Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

CTI

1 source

CTIAssessment tier A

GreyNoise

GreyNoise Intelligence, Inc.

Visit source : GreyNoise

GreyNoise collects internet-wide scan and exploitation traffic through a distributed sensor network and exposes context through its Visualizer and APIs. Analysts use its IP classifications, behavioral tags, CVE context, and business-service data to separate widespread background activity from events that merit investigation. The free tier supports limited lookups, while deeper history, exports, integrations, and automation are commercial. Its observations are valuable enrichment, not proof that an address targeted or compromised a particular organization.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

GreyNoise Intelligence operates a distributed sensor network that observes systems scanning, probing, and attacking internet-facing infrastructure. Its Visualizer, Community API, GNQL searches, behavioral tags, CVE views, and business-service context help SOC analysts distinguish widespread background activity from potentially targeted traffic, investigate scanning infrastructure, and monitor mass-exploitation trends. Current official plans provide a free community tier for basic IP lookups; authenticated community use is rate-limited, API-key access requires an eligible account, and richer history, exports, feeds, integrations, and automation require paid modules. GreyNoise is a proprietary service whose conclusions reflect its sensor placement, collection window, signatures, and classification logic. An absent observation does not make an address safe, a malicious label does not establish compromise, and IP ownership can change. Preserve the observation time and underlying behavior, corroborate important decisions with local telemetry and independent sources, and review the service's account and privacy terms before submitting internal asset lists. Use blocklist or alert outputs only after testing scope, age, shared infrastructure, and false-positive impact.

Strengths

  • Distinctive first-party telemetry about internet-wide scanning and mass-exploitation behavior
  • Queryable IP, CVE, tag, and business-service context supports rapid SOC enrichment
  • Free community access permits limited lookups before an organization licenses broader coverage

Limitations

  • Coverage and classifications are proprietary, sensor-dependent observations rather than proof of targeting or compromise
  • Free and community access is rate-limited, while deeper history, exports, and automation require paid access
  • IP ownership, shared hosting, and observation age can make unreviewed blocking decisions unsafe

Best for

  • internet-scan alert enrichment
  • mass-exploitation trend monitoring
  • background-noise reduction
  • IP reputation triage

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Distinctive first-party telemetry about internet-wide scanning and mass-exploitation behavior; principal limitation: Coverage and classifications are proprietary, sensor-dependent observations rather than proof of targeting or compromise.

Audience

  • SOC analysts
  • threat-intelligence analysts
  • incident responders
  • vulnerability teams

Formats

  • web visualizer
  • API
  • behavioral tags
  • feeds
  • research reports

Keywords

  • cti
  • threat-research
  • network-security
  • soc
  • feeds
  • internet-scanning
  • ip-enrichment
  • mass-exploitation
  • vulnerability-research
  • freemium

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Detection Engineering

1 source

Detection EngineeringAssessment tier A

LOLBAS

LOLBAS Project

Visit source : LOLBAS

LOLBAS is a GPL-3.0 community project cataloging Microsoft-signed Windows binaries, scripts, and libraries with unexpected functionality useful to an attacker or red team. Entries document paths, command examples, privileges, operating-system applicability, ATT&CK mappings, references, and available detection ideas. It is a strong bridge between living-off-the-land research and defensive analytics. Inclusion does not prove malicious use or exploitable configuration, and commands must be validated against exact Windows builds, products, controls, and telemetry.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

LOLBAS, the Living Off The Land Binaries, Scripts and Libraries project, maintains structured records for Microsoft-signed Windows components with unexpected functionality relevant to adversaries and authorized security testers. Entries can describe execution, compilation, download, upload, file operations, persistence, application-control bypass, UAC bypass, credential access, or process-memory dumping, along with known paths, prerequisites, supported Windows versions, ATT&CK techniques, references, acknowledgements, and detection ideas. The community project publishes its source data and site under GPL-3.0 and provides programmatic access, making it useful for threat hunting, analytic development, allow-list review, and purple-team validation. LOLBAS is not proof that a binary invocation is malicious: legitimate administrative workflows may use the same component, and behavior can change across Windows releases or installed products. Validate command lines, parent-child context, user and integrity level, file or network effects, signing information, and local prevalence before deploying detections. Treat ATT&CK mappings and contributed detection links as starting points rather than guaranteed coverage. The documented commands are materially dual-use; test only within an explicitly authorized scope, protect sensitive outputs, monitor side effects, and restore the environment afterward.

Strengths

  • Structured Windows living-off-the-land records connect commands, context, references, and ATT&CK mappings
  • GPL-3.0 source data supports inspection, programmatic use, and community contribution
  • Entries often link concrete detection ideas for defenders as well as validation steps for testers

Limitations

  • An entry does not prove malicious execution because many cataloged binaries have legitimate administrative uses
  • Commands and detection assumptions can vary by Windows version, installed product, privilege, and control policy
  • Dual-use techniques require explicit authorization, telemetry capture, and safe cleanup

Best for

  • Windows living-off-the-land detection
  • application-control reviews
  • threat hunting
  • purple-team validation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Structured Windows living-off-the-land records connect commands, context, references, and ATT&CK mappings; principal limitation: An entry does not prove malicious execution because many cataloged binaries have legitimate administrative uses.

Audience

  • Windows defenders
  • detection engineers
  • penetration testers
  • purple teams

Formats

  • web catalog
  • github repository
  • YAML data
  • command examples
  • ATT&CK mappings

Keywords

  • detection-engineering
  • penetration-testing
  • red-team
  • blue-team
  • mitre-attack
  • repositories
  • tools
  • windows
  • living-off-the-land
  • application-control
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Malware Analysis

3 sources

Malware AnalysisAssessment tier A

ANY.RUN

ANYRUN FZCO

Visit source : ANY.RUN

ANY.RUN is a commercial cloud sandbox with a free Community plan for interactively detonating suspicious files and URLs and observing processes, network activity, indicators, and ATT&CK-aligned behavior. Its public analysis corpus is useful for malware triage and training. Community analyses are public, use a personal license, and have restricted environments, duration, file size, reports, and export features. Automated verdicts and extracted indicators require validation through static analysis and other evidence.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

ANY.RUN is a cloud malware-analysis service that lets an analyst execute a suspicious file or URL in a disposable virtual machine and interact with the environment while processes, files, registry activity, network connections, and detection events are recorded. Reports can support rapid alert triage, IOC extraction, behavioral comparison, ATT&CK-oriented review, and analyst training; the public corpus also supplies searchable examples. The proprietary service is maintained by ANYRUN FZCO. Its current free Community plan requires an account, carries a personal license, allows public analyses, and restricts available operating systems, runtime, file size, reporting, exports, and advanced inspection relative to paid plans. Public submissions and reports are available to other users and may be used for research and intelligence, so never upload customer data, internal URLs, credentials, unreleased software, or confidential samples in public mode. Sandbox-aware malware, environment differences, failed detonation, and automated signatures can produce incomplete or misleading results. Validate consequential findings with hashes, static analysis, controlled reproduction, packet evidence, and another source. Handle downloaded samples as live malware and use the service only for authorized defensive work.

Strengths

  • Interactive detonation exposes behavior that a purely automated sandbox can miss
  • Public analysis corpus provides searchable malware examples and indicators
  • Reports combine process, network, file, and ATT&CK-oriented context for fast triage

Limitations

  • Free Community analyses are public and can expose submitted files, URLs, reports, and sensitive context
  • The free personal plan limits runtime, environments, file size, exports, and advanced inspection
  • Sandbox evasion and automated classification errors require corroborating static and behavioral evidence

Best for

  • interactive malware triage
  • phishing attachment analysis
  • IOC extraction
  • malware-analysis training

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Interactive detonation exposes behavior that a purely automated sandbox can miss; principal limitation: Free Community analyses are public and can expose submitted files, URLs, reports, and sensitive context.

Audience

  • malware analysts
  • SOC analysts
  • incident responders
  • security students

Formats

  • cloud sandbox
  • behavioral reports
  • public sample dataset
  • threat-intelligence search
  • API

Keywords

  • malware-analysis
  • cti
  • datasets
  • tools
  • labs
  • dynamic-analysis
  • interactive-sandbox
  • ioc-enrichment
  • mitre-attack
  • public-submissions
  • dual-use
  • freemium

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Malware AnalysisAssessment tier A

Recorded Future Triage

Recorded Future

Visit source : Recorded Future Triage

Recorded Future Triage, available publicly at tria.ge, is a cloud malware sandbox that combines static processing, configurable behavioral runs, family scoring, configuration extraction, indicators, and a stable API. Researchers use the free public service for repeatable automated analysis and corpus search. Every public tria.ge submission is visible to other account holders and cannot normally be deleted; private analysis belongs to the commercial enterprise service. Verdicts remain hypotheses that require corroboration.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Recorded Future Triage is the public cloud entry point for Recorded Future's Sandbox technology. It accepts files and URLs, performs static processing, runs one or more configurable behavioral tasks, and produces machine-readable reports containing process activity, network connections, extracted configuration, indicators, family assessments, and tactics or techniques. A documented REST-like API supports submission, event streams, search, and report retrieval, making the service useful for repeatable malware triage and enrichment pipelines. The free tria.ge service requires an account and is explicitly public: all submissions are visible to other account holders, public users cannot delete them themselves, and private-by-default workflows are provided through the commercial Recorded Future Enterprise Sandbox. Never submit internal documents, credentials, private URLs, customer samples, or material whose disclosure would create legal or operational harm. Family scores, configuration extraction, and behavior depend on the chosen profile, runtime, network path, anti-analysis behavior, and current signatures. Treat results as analytical leads, preserve sample hashes and profile details, and corroborate them with static reverse engineering, packet evidence, and independent intelligence. Downloaded samples are hazardous and belong only in an authorized isolated lab.

Strengths

  • Documented API supports repeatable submission, search, event, and report workflows
  • Combines static analysis, behavioral execution, configuration extraction, and family-oriented scoring
  • Public corpus helps analysts compare samples and pivot across observable relationships

Limitations

  • All free public tria.ge submissions are visible to other account holders and cannot normally be self-deleted
  • Private analysis and organization controls require the commercial enterprise service
  • Profile selection, sandbox evasion, and signature quality can make automated verdicts incomplete or wrong

Best for

  • automated malware detonation
  • malware-family and configuration triage
  • sandbox API integration
  • public sample research

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Documented API supports repeatable submission, search, event, and report workflows; principal limitation: All free public tria.ge submissions are visible to other account holders and cannot normally be self-deleted.

Audience

  • malware analysts
  • incident responders
  • threat-intelligence analysts
  • security automation engineers

Formats

  • cloud sandbox
  • static reports
  • behavioral reports
  • public sample dataset
  • API

Keywords

  • malware-analysis
  • cti
  • datasets
  • tools
  • dynamic-analysis
  • sandbox
  • malware-config
  • ioc-enrichment
  • public-submissions
  • automation
  • dual-use
  • freemium

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Malware AnalysisAssessment tier B

VX-Underground

vx-underground

Visit source : VX-Underground

vx-underground is an independent, donation-supported archive of malware samples, source code, technical papers, historical material, and community publications. It provides rare primary artifacts for qualified malware researchers and detection engineers without requiring registration. The same openness creates severe handling, legal, licensing, and provenance risks: files may be live malware or offensive code, hosted material does not share one blanket reuse license, and metadata may be incomplete. Access belongs only in a controlled, authorized research environment.

Source type
Independent Technical
Access
Free
Evidence use
Mixed
Maintenance
Active
Skill level
Advanced
Detailed assessment

Description

vx-underground is an independent public archive focused on malware history and contemporary malicious code. Its infrastructure hosts malware samples, malware source code, papers, zines, threat-research collections, and other artifacts that can support reverse engineering, family comparison, detection development, and preservation of material that may disappear elsewhere. The project describes itself as community- and donation-supported and makes much of the collection available without registration. That accessibility is also its central limitation: files and code can be immediately harmful, collections may contain offensive capabilities, artifact provenance and labeling can be incomplete, and individual papers or samples retain differing copyrights and licenses. Public hosting does not grant blanket permission to redistribute or operationalize content. Researchers should establish a legitimate purpose, applicable legal authority, retention policy, and sample-handling procedure before access. Use a segmented, disposable analysis environment with no production credentials or shared storage; verify hashes, preserve source paths and timestamps, and cross-check family or attribution claims with independent analysis. Do not browse or download casually from a managed workstation. Never execute, compile, or deploy hosted code outside an explicitly authorized defensive research scope.

Strengths

  • Unusually broad archive of malware samples, source code, papers, and historical artifacts
  • Provides rare primary material for reverse engineering and detection research
  • Open access and continued community activity help preserve otherwise ephemeral research material

Limitations

  • The archive contains live malware and offensive source code with severe handling risk
  • Artifact provenance, labels, and family or attribution context may be incomplete or unverified
  • Hosted items have differing copyrights and licenses, so public availability is not blanket reuse permission

Best for

  • advanced malware reverse engineering
  • malware-history research
  • detection corpus development
  • preservation of technical papers

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Unusually broad archive of malware samples, source code, papers, and historical artifacts; principal limitation: The archive contains live malware and offensive source code with severe handling risk.

Audience

  • experienced malware researchers
  • reverse engineers
  • detection engineers
  • digital archivists

Formats

  • malware sample datasets
  • source-code archives
  • technical papers
  • zines
  • research collections

Keywords

  • malware-analysis
  • reverse-engineering
  • datasets
  • repositories
  • threat-research
  • malware-samples
  • source-code
  • digital-preservation
  • advanced
  • dual-use

Link validation: Automated access restricted · checked 2026-09-07 · HTTP 403

Category

Penetration Testing

2 sources

Penetration TestingAssessment tier A

GTFOBins

GTFOBins Project

Visit source : GTFOBins

GTFOBins is a GPL-3.0 community catalog of legitimate Unix-like executables whose normal functions can bypass local restrictions in misconfigured environments. Entries organize shell execution, file access, transfer, library loading, privilege escalation, and related behavior by execution context, with source history and machine-readable exports. It supports both authorized testing and defensive hardening. The catalog documents capabilities rather than software vulnerabilities, and every technique must be validated against the exact executable version, privileges, policy, and operating system.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

GTFOBins is a community-curated catalog of legitimate Unix-like executables that can be abused when local permissions, sudo policy, SUID bits, capabilities, restricted shells, or application controls are misconfigured. The project, created by Emilio Pinna and Andrea Cardaci with many contributors, documents functions such as command or shell execution, file read and write, upload and download, library loading, bind or reverse shells, and privilege escalation. Its current canonical site is gtfobins.org; the former gtfobins.github.io address redirects there, while the public source repository and content are GPL-3.0 licensed. Red and purple teams can use entries to validate a scoped path, and defenders can review installed binaries, execution context, sudoers rules, telemetry, and compensating controls. GTFOBins explicitly states that listed programs are not inherently vulnerable and that the collection is not an exploit database. A command may depend on a specific implementation, version, compile option, environment variable, permission, or interactive context. Reproduce it safely before drawing conclusions, and translate successful tests into prevention and detection evidence. All commands are dual-use; run them only in an authorized isolated environment and plan cleanup.

Strengths

  • Canonical, structured catalog of Unix living-off-the-land capabilities and execution contexts
  • Transparent GPL-3.0 source repository exposes history, contributions, and machine-readable data
  • Useful to both offensive validation and defensive sudo, SUID, capability, and telemetry reviews

Limitations

  • Entries describe potentially abusable capabilities rather than proving a vulnerability or exploitable configuration
  • Behavior varies by executable implementation, version, privileges, policy, and environment
  • Commands are dual-use and can expose data or elevate privileges if run outside an authorized lab

Best for

  • Unix privilege-escalation validation
  • living-off-the-land detection research
  • sudo and SUID hardening reviews
  • authorized security labs

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Canonical, structured catalog of Unix living-off-the-land capabilities and execution contexts; principal limitation: Entries describe potentially abusable capabilities rather than proving a vulnerability or exploitable configuration.

Audience

  • penetration testers
  • Linux defenders
  • purple teams
  • security students

Formats

  • web catalog
  • github repository
  • command examples
  • JSON API
  • ATT&CK Navigator data

Keywords

  • penetration-testing
  • red-team
  • blue-team
  • mitre-attack
  • repositories
  • tools
  • unix
  • linux
  • living-off-the-land
  • privilege-escalation
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Penetration TestingAssessment tier B

HackTricks

HackTricks-wiki and Carlos Polop

Visit source : HackTricks

HackTricks is a broad, frequently updated community knowledge base covering penetration-testing methodology, privilege escalation, Active Directory, cloud platforms, web applications, containers, mobile systems, and related offensive techniques. It is valuable as a working checklist and discovery layer during authorized labs and assessments. Its pages aggregate community experience of uneven depth and freshness, contain commands with real operational impact, and are not authoritative vendor guidance. The public repository currently declares no top-level machine-readable license, so verify reuse terms.

Source type
Independent Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

HackTricks is a public, community-maintained offensive-security knowledge base led by Carlos Polop. Its multilingual material spans reconnaissance, web and API testing, Linux and Windows privilege escalation, Active Directory, cloud services, containers, macOS, mobile platforms, persistence, forensics, and numerous protocol or product notes. Practitioners use it to build engagement checklists, discover likely attack paths, recall commands, and locate references that should then be followed to their original source. The repository and site are updated frequently, but breadth creates uneven editorial quality: pages can mix verified techniques, historical notes, copied commands, third-party research, advertisements, and environment-specific assumptions. Check dates, prerequisites, cited sources, target versions, and defensive consequences before relying on a procedure. The official public repository currently exposes no top-level license through its repository metadata, so public readability must not be treated as permission to republish; review the current project and page terms before reuse. Commands and techniques are materially dual-use. Execute them only on systems explicitly included in an authorized scope, prefer an isolated lab, protect secrets and evidence, and record cleanup and observed effects.

Strengths

  • Exceptionally broad practitioner coverage across host, identity, application, cloud, and platform security
  • Frequently updated pages provide useful checklists, commands, and links for technique discovery
  • Public source repository makes content history and contributions inspectable

Limitations

  • Community material varies in accuracy, sourcing, freshness, and environment applicability
  • The official repository currently declares no top-level machine-readable license, so redistribution rights must be checked
  • Offensive commands can disrupt systems or expose data if used without authorization and review

Best for

  • authorized penetration-testing checklists
  • privilege-escalation research
  • cloud and Active Directory technique discovery
  • security lab reference

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Exceptionally broad practitioner coverage across host, identity, application, cloud, and platform security; principal limitation: Community material varies in accuracy, sourcing, freshness, and environment applicability.

Audience

  • penetration testers
  • red teams
  • security students
  • defenders researching adversary techniques

Formats

  • web knowledge base
  • github repository
  • command examples
  • technical references
  • multilingual documentation

Keywords

  • penetration-testing
  • red-team
  • cloud-security
  • active-directory
  • web-security
  • application-security
  • repositories
  • training
  • privilege-escalation
  • offensive-security
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Web Security

1 source

Web SecurityAssessment tier B

PayloadsAllTheThings

Swissky and community contributors

Visit source : PayloadsAllTheThings

PayloadsAllTheThings is an MIT-licensed repository and rendered knowledge base of payloads, bypasses, methodology notes, and references for web-application security, penetration testing, CTFs, and selected post-exploitation topics. Its breadth makes it a useful working companion during authorized testing and defensive reproduction. Community examples vary in age, safety, encoding, prerequisites, and target assumptions; copying a payload does not demonstrate a vulnerability. Validate every technique against primary documentation, source code, and an isolated representative environment.

Source type
Open Source Project
Access
Free
Evidence use
Mixed
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

PayloadsAllTheThings is a large community-maintained collection of payloads, bypass techniques, vulnerability notes, and methodology references led by Swissky. The MIT-licensed GitHub repository and its rendered documentation cover topics including injection classes, deserialization, request smuggling, authentication and authorization weaknesses, file handling, token formats, API behavior, cloud or internal assessment, and selected privilege-escalation paths. Testers use it to recall syntax variants and build hypotheses; developers and defenders can use the same examples to reproduce a reported issue, design negative tests, and understand bypass patterns. The collection is a practitioner reference rather than a normative testing standard. Examples may be version-specific, incomplete, destructive, encoded for a particular tool, or copied from third-party research whose context has changed. A successful response must still be tied to a clear security boundary and impact, while a failed payload does not establish safety. Review citations, source code, content type, encoding, authentication state, rate limits, and cleanup before testing. Techniques are dual-use and can modify data or disrupt services; use only against explicitly authorized targets, prefer a lab or staging system, and never turn raw examples into unsupervised production scanning.

Strengths

  • Broad, searchable collection of concrete payload variants and bypass patterns
  • MIT-licensed public repository supports transparent review and contribution
  • Useful bridge between vulnerability descriptions, manual reproduction, and defensive test cases

Limitations

  • Community examples vary in currency, provenance, safety, and applicability to specific versions
  • Payload success or failure alone does not establish vulnerability impact or application safety
  • Some techniques can alter data, evade controls, or disrupt services without careful authorization and isolation

Best for

  • authorized web-application testing
  • payload and bypass research
  • defensive vulnerability reproduction
  • CTF and lab reference

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Broad, searchable collection of concrete payload variants and bypass patterns; principal limitation: Community examples vary in currency, provenance, safety, and applicability to specific versions.

Audience

  • application-security testers
  • penetration testers
  • developers
  • security students

Formats

  • github repository
  • web knowledge base
  • payload examples
  • methodology notes
  • technical references

Keywords

  • penetration-testing
  • web-security
  • application-security
  • api-security
  • red-team
  • repositories
  • training
  • payloads
  • bypass-techniques
  • vulnerability-research
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.