Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Academic

1 source

AcademicAssessment tier A

NDSS Symposium

Internet Society

Visit source : NDSS Symposium

The Network and Distributed System Security Symposium is a leading peer-reviewed venue for original systems and network security research. Its public archive provides accepted papers and proceedings across software, networks, privacy, authentication, measurement, hardware, mobile, usable security, and emerging AI-related topics. The source is valuable for literature review, technical methods, and finding research artifacts, but publication does not guarantee reproducibility or production readiness. Read each paper's threat model, methods, datasets, ethics, and limitations, check follow-up work, and validate proposed attacks or defenses against current systems before operational use.

Source type
Academic
Access
Free
Evidence use
Peer Reviewed Primary
Maintenance
Periodic
Skill level
Advanced
Detailed assessment

Description

The Network and Distributed System Security Symposium is an annual, peer-reviewed security research venue organized by the Internet Society. Its site publishes accepted-paper lists, programs, proceedings, and individual papers covering network and distributed-system security as well as adjacent software, web, privacy, authentication, hardware, mobile, measurement, usable-security, and machine-learning topics. Researchers and graduate students can use the archive for structured literature review, compare methods and threat models, and follow citations into prior and subsequent work. Advanced practitioners can translate an attack, measurement, or defense into a controlled replication plan and evaluate whether its assumptions match current products and their environment. Begin with the exact paper and edition, then inspect methodology, datasets, experimental setup, ethics, disclosed artifacts, limitations, and later corrections or follow-up studies. Peer review is a strong quality filter, not proof that every result reproduces, generalizes, or remains current. Academic prototypes may omit deployment, maintenance, performance, privacy, or adversarial adaptation concerns. Do not convert a paper directly into production guidance or offensive testing; reproduce only within legal authorization, preserve versions and parameters, compare with independent research, and evaluate the defense against realistic local threats and operational constraints.

Strengths

  • Leading peer-reviewed venue for original network, systems, software, and privacy security research
  • Provides durable public access to proceedings, accepted papers, programs, and bibliographic context
  • Offers advanced methods and empirical results that support literature review and controlled replication

Limitations

  • Peer review does not guarantee reproducibility, generalizability, or continued relevance to current systems
  • Academic prototypes and evaluations may omit production operations, maintenance, cost, or deployment constraints

Best for

  • Advanced security literature review
  • Finding peer-reviewed methods and measurements
  • Research replication planning
  • Tracking emerging security research

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 5/5

Leading peer-reviewed venue for original network, systems, software, and privacy security research; principal limitation: Peer review does not guarantee reproducibility, generalizability, or continued relevance to current systems.

Audience

  • security researchers
  • graduate students
  • advanced practitioners
  • security engineers
  • educators

Formats

  • peer-reviewed papers
  • conference proceedings
  • research artifacts
  • conference presentations
  • bibliographic records

Keywords

  • academic
  • peer-reviewed-research
  • security-research
  • network-security
  • systems-security
  • privacy
  • open-access
  • conference

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Government

3 sources

GovernmentAssessment tier A

ANSSI France

Agence nationale de la sécurité des systèmes d'information

Visit source : ANSSI France

ANSSI is France's national authority for cybersecurity and cyberdefence. Its official portal publishes security guides and recommendations, threat-landscape reports, risk methods, certification and qualification information, technical tools, scientific work, and access to CERT-FR incident and vulnerability reporting. The material is especially valuable for French public services, critical operators, regulated entities, and comparative government guidance. Much operational content is French-first, service eligibility varies, and official assessments do not by themselves prove attribution or local compromise. Check publication dates, scope, and applicable French or European requirements before implementation.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

ANSSI, the French National Cybersecurity Agency, is France's national authority for cybersecurity and cyberdefence and an authoritative source for government security guidance. Its portal brings together practical technical recommendations, organizational and risk-management methods, threat panoramas, scientific publications, certification and qualification schemes, training resources, open tools, and links to CERT-FR alerts and incident-response services. French government bodies, operators of vital or essential services, regulated organizations, architects, and service providers can use the material to establish baselines, compare architectures, prepare crises, evaluate products, and follow nationally relevant threats. Start with the exact guide or alert rather than the portal summary, record its publication and revision date, and identify whether language expresses regulation, qualification criteria, or non-binding advice. French and English coverage differs, and some digital services are restricted to eligible public or regulated beneficiaries. Recommendations reflect French legal, institutional, and threat contexts and may need adaptation elsewhere. A CERT-FR or ANSSI warning establishes official concern but does not prove that a named actor compromised a particular organization. Corroborate campaign and vulnerability claims with technical evidence and vendor advisories, map requirements to the governing jurisdiction, test changes, and document local risk acceptance and operational constraints.

Strengths

  • Authoritative French source for cybersecurity guidance, national policy, certification, and incident support
  • Publishes detailed technical recommendations, risk methods, threat reports, and practical tools
  • Connects strategic government policy with CERT-FR operational alerts and response services

Limitations

  • Much material is French-first, and English coverage may be narrower or delayed
  • Legal applicability, service eligibility, and threat priorities are centered on the French context

Best for

  • French cybersecurity compliance and architecture
  • Government security guidance comparison
  • Critical-infrastructure resilience
  • National threat and incident awareness

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Authoritative French source for cybersecurity guidance, national policy, certification, and incident support; principal limitation: Much material is French-first, and English coverage may be narrower or delayed.

Audience

  • public-sector organizations
  • critical-infrastructure operators
  • security architects
  • incident responders
  • risk managers

Formats

  • government guidance
  • security advisories
  • threat reports
  • technical guides
  • research publications

Keywords

  • government
  • national-cert
  • government-guidance
  • critical-infrastructure
  • incident-response
  • risk-management
  • cyber-resilience
  • european-union

Link validation: Reachable · checked 2026-09-07 · HTTP 200

GovernmentAssessment tier A

Canadian Centre for Cyber Security

Canadian Centre for Cyber Security, Communications Security Establishment Canada

Visit source : Canadian Centre for Cyber Security

The Canadian Centre for Cyber Security is Canada's technical authority and unified public source for cybersecurity advice, guidance, services, alerts, advisories, incident reporting, and national cyber-threat assessments. Its publications serve individuals, businesses, critical infrastructure, academia, and government and provide strong Canadian operational and policy context. Some services and notifications have eligibility or asset-location requirements, while threat assessments can incorporate classified insight that readers cannot independently inspect. Apply guidance to the relevant audience and date, corroborate attribution and vulnerability facts, and do not treat an alert or notification alone as confirmation of compromise.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The Canadian Centre for Cyber Security is part of the Communications Security Establishment Canada and acts as Canada's technical authority and unified public source for cybersecurity guidance, services, and support. Its portal publishes vulnerability advisories and alerts, technical and executive guidance, national cyber-threat assessments, critical-infrastructure resources, public-awareness material, incident-reporting routes, and selected defensive tools and services. Canadian organizations can use it to follow nationally relevant threats, improve baseline controls and resilience, prepare incident plans, and locate official support. The wider public and smaller organizations benefit from audience-specific advice, while threat assessments help leaders frame strategic risks. Read the exact publication and retain its modification date, audience, confidence language, and scope. Some services, including organization-specific notifications, have enrollment, ownership, or Canadian asset requirements. National assessments may combine public and classified information, so the complete evidence base is not always reproducible. Government attribution and forecasts carry authority within their remit but do not prove local targeting or compromise. Corroborate vulnerability details with vendors, validate alerts against asset inventory and telemetry, and adapt general recommendations to business impact, sector obligations, architecture, and available resources before treating them as completed controls.

Strengths

  • Authoritative Canadian source for guidance, alerts, incident reporting, and national threat assessments
  • Provides audience-specific material for individuals, businesses, critical infrastructure, academia, and government
  • Connects strategic assessments with practical readiness, mitigation, and response resources

Limitations

  • Some services and notifications have Canadian eligibility, enrollment, or asset-ownership requirements
  • Threat assessments may rely partly on classified evidence and require local validation before action

Best for

  • Canadian cyber-resilience planning
  • Government alert and advisory monitoring
  • Critical-infrastructure guidance
  • National threat-landscape assessment

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Authoritative Canadian source for guidance, alerts, incident reporting, and national threat assessments; principal limitation: Some services and notifications have Canadian eligibility, enrollment, or asset-ownership requirements.

Audience

  • Canadian organizations
  • critical-infrastructure operators
  • security leaders
  • incident responders
  • general public

Formats

  • government guidance
  • security advisories
  • threat reports
  • incident-reporting services
  • training resources

Keywords

  • government
  • national-cert
  • government-guidance
  • critical-infrastructure
  • incident-response
  • threat-reports
  • cyber-resilience
  • public-sector

Link validation: Reachable · checked 2026-09-07 · HTTP 200

GovernmentAssessment tier A

BSI Germany IT-Grundschutz

German Federal Office for Information Security

Visit source : BSI Germany IT-Grundschutz

BSI IT-Grundschutz is Germany's modular methodology and compendium for establishing, assessing, and improving an information security management system. It organizes requirements around common processes, applications, systems, networks, facilities, and organizational conditions and connects them to baseline, standard, and elevated protection approaches. It is detailed and implementation-oriented, especially for German public-sector and regulated contexts. Users must select the current edition, model their own information domain, justify tailoring, and add individual risk analysis where protection needs or technologies exceed the compendium's assumptions; much current material is German-first.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

IT-Grundschutz is the German Federal Office for Information Security's structured methodology for building and maintaining an information security management system. BSI standards define the process, while the regularly revised Compendium supplies modular requirements for organizational processes, applications, IT systems, communication links, physical infrastructure, and operational environments. Security managers can inventory and model an information domain, select applicable modules, compare implemented safeguards with baseline and standard requirements, document gaps, and perform additional risk analysis where protection needs are higher or no suitable module exists. Auditors and public-sector teams can also use the associated profiles, implementation guidance, tools, and certification framework. The material is authoritative within its stated German context, but applying modules mechanically can create paperwork without effective risk reduction. Editions and supporting documents change, German and English availability differ, and legal or certification relevance depends on jurisdiction and scope. Use the current edition, record every selected module and justified deviation, map requirements to accountable owners and evidence, and validate technical safeguards against actual architecture and threats. IT-Grundschutz complements rather than replaces business-impact analysis, sector obligations, engineering judgment, penetration testing, incident learning, or an individualized assessment of unusual systems.

Strengths

  • Provides a comprehensive modular methodology for building and assessing an ISMS
  • Connects organizational, personnel, physical, process, and technical security requirements
  • Offers supporting profiles, implementation guidance, audit methods, tools, and certification paths

Limitations

  • The framework is detailed and can become documentation-heavy without careful scoping and ownership
  • Current editions and supporting material are often German-first and require jurisdiction-specific interpretation

Best for

  • ISMS design and improvement
  • German public-sector security programs
  • Baseline control and gap assessment
  • Structured security audits

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Provides a comprehensive modular methodology for building and assessing an ISMS; principal limitation: The framework is detailed and can become documentation-heavy without careful scoping and ownership.

Audience

  • security leaders
  • risk managers
  • security architects
  • auditors
  • public-sector organizations

Formats

  • framework
  • control catalog
  • implementation guidance
  • audit guide
  • government publications

Keywords

  • government
  • security-framework
  • risk-management
  • control-framework
  • secure-configuration
  • compliance
  • government-guidance
  • cyber-resilience

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Threat Reports

3 sources

Threat ReportsAssessment tier B

IBM X-Force Threat Intelligence Index

IBM X-Force

Visit source : IBM X-Force Threat Intelligence Index

The IBM X-Force Threat Intelligence Index is an annual report on incidents, initial-access patterns, vulnerabilities, ransomware and extortion, industries, regions, and adversary techniques observed through IBM's incident response, managed security, research, and partner visibility. It provides useful cross-industry context and practical themes for security planning. Its percentages describe the report's underlying case and telemetry population, not every attack worldwide, and edition methods can change. Record definitions and periods, distinguish observed events from forecasts, and corroborate trend or attribution claims with independent sources and local evidence.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The IBM X-Force Threat Intelligence Index is an annual assessment of the threat landscape based on IBM X-Force incident-response engagements, managed-security observations, vulnerability and malware research, dark-web analysis, and partner or public reporting. Editions organize findings around initial-access vectors, exploitation, identity abuse, ransomware and extortion, affected sectors and regions, and defensive priorities. Security leaders can use the report as one comparative input for annual planning, while CTI and operations teams can translate relevant behaviors into hypotheses about exposed applications, credentials, detection coverage, and response readiness. Preserve the report year, data period, population, definitions, and methodology before comparing metrics across editions or with other reports. IBM's cases and telemetry reflect its customers, products, geography, service mix, and analytical taxonomy; they do not provide a representative census of global attacks. Percentage changes may be sensitive to small samples or classification changes, and strategic recommendations can overlap with IBM services. Follow important claims to technical research and primary advisories, cross-map actor names carefully, and corroborate prevalence and attribution with independent vendor and government sources. Validate every proposed priority against the organization's assets, threats, controls, incident history, and business consequences.

Strengths

  • Combines incident response, managed-security telemetry, vulnerability research, and threat analysis
  • Provides annual sector, region, initial-access, ransomware, and adversary-behavior perspectives
  • Translates observed patterns into accessible defensive and risk-management themes

Limitations

  • The data population reflects IBM customers, engagements, services, geography, and classification methods
  • Annual percentages and forecasts require careful methodological comparison and independent corroboration

Best for

  • Annual threat-landscape review
  • Sector and regional risk context
  • Initial-access trend analysis
  • Executive security planning

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Combines incident response, managed-security telemetry, vulnerability research, and threat analysis; principal limitation: The data population reflects IBM customers, engagements, services, geography, and classification methods.

Audience

  • security leaders
  • cti analysts
  • risk managers
  • incident-response leaders
  • security architects

Formats

  • annual report
  • executive summary
  • charts
  • industry snapshots
  • webinars

Keywords

  • threat-reports
  • threat-landscape
  • incident-response
  • ransomware
  • cybercrime
  • vulnerability-management
  • vendor-research
  • risk-communication

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Threat ReportsAssessment tier B

Microsoft Digital Defense Report

Microsoft

Visit source : Microsoft Digital Defense Report

The Microsoft Digital Defense Report is an annual strategic overview of cybercrime, nation-state activity, identity threats, vulnerabilities, influence operations, and defensive priorities derived from Microsoft's global products, services, investigations, and partnerships. It offers broad visibility and accessible leadership context, with supporting recommendations for defenders and governments. The report reflects Microsoft's customer base, telemetry, taxonomy, and policy perspective rather than the whole threat landscape. Preserve the edition and methodology, avoid comparing headline numbers without consistent definitions, and corroborate attribution or prevalence claims with independent evidence and local risk analysis.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The Microsoft Digital Defense Report is Microsoft's annual synthesis of threat activity and defensive lessons drawn from its cloud, identity, endpoint, email, consumer, vulnerability, and incident-response visibility. Editions address cybercrime, ransomware, nation-state operations, influence activity, identity abuse, vulnerabilities, artificial intelligence, and priorities for organizations and governments. Security leaders can use the report to update strategic threat assumptions and communicate broad shifts; CTI teams can follow named actors and campaign references into more detailed Microsoft Threat Intelligence reporting; and architects can compare recommended controls with locally observed attack paths. Record the edition, reporting period, metrics, definitions, and named-actor taxonomy because these change over time and can differ from other vendors. Microsoft's very large telemetry base is valuable but is shaped by product deployment, customer geography, detection logic, commercial priorities, and what the company can publicly disclose. Aggregate signal counts are not incident counts, and a global pattern does not prove local risk or compromise. Corroborate material attribution, prevalence, and policy conclusions with other vendor reports, government advisories, primary incident evidence, and organization-specific exposure. Translate recommendations into owned, measurable controls rather than adopting headline statistics as priorities by themselves.

Strengths

  • Combines broad cloud, identity, endpoint, email, vulnerability, and investigation visibility
  • Covers cybercrime, nation-state, influence, technology, and policy trends in one annual synthesis
  • Provides accessible strategic context and defensive recommendations for leaders and practitioners

Limitations

  • Telemetry and conclusions reflect Microsoft's products, customers, taxonomy, and disclosure choices
  • Large signal counts and annual aggregates do not directly measure incidents, prevalence, or local exposure

Best for

  • Executive threat briefings
  • Annual security strategy reviews
  • Nation-state and cybercrime context
  • Threat-model assumption updates

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Combines broad cloud, identity, endpoint, email, vulnerability, and investigation visibility; principal limitation: Telemetry and conclusions reflect Microsoft's products, customers, taxonomy, and disclosure choices.

Audience

  • security leaders
  • cti analysts
  • risk managers
  • policy professionals
  • security architects

Formats

  • annual report
  • executive summary
  • charts
  • threat reports
  • web presentation

Keywords

  • threat-reports
  • threat-landscape
  • nation-state
  • cybercrime
  • identity-security
  • cloud-security
  • government
  • risk-communication

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Threat ReportsAssessment tier B

Red Canary Threat Detection Report

Red Canary

Visit source : Red Canary Threat Detection Report

Red Canary's annual Threat Detection Report analyzes confirmed threats, prevalent adversary behaviors, and MITRE ATT&CK techniques observed through its managed detection and response work. Its online field guide connects ranked trends to detection, testing, and mitigation guidance, making the report unusually useful to detection engineers and SOC teams. Results reflect Red Canary's customers, data sources, analytics, and counting method rather than universal prevalence. Preserve the report year and methodology, validate suggested analytics against local telemetry, and corroborate actor or trend claims with independent evidence.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Red Canary's Threat Detection Report is an annual, web-based analysis of confirmed threats and adversary behaviors observed through the company's managed detection and response operations. It ranks significant threats and MITRE ATT&CK techniques, explains changes in tradecraft, and often pairs findings with detection opportunities, testing ideas, and defensive actions. Detection engineers can use a relevant technique page to identify required telemetry, build or adapt an analytic, reproduce behavior safely with validated test content, and measure results against expected evidence. SOC leaders can compare the report's themes with alert and incident history to prioritize investigation playbooks and collection gaps. Record the edition, observation period, protected population, data-source mix, and counting method: endpoint, identity, network, cloud, and SaaS adoption can materially change what appears prevalent. Confirmed MDR threats are stronger evidence than raw alerts, but the customer population is not a representative sample of all organizations, and vendor detection logic shapes visibility. A ranked technique is not automatically the highest local risk. Validate every recommendation against local logs and adversaries, distinguish ATT&CK mapping from proven coverage, and corroborate attribution and broad trend claims with primary reports and independent research.

Strengths

  • Links confirmed MDR observations to ATT&CK techniques and practical detection guidance
  • Provides an accessible online field guide for threats, trends, testing, and response actions
  • Helps teams translate annual telemetry into concrete detection and collection hypotheses

Limitations

  • Rankings reflect Red Canary customers, deployed data sources, analytics, and counting methodology
  • Technique prevalence and mappings do not demonstrate local risk or effective detection coverage

Best for

  • Detection engineering prioritization
  • SOC threat and technique reviews
  • ATT&CK-informed validation planning
  • Telemetry gap analysis

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Links confirmed MDR observations to ATT&CK techniques and practical detection guidance; principal limitation: Rankings reflect Red Canary customers, deployed data sources, analytics, and counting methodology.

Audience

  • detection engineers
  • SOC analysts
  • threat hunters
  • security leaders
  • purple teams

Formats

  • annual report
  • technique pages
  • detection references
  • charts
  • webinars

Keywords

  • threat-reports
  • detection-engineering
  • mitre-attack
  • threat-hunting
  • detection-validation
  • adversary-behavior
  • soc
  • vendor-research

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Threat Research

1 source

Threat ResearchAssessment tier A

Microsoft Threat Intelligence blog

Microsoft Threat Intelligence

Visit source : Microsoft Threat Intelligence blog

The Microsoft Security Blog's Threat Intelligence channel publishes timely research on active campaigns, malware, vulnerabilities, nation-state and cybercrime actors, identity abuse, cloud attacks, and defensive guidance. Posts often combine Microsoft's telemetry and investigations with indicators, behavior descriptions, detection queries, and mitigations that can support incident triage and hunting. Evidence depth varies, indicators decay, and Microsoft actor names and visibility are vendor-specific. Preserve publication and update dates, follow claims to primary evidence, and corroborate attribution, prevalence, and remediation with independent sources and local telemetry.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Microsoft Threat Intelligence's channel on the Microsoft Security Blog is a continuously updated source of research on active campaigns, threat actors, malware, vulnerability exploitation, identity attacks, cloud and software-supply-chain activity, and defensive response. Articles can include observed intrusion sequences, actor and campaign naming, indicators, MITRE ATT&CK behaviors, hunting queries, product detections, and mitigations. CTI analysts can extract dated claims and cross-map Microsoft names with other taxonomies; responders can turn reported behaviors and infrastructure into scoped searches; and detection engineers can adapt queries only after confirming schemas and data sources. Preserve the original publication date and later update notes because campaign scope, affected products, indicators, and attribution may change. Microsoft's findings reflect its products, customers, partners, and investigations, while posts vary from rapid operational reporting to deeper technical analysis. Indicators can be shared, reassigned, or obsolete, and absence from Microsoft telemetry has no negative evidentiary meaning. Do not deploy permanent blocks or claim compromise from a single match. Corroborate important actor and prevalence assertions with other primary reporting, validate remediation against current vendor advisories, and require local event, asset, and timeline evidence before reaching case conclusions.

Strengths

  • Publishes frequent original research from broad identity, endpoint, cloud, email, and incident visibility
  • Often includes behaviors, indicators, hunting guidance, detections, and mitigation context
  • Provides timely updates on nation-state, cybercrime, vulnerability, and campaign activity

Limitations

  • Coverage and actor taxonomy reflect Microsoft telemetry, products, customers, and analytical decisions
  • Article depth varies, indicators decay, and attribution or prevalence claims require corroboration

Best for

  • Current campaign monitoring
  • Threat hunting and incident triage
  • Microsoft ecosystem detection guidance
  • Actor and malware research

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Publishes frequent original research from broad identity, endpoint, cloud, email, and incident visibility; principal limitation: Coverage and actor taxonomy reflect Microsoft telemetry, products, customers, and analytical decisions.

Audience

  • cti analysts
  • incident responders
  • detection engineers
  • threat hunters
  • security administrators

Formats

  • technical articles
  • campaign reports
  • indicator lists
  • query examples
  • remediation guidance

Keywords

  • threat-research
  • threat-intelligence-platform
  • nation-state
  • cybercrime
  • indicators-of-compromise
  • threat-hunting
  • detection-engineering
  • vendor-research

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.