Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Framework

3 sources

FrameworkAssessment tier A

NIST Cybersecurity Framework

National Institute of Standards and Technology

Visit source : NIST Cybersecurity Framework

NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based structure for managing cybersecurity risk across organizations of any size or sector. Its Core organizes outcomes under Govern, Identify, Protect, Detect, Respond, and Recover, supported by organizational profiles, implementation tiers, quick-start guides, and mappings. It provides a common language for aligning leadership, risk, and technical teams without prescribing products or exact controls. Organizations must tailor outcomes to their mission, threats, obligations, and resources; using the framework alone does not establish compliance or effective implementation.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

NIST Cybersecurity Framework 2.0 is a voluntary, outcome-based structure for managing cybersecurity risk across organizations of any size or sector. Its Core organizes outcomes under Govern, Identify, Protect, Detect, Respond, and Recover, supported by organizational profiles, implementation tiers, quick-start guides, and mappings. It provides a common language for aligning leadership, risk, and technical teams without prescribing products or exact controls. A practical adoption starts with a Current Profile grounded in interviews and evidence, defines a Target Profile informed by threats and obligations, and prioritizes gaps according to mission impact and resources. The Informative References can connect outcomes to detailed control catalogs such as SP 800-53, but a mapping is not proof that a control is implemented or effective. Use Tiers to discuss the rigor of risk governance, not as a simple maturity score. Organizations must tailor outcomes to their mission, threats, obligations, and resources; using the framework alone does not establish compliance or effective implementation.

Strengths

  • Authoritative, technology-neutral vocabulary for organization-wide cybersecurity risk management
  • Flexible profiles and tiers support gap analysis, target-state planning, and stakeholder communication
  • Extensive implementation examples and mappings connect outcomes to more detailed standards

Limitations

  • Outcome-based guidance does not prescribe detailed controls, tests, or implementation priorities
  • Adoption or profile completion does not by itself demonstrate security effectiveness or regulatory compliance

Best for

  • Cybersecurity program design
  • Current-state and target-state profiles
  • Executive risk communication
  • Cross-framework alignment

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 5/5

Authoritative, technology-neutral vocabulary for organization-wide cybersecurity risk management; principal limitation: Outcome-based guidance does not prescribe detailed controls, tests, or implementation priorities.

Audience

  • security leaders
  • risk managers
  • security architects
  • policy makers
  • small and large organizations

Formats

  • framework
  • implementation guides
  • profiles
  • reference tool
  • mappings

Keywords

  • standards
  • security-framework
  • risk-management
  • governance
  • cyber-resilience
  • security-program
  • nist-csf

Link validation: Reachable · checked 2026-09-07 · HTTP 200

FrameworkAssessment tier A

NIST SP 800-207 Zero Trust Architecture

National Institute of Standards and Technology

Visit source : NIST SP 800-207 Zero Trust Architecture

NIST SP 800-207 defines zero trust as an architectural approach that removes implicit trust based on network location or ownership and focuses protection on users, devices, assets, services, and workflows. It describes logical components, policy decision and enforcement, deployment models, use cases, and migration considerations for enterprise environments. The publication is a strong vendor-neutral conceptual baseline for zero-trust programs. It is not a product blueprint, certification, or step-by-step implementation plan, and its 2020 examples should be supplemented with current cloud-native and identity-specific guidance.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

NIST SP 800-207 defines zero trust as an architectural approach that removes implicit trust based on network location or ownership and focuses protection on users, devices, assets, services, and workflows. It describes logical components, policy decision and enforcement, deployment models, use cases, and migration considerations for enterprise environments. The publication is a strong vendor-neutral conceptual baseline for zero-trust programs. Architecture teams can use its policy engine, policy administrator, and policy enforcement point model to separate decisions from enforcement and identify required identity, device, workload, and telemetry inputs. Map existing access paths and trust assumptions first, then plan incremental migration around high-value resources and measurable policy outcomes. Use the document to test vendor claims against architectural principles, while supplementing it with implementation guidance for cloud workloads, service identities, and modern identity protocols. It is not a product blueprint, certification, or step-by-step implementation plan, and its 2020 examples should be supplemented with current cloud-native and identity-specific guidance.

Strengths

  • Canonical vendor-neutral definition of zero-trust principles and logical architecture
  • Explains policy decision, enforcement, telemetry, trust evaluation, and deployment models
  • Counters perimeter-only interpretations with a resource- and identity-focused model

Limitations

  • Conceptual architecture requires substantial organization-specific engineering to implement
  • It does not certify products or guarantee that a marketed zero-trust solution meets the model

Best for

  • Zero-trust architecture planning
  • Identity and access strategy
  • Vendor requirement evaluation
  • Legacy-to-modern security migration

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 5/5

Canonical vendor-neutral definition of zero-trust principles and logical architecture; principal limitation: Conceptual architecture requires substantial organization-specific engineering to implement.

Audience

  • security architects
  • identity engineers
  • network architects
  • security leaders
  • cloud practitioners

Formats

  • architecture standard
  • pdf publication
  • deployment models
  • use cases
  • references

Keywords

  • standards
  • zero-trust
  • security-architecture
  • identity-security
  • access-control
  • network-security
  • cloud-security
  • risk-management

Link validation: Reachable · checked 2026-09-07 · HTTP 200

FrameworkAssessment tier A

NIST SP 800-53

National Institute of Standards and Technology

Visit source : NIST SP 800-53

NIST SP 800-53 Revision 5 is a comprehensive catalog of security and privacy controls for information systems and organizations. Its outcome-oriented control families cover governance, access, operations, incident response, system integrity, supply chains, privacy, and related risks, with machine-readable OSCAL versions available. The catalog supports the NIST Risk Management Framework and many crosswalks beyond U.S. federal use. SP 800-53 is not a ready-made checklist: baselines, tailoring, assessment procedures, implementation evidence, and organizational risk decisions must come from companion publications and local context.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

NIST SP 800-53 Revision 5 is a comprehensive catalog of security and privacy controls for information systems and organizations. Its outcome-oriented control families cover governance, access, operations, incident response, system integrity, supply chains, privacy, and related risks, with machine-readable OSCAL versions available. The catalog supports the NIST Risk Management Framework and many crosswalks beyond U.S. federal use. Architects can select an applicable baseline through companion guidance, tailor it for system characteristics and inherited services, assign responsibility, and define evidence that will demonstrate implementation. Assessors should use the corresponding assessment procedures and test design rather than infer effectiveness from policy text. OSCAL representations help exchange control catalogs, profiles, component definitions, and assessment information, but automation still depends on accurate scoping and evidence. Crosswalks to other frameworks are navigation aids, not equivalence statements. SP 800-53 is not a ready-made checklist: baselines, tailoring, assessment procedures, implementation evidence, and organizational risk decisions must come from companion publications and local context.

Strengths

  • Deep, authoritative catalog integrating security, privacy, and supply-chain controls
  • Outcome-based controls are reusable across technologies and organizational levels
  • Machine-readable OSCAL data and companion publications support automation and assessment

Limitations

  • The catalog is large and requires expert tailoring, scoping, and prioritization
  • Control text alone does not supply baselines or prove that implementation is effective

Best for

  • Enterprise control architecture
  • Federal and regulated-system programs
  • Control mapping and assurance planning
  • Security and privacy requirements engineering

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 5/5

Deep, authoritative catalog integrating security, privacy, and supply-chain controls; principal limitation: The catalog is large and requires expert tailoring, scoping, and prioritization.

Audience

  • security architects
  • risk and compliance teams
  • system owners
  • auditors
  • privacy professionals

Formats

  • control catalog
  • pdf standard
  • oscal data
  • spreadsheets
  • supporting guidance

Keywords

  • standards
  • security-controls
  • privacy-controls
  • risk-management
  • governance
  • supply-chain-security
  • compliance
  • oscal

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Government

3 sources

GovernmentAssessment tier A

NCSC Ireland Guidance

National Cyber Security Centre of Ireland

Visit source : NCSC Ireland Guidance

Ireland’s National Cyber Security Centre publishes official guidance for organizations operating within Ireland and the European regulatory environment. The collection covers incident preparation, cyber governance, NIS2 risk-management measures, Cyber Resilience Act reporting, cloud and remote work, and newer subjects such as public-sector AI deployment. It is particularly useful for translating EU obligations into practical security actions. The collection is smaller than some national guidance libraries, and draft or consultation material must be distinguished from final requirements and checked against applicable legislation and regulator instructions.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Ireland’s National Cyber Security Centre publishes official guidance for organizations operating within Ireland and the European regulatory environment. The collection covers incident preparation, cyber governance, NIS2 risk-management measures, Cyber Resilience Act reporting, cloud and remote work, and newer subjects such as public-sector AI deployment. It is particularly useful for translating EU obligations into practical security actions. Security and governance teams can use the publications to identify expected management measures, reporting considerations, and sector-relevant preparation activities, then map them to internal controls, accountable owners, and evidence. Pair the operational recommendations with ENISA implementation material and the exact Irish or EU legal text that applies to the organization. Always capture publication status and date: a consultation paper, explanatory guide, regulator notice, and enacted obligation carry different authority. The collection is smaller than some national guidance libraries, and draft or consultation material must be distinguished from final requirements and checked against applicable legislation and regulator instructions.

Strengths

  • Official Irish guidance aligned with current EU cybersecurity obligations
  • Practical material for governance, incident readiness, and emerging technologies
  • Clear value for public-sector and NIS2-regulated organizations

Limitations

  • Some documents are drafts or consultation material rather than final regulatory requirements
  • Jurisdiction-specific guidance should not be generalized without checking local law

Best for

  • Irish and EU regulatory readiness
  • Management-board cyber governance
  • Public-sector AI risk assessment
  • Incident and resilience planning

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Official Irish guidance aligned with current EU cybersecurity obligations; principal limitation: Some documents are drafts or consultation material rather than final regulatory requirements.

Audience

  • Irish organizations
  • public-sector leaders
  • risk managers
  • security architects
  • compliance teams

Formats

  • government guidance
  • risk assessments
  • regulatory guidance
  • pdf publications
  • planning documents

Keywords

  • government
  • security-guidance
  • nis2
  • cyber-resilience-act
  • risk-management
  • incident-response
  • ai-security
  • ireland

Link validation: Reachable · checked 2026-09-07 · HTTP 200

GovernmentAssessment tier A

NCSC UK Guidance

UK National Cyber Security Centre

Visit source : NCSC UK Guidance

The UK National Cyber Security Centre’s guidance library provides official, audience-specific advice for individuals, small organizations, large enterprises, public bodies, boards, and cybersecurity professionals. It spans foundational hygiene, secure design, identity, cloud, supply chains, incident management, ransomware, AI, and critical services, and links to practical programs and assessment material. The guidance is concise and operationally oriented, making it a strong starting point for policy and architecture. It reflects UK threat, legal, and government contexts and is not a detailed implementation standard for every technology.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The UK National Cyber Security Centre’s guidance library provides official, audience-specific advice for individuals, small organizations, large enterprises, public bodies, boards, and cybersecurity professionals. It spans foundational hygiene, secure design, identity, cloud, supply chains, incident management, ransomware, AI, and critical services, and links to practical programs and assessment material. The guidance is concise and operationally oriented, making it a strong starting point for policy and architecture. Teams can use it to establish policy principles, brief leadership, create incident-readiness checklists, and translate common threats into proportionate baseline actions. More mature programs should connect each recommendation to a named owner, implementation evidence, testing method, and a detailed control framework such as the NIST CSF or Cyber Assessment Framework. Check the page’s intended audience and linked collection because similarly named advice may address home users, small businesses, or regulated operators differently. It reflects UK threat, legal, and government contexts and is not a detailed implementation standard for every technology.

Strengths

  • Authoritative UK guidance written for clearly identified audiences
  • Broad coverage from personal safety and small-business hygiene to enterprise architecture
  • Translates technical risk into practical governance and implementation advice

Limitations

  • Recommendations reflect UK policy and may need adaptation for other jurisdictions
  • Many pages are concise guidance rather than detailed engineering specifications

Best for

  • Security-program baselines
  • Board and risk communication
  • Incident preparedness
  • Secure architecture and policy guidance

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Authoritative UK guidance written for clearly identified audiences; principal limitation: Recommendations reflect UK policy and may need adaptation for other jurisdictions.

Audience

  • individuals
  • small businesses
  • security leaders
  • security architects
  • public-sector organizations

Formats

  • web guidance
  • collections
  • toolkits
  • pdf guidance
  • checklists

Keywords

  • government
  • security-guidance
  • cyber-resilience
  • risk-management
  • incident-response
  • security-architecture
  • cyber-hygiene
  • united-kingdom

Link validation: Reachable · checked 2026-09-07 · HTTP 200

GovernmentAssessment tier B

ENISA Publications

European Union Agency for Cybersecurity

Visit source : ENISA Publications

ENISA’s publications portal is the European Union Agency for Cybersecurity’s library of reports, methodologies, implementation guidance, sector assessments, threat landscapes, certification work, and policy-oriented studies. It provides a vendor-neutral institutional view of EU cyber resilience, NIS2, product security, critical sectors, incident response, skills, and emerging technology. The portal is strong for strategic analysis and European governance context, with some technically actionable reports. Scope and depth vary by publication, and many conclusions synthesize public reporting rather than expose raw operational telemetry.

Source type
Government
Access
Free
Evidence use
Mixed
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

ENISA’s publications portal is the European Union Agency for Cybersecurity’s library of reports, methodologies, implementation guidance, sector assessments, threat landscapes, certification work, and policy-oriented studies. It provides a vendor-neutral institutional view of EU cyber resilience, NIS2, product security, critical sectors, incident response, skills, and emerging technology. The portal is strong for strategic analysis and European governance context, with some technically actionable reports. Use a threat-landscape report to update assumptions and vocabulary, a sector study to frame dependencies and systemic risks, and implementation guidance to derive program questions or controls. For compliance work, connect ENISA interpretation to applicable legislation, national transposition, and competent-authority guidance rather than treating an agency report as legal advice. Review each document’s methodology, data period, contributors, and target audience before comparing findings across years or sectors. Scope and depth vary by publication, and many conclusions synthesize public reporting rather than expose raw operational telemetry.

Strengths

  • Authoritative EU institutional source with broad sector and policy coverage
  • Publishes transparent methodologies, threat landscapes, and implementation guidance
  • Useful bridge between cybersecurity operations, resilience, and European regulation

Limitations

  • Technical depth and timeliness vary across a large and heterogeneous publication library
  • Threat-landscape products often synthesize open sources and should not be treated as raw telemetry

Best for

  • EU policy and regulatory research
  • Sector threat-landscape analysis
  • Cyber-resilience program design
  • Strategic and board-level briefings

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Authoritative EU institutional source with broad sector and policy coverage; principal limitation: Technical depth and timeliness vary across a large and heterogeneous publication library.

Audience

  • policy makers
  • security leaders
  • risk managers
  • cti analysts
  • critical-sector operators

Formats

  • research reports
  • threat landscapes
  • methodologies
  • implementation guidance
  • policy studies

Keywords

  • government
  • european-union
  • threat-reports
  • cyber-resilience
  • nis2
  • critical-infrastructure
  • risk-management
  • policy

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Incident Response

1 source

Incident ResponseAssessment tier A

NIST SP 800-61 Rev. 3

National Institute of Standards and Technology

Visit source : NIST SP 800-61 Rev. 3

NIST SP 800-61 Revision 3 is the April 2025 incident-response community profile for the NIST Cybersecurity Framework 2.0. It explains how organizations can integrate preparation, detection, response, recovery, and improvement into enterprise cybersecurity risk management. The publication is a strong governance and program-design reference for incident-response leaders, assessors, and security architects. It intentionally provides outcome-oriented recommendations rather than product instructions, forensic procedures, or ready-to-run playbooks, so teams must translate it into environment-specific roles and workflows.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

NIST SP 800-61 Revision 3 is the National Institute of Standards and Technology's April 2025 incident-response community profile for the NIST Cybersecurity Framework 2.0. It organizes incident preparation, detection, response, recovery, and continual improvement as enterprise risk-management outcomes rather than a stand-alone technical function. Security leaders can use it to define responsibilities, align incident plans with CSF Govern through Recover activities, evaluate readiness, structure exercises, and communicate expectations to executives, legal teams, suppliers, and operational responders. It works best alongside NIST CSF for program outcomes, SP 800-53 for control selection, and organization-specific forensic procedures, escalation matrices, communications plans, and playbooks. The publication is authoritative federal guidance and provides stable terminology for policies, audits, and assessments, but it is intentionally technology-neutral. It does not prescribe evidence-collection commands, SIEM queries, containment steps, staffing models, or regulatory decisions. Teams must translate its recommendations into tested workflows that reflect their systems, threat model, jurisdiction, contractual duties, and tolerance for operational disruption.

Strengths

  • Authoritative federal guidance aligned directly to NIST CSF 2.0 outcomes
  • Treats incident response as an organization-wide risk-management capability
  • Stable terminology and recommendations suitable for policies and assessments

Limitations

  • Does not provide tool-specific investigation procedures or executable playbooks
  • Requires local tailoring for legal, regulatory, staffing, and technology contexts

Best for

  • incident-response program design
  • policy and governance reviews
  • tabletop planning
  • control assessment criteria

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.5/5
  • Transparency 5/5

Authoritative federal guidance aligned directly to NIST CSF 2.0 outcomes; principal limitation: Does not provide tool-specific investigation procedures or executable playbooks.

Audience

  • incident-response leaders
  • security architects
  • risk managers
  • auditors

Formats

  • standard
  • pdf
  • implementation guidance

Keywords

  • incident-response
  • nist-csf
  • risk-management
  • governance
  • preparation
  • recovery
  • standards

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Vulnerability

1 source

VulnerabilityAssessment tier A

FIRST CVSS v4.0

Forum of Incident Response and Security Teams

Visit source : FIRST CVSS v4.0

FIRST’s CVSS v4.0 site is the canonical specification, user guide, examples, calculator, and supporting material for the Common Vulnerability Scoring System. Version 4.0 separates base, threat, environmental, and supplemental metrics and improves representation of downstream and operational-technology impacts. It gives vendors and defenders a consistent vocabulary for communicating technical severity. CVSS does not measure exploitation probability, asset exposure, business value, or complete risk; scores should be interpreted with environmental context and combined with KEV, EPSS, and vendor remediation information.

Source type
Standards Body
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

FIRST’s CVSS v4.0 site is the canonical specification, user guide, examples, calculator, and supporting material for the Common Vulnerability Scoring System. Version 4.0 separates base, threat, environmental, and supplemental metrics and improves representation of downstream and operational-technology impacts. It gives vendors and defenders a consistent vocabulary for communicating technical severity. Assessors should record the full vector, not only the numeric score, because the metric choices make assumptions reviewable and reproducible. Start from the publisher’s Base metrics, update Threat information when supported, and calculate Environmental metrics for the affected deployment and its safety or mission consequences. Compare vectors when two teams disagree rather than averaging scores. Use the official examples and calculator for training, then retain evidence for every metric decision. CVSS does not measure exploitation probability, asset exposure, business value, or complete risk; scores should be interpreted with environmental context and combined with KEV, EPSS, and vendor remediation information.

Strengths

  • Canonical specification and calculator for a widely used vulnerability-severity standard
  • Defines reproducible metrics and vector notation for communicating technical characteristics
  • Version 4.0 adds clearer threat, environmental, and supplemental context

Limitations

  • CVSS measures severity characteristics, not exploitation likelihood or complete organizational risk
  • Scores can vary with assessor assumptions and incomplete environmental information

Best for

  • Vulnerability severity assessment
  • Interpreting vendor security advisories
  • Standardized risk communication
  • Training vulnerability analysts

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 5/5

Canonical specification and calculator for a widely used vulnerability-severity standard; principal limitation: CVSS measures severity characteristics, not exploitation likelihood or complete organizational risk.

Audience

  • vulnerability analysts
  • product security teams
  • risk managers
  • security researchers
  • incident responders

Formats

  • standard specification
  • user guide
  • calculator
  • examples
  • training materials

Keywords

  • vulnerability-management
  • cvss
  • severity-scoring
  • risk-communication
  • standards
  • vulnerability-assessment
  • vulnerability-scoring

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.