

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

OT/ICS Security

1 source

OT/ICS SecurityAssessment tier A

CISA ICS Advisories

Cybersecurity and Infrastructure Security Agency

Visit source : CISA ICS Advisories

CISA ICS Advisories are official U.S. government bulletins covering vulnerabilities in industrial-control, operational-technology, and related products. Advisories identify affected products and versions, describe impact, assign severity information, credit researchers, and relay vendor mitigations or workarounds. They are a primary starting point for OT vulnerability triage, but they often depend on vendor-supplied facts and cannot determine whether a device is exposed or safely patchable in a specific plant. Validate inventory, process risk, compensating controls, and current vendor guidance before changing production systems.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

CISA's Industrial Control Systems Advisories provide a continuously updated government channel for vulnerabilities affecting industrial-control systems, operational technology, building automation, medical or embedded devices, and other cyber-physical products. Individual advisories normally identify vendors, affected products and versions, vulnerability identifiers, reported impact, severity information, researcher credit, and recommended mitigations or vendor references. Asset owners can match advisories to an authoritative inventory, confirm the vulnerable component and deployment mode, and open an engineering-led risk decision that considers safety, availability, remote access, network segmentation, and recovery options. Incident responders can also use advisory details to frame evidence collection when exploitation is suspected. The bulletin establishes that CISA and the vendor recognize a reported issue; it does not prove internet exposure, exploitation, compromise, or that a generic patch can be applied without operational consequences. Advisory content may originate with vendors and can change as fixes or affected-version ranges are revised. Follow the current vendor bulletin, CISA KEV when exploitation evidence exists, and site-specific change procedures. Test mitigations in a representative environment and coordinate with operations, safety, and equipment owners before modifying fragile production systems.

Strengths

  • Authoritative central stream of vulnerability advisories for industrial and cyber-physical products
  • Links affected versions, severity, researcher credit, and vendor remediation guidance
  • Supports structured OT asset review and coordinated vulnerability response

Limitations

  • Advisories may rely on vendor-reported scope and do not establish exploitation or local exposure
  • Recommended changes require environment-specific safety, availability, and process validation

Best for

  • OT vulnerability triage
  • Industrial asset exposure review
  • Control-system remediation planning
  • Coordinated vulnerability monitoring

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Authoritative central stream of vulnerability advisories for industrial and cyber-physical products; principal limitation: Advisories may rely on vendor-reported scope and do not establish exploitation or local exposure.

Audience

  • critical-infrastructure operators
  • OT security teams
  • vulnerability managers
  • incident responders
  • control-system engineers

Formats

  • vulnerability advisories
  • security alerts
  • remediation guidance
  • vendor statements

Keywords

  • ics-security
  • critical-infrastructure
  • vulnerability-advisories
  • government
  • cve
  • patch-management
  • incident-response
  • risk-analysis

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Training

2 sources

TrainingAssessment tier A

Hack The Box Academy

Hack The Box

Visit source : Hack The Box Academy

Hack The Box Academy is a structured cybersecurity education platform that combines written modules, knowledge checks, interactive targets, exercises, skill paths, and job-role paths. Its catalog spans networking, Linux and Windows, penetration testing, Active Directory, web applications, defensive operations, incident response, cloud, and specialized techniques, with subscription and organizational plans plus certification-oriented paths. Academy offers more guided instruction than standalone challenge machines, but modules vary in depth and cost, lab targets remain controlled, and completion should be supplemented with independent documentation, reporting practice, and real operational experience.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Hack The Box Academy is a structured cybersecurity education platform that combines written modules, knowledge checks, interactive targets, exercises, skill paths, and job-role paths. Its catalog spans networking, Linux and Windows, penetration testing, Active Directory, web applications, defensive operations, incident response, cloud, and specialized techniques, with subscription and organizational plans plus certification-oriented paths. Academy offers more guided instruction than standalone challenge machines, but modules vary in depth and cost, lab targets remain controlled, and completion should be supplemented with independent documentation, reporting practice, and real operational experience. Learners can follow prerequisites, read a section, execute tasks against an assigned target, and use assessments to consolidate a path. It complements narrower resources such as PentesterLab for code-centered web practice and OpenSecurityTraining2 for systems foundations. Module availability, consumption units, subscriptions, lab time, paths, and certification requirements can change, so review current terms before committing to a program. Keep platform credentials separate and test only assigned systems. Progress and certificates reflect defined Academy objectives, not authorization for external testing or demonstrated ability to scope engagements, manage evidence, communicate risk, remediate systems, or operate safely under production constraints.

Strengths

  • Combines detailed written instruction with integrated practical targets and progress checks.
  • Provides broad skill and job-role paths from foundations to advanced offensive and defensive topics.
  • Maintains a consistent learning interface and links selected paths to practical certifications.

Limitations

  • Access uses a paid and consumption-based model whose cost depends on the selected path.
  • Controlled modules cannot reproduce full production ambiguity, stakeholder communication, or engagement reporting.

Best for

  • structured penetration-testing study
  • job-role learning paths
  • hands-on infrastructure labs
  • certification preparation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Combines detailed written instruction with integrated practical targets and progress checks; principal limitation: Access uses a paid and consumption-based model whose cost depends on the selected path.

Audience

  • penetration testers
  • security students
  • red teams
  • blue-team analysts

Formats

  • online modules
  • interactive labs
  • skill paths
  • job-role paths
  • certifications

Keywords

  • security-training
  • hands-on-labs
  • penetration-testing
  • active-directory
  • web-security
  • red-team
  • blue-team

Link validation: Reachable · checked 2026-09-07 · HTTP 200

TrainingAssessment tier A

Malware-Traffic-Analysis.net

Brad Duncan

Visit source : Malware-Traffic-Analysis.net

Malware-Traffic-Analysis.net is Brad Duncan's practical archive of malicious network-traffic exercises, packet captures, incident artifacts, tutorials, and answer write-ups. Scenarios let analysts inspect infection chains, web requests, DNS, TLS, command-and-control behavior, alerts, and host details using Wireshark and related tools, making it valuable for repeatable SOC and network-forensics practice. Some exercises include live-malware-derived artifacts or password-protected samples and require an isolated lab. The curated cases emphasize particular Windows infections and known outcomes, so they do not represent prevalence, unbiased telemetry, or a complete incident-response process.

Source type
Independent Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Malware-Traffic-Analysis.net is Brad Duncan's practical archive of malicious network-traffic exercises, packet captures, incident artifacts, tutorials, and answer write-ups. Scenarios let analysts inspect infection chains, web requests, DNS, TLS, command-and-control behavior, alerts, and host details using Wireshark and related tools, making it valuable for repeatable SOC and network-forensics practice. Some exercises include live-malware-derived artifacts or password-protected samples and require an isolated lab. The curated cases emphasize particular Windows infections and known outcomes, so they do not represent prevalence, unbiased telemetry, or a complete incident-response process. Learners can download a dated case, preserve the original archive and hashes, establish a timeline from packet evidence, identify hosts and protocols, extract defensible indicators, and compare conclusions with the published answer. Defenders can replay captures through Zeek, Suricata, or other lab sensors to test visibility and rule hypotheses. The archive is free, but each exercise has its own files, passwords, and instructions; cite the case date and verify handling notes. Use a non-production analysis VM with no uncontrolled egress, and never execute extracted payloads casually. Known answers may bias investigation, so work independently first and distinguish observed traffic from inferred infection behavior, attribution, and prevalence.

Strengths

  • Provides realistic packet captures and incident context tied to documented malicious activity.
  • Includes exercises and answer material that support self-paced network-forensics skill development.
  • Maintains an extensive chronological archive useful for comparing infection patterns over time.

Limitations

  • Malware-related artifacts require isolation, safe handling, and strict avoidance of production execution.
  • Curated scenarios and known answers simplify the uncertainty and breadth of real incident response.

Best for

  • malware traffic analysis
  • packet-analysis practice
  • SOC investigation training
  • infection-chain reconstruction

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 4/5

Provides realistic packet captures and incident context tied to documented malicious activity; principal limitation: Malware-related artifacts require isolation, safe handling, and strict avoidance of production execution.

Audience

  • SOC analysts
  • network defenders
  • incident responders
  • malware analysts

Formats

  • packet captures
  • analysis exercises
  • incident artifacts
  • answer write-ups
  • tutorials

Keywords

  • security-training
  • malware-traffic
  • network-forensics
  • packet-analysis
  • incident-response
  • wireshark
  • safe-malware-handling

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Vulnerability

1 source

VulnerabilityAssessment tier A

Google Project Zero

Google Project Zero

Visit source : Google Project Zero

Google Project Zero publishes original vulnerability research, root-cause analyses, exploit-development case studies, a public issue tracker, and recurring analysis of zero-days exploited in the wild. Its work is unusually detailed about exploitation primitives, patch gaps, mitigations, and disclosure timelines, making it valuable to vulnerability researchers and product-security teams. Coverage is deliberately selective rather than a comprehensive vulnerability feed, and exploit-relevant material is dual-use. Use each publication as a technical case study, verify current vendor patches, and keep reproduction inside an authorized laboratory.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Google Project Zero is Google's specialist vulnerability-research team and a primary source for deeply technical work on high-impact software flaws. Its public material includes root-cause analyses, exploitation case studies, a searchable issue tracker, disclosure-policy documentation, and recurring reviews of zero-days observed in the wild. Researchers can follow a report from vulnerable code and exploitation primitive through vendor response, patch analysis, and systemic mitigation, which makes the archive especially useful for learning modern browser, operating-system, mobile, and kernel exploitation. Product-security teams can convert recurring bug classes and variant-analysis methods into review and testing hypotheses, while defenders can use patch-gap discussions to improve exposure decisions. Always record the article, issue, and patch dates because disclosure status and affected versions change. Project Zero selects targets according to its research priorities, so the archive is not a vulnerability catalog, prevalence measure, or complete view of exploitation. Technical details and proof-of-concept material are dual-use; reproduce them only on systems you own or are explicitly authorized to assess, and confirm remediation through current vendor advisories before taking operational action.

Strengths

  • Publishes original, technically deep vulnerability and exploitation research with clear evidence chains
  • Connects root causes, disclosure timelines, patch analysis, and broader mitigation lessons
  • Maintains a public issue tracker that preserves vulnerability provenance and coordination context

Limitations

  • Coverage is intentionally selective and does not represent the full vulnerability or exploitation landscape
  • Exploit-development detail is dual-use, and older articles may describe superseded versions or mitigations

Best for

  • Advanced vulnerability research
  • Root-cause and patch analysis
  • Exploit-mitigation study
  • Product-security variant analysis

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Publishes original, technically deep vulnerability and exploitation research with clear evidence chains; principal limitation: Coverage is intentionally selective and does not represent the full vulnerability or exploitation landscape.

Audience

  • vulnerability researchers
  • product security teams
  • exploit mitigations researchers
  • security engineers
  • advanced defenders

Formats

  • research articles
  • vulnerability reports
  • disclosure timelines
  • proof-of-concept code
  • datasets

Keywords

  • vulnerability-research
  • zero-day
  • exploit-research
  • coordinated-disclosure
  • variant-analysis
  • memory-safety
  • security-research
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.