Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Container Security

1 source

Container SecurityAssessment tier A

Falco

Cloud Native Computing Foundation

Visit source : Falco

Falco is an Apache-2.0, CNCF graduated project for cloud-native runtime detection across Linux hosts, containers, Kubernetes, and plugin-provided event sources. Its privileged agent observes kernel events, enriches them with workload context, evaluates YAML rules, and emits alerts for downstream response or analysis. A maintained rules ecosystem and transparent release process support customization. Falco detects and notifies rather than enforcing controls, and production value depends on safe driver deployment, event visibility, version-compatible rules, environment profiling, tuning, and alert routing.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Falco is an Apache-2.0 open-source runtime-security project originally created by Sysdig and now governed as a graduated Cloud Native Computing Foundation project. Its agent observes Linux kernel activity through supported drivers, enriches events with container and Kubernetes context, evaluates a rule engine, and sends alerts to downstream systems. Plugins extend collection beyond system calls, while versioned stable, incubating, and sandbox rule artifacts let teams adopt content at different maturity levels. The project publishes source, packages, container images, drivers, rules, documentation, and a defined release process; official releases remained active in 2026. Falco is a detection and notification component, not an enforcement, isolation, or incident-response product. It runs with sensitive host and kernel visibility, so driver choice, privileges, package provenance, configuration access, and output protection matter. Default rules intentionally surface behaviors that may be normal in a given workload and require profiling, exceptions, severity design, and performance testing. Conversely, unsupported kernels, missing event sources, disabled rules, container abstractions, or attacker evasion can create blind spots. Pin compatible engine, driver, plugin, and rules versions; test controlled behaviors; monitor dropped events; and validate alerts with orchestration, cloud, network, and application evidence.

Strengths

  • Transparent CNCF governance and Apache-2.0 source support independent inspection and adoption
  • Kernel-event rules enriched with container and Kubernetes context enable practical runtime detection
  • Versioned rules, plugins, packages, and release processes form a mature operational ecosystem

Limitations

  • Falco detects and alerts but does not itself block, isolate, or remediate activity
  • Privileged kernel visibility creates deployment, compatibility, performance, and security considerations
  • Default rules require environment profiling and tuning, while missing or dropped events can create blind spots

Best for

  • Kubernetes runtime detection
  • container behavior monitoring
  • Linux syscall threat detection
  • cloud-native detection engineering

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Transparent CNCF governance and Apache-2.0 source support independent inspection and adoption; principal limitation: Falco detects and alerts but does not itself block, isolate, or remediate activity.

Audience

  • cloud-security engineers
  • Kubernetes platform teams
  • detection engineers
  • SOC analysts

Formats

  • software agent
  • YAML rules
  • github repositories
  • plugins
  • documentation
  • release packages

Keywords

  • container-security
  • kubernetes
  • cloud-security
  • detection-engineering
  • soc
  • blue-team
  • tools
  • repositories
  • runtime-security
  • linux
  • rules

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Network Security

3 sources

Network SecurityAssessment tier A

Arkime

Arkime Project

Visit source : Arkime

Arkime is an actively maintained Apache-2.0 platform for large-scale full-packet capture, session metadata extraction, indexing, search, and packet retrieval. Sensors retain PCAP while the viewer and OpenSearch or Elasticsearch-backed metadata enable analysts to pivot across network sessions; companion components add intelligence workflows and cluster management. Arkime provides powerful retrospective evidence but demands substantial storage, database, access-control, and lifecycle engineering. Packet capture is sensitive, visibility is placement-dependent, and metadata or search results do not by themselves establish malicious activity.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Arkime is an Apache-2.0 open-source platform for capturing, indexing, searching, and retrieving network traffic at scale. Its sensors write full packet capture to local or managed storage while extracting session metadata into a supported OpenSearch or Elasticsearch cluster; the viewer lets analysts pivot from fields and timelines back to packets. The project also includes components for intelligence investigation and multi-cluster management. Arkime's public repository and current documentation are actively maintained, with official packages, containers, upgrade guidance, compatibility matrices, and 2026 releases. It is especially useful when incident responders need retrospective protocol evidence beyond alerts, but it is not a turnkey appliance. Production sizing requires sustained packet throughput, retention calculations, database capacity, separate storage planning, encryption, authentication, role design, clock accuracy, and monitored capture loss. Sensor placement, asymmetric routing, encrypted sessions, tunneling, sampling, and retention gaps can leave material blind spots. PCAP may contain credentials, personal data, regulated content, and proprietary traffic; minimize collection, restrict access, define lawful retention, and audit exports. Treat metadata and intelligence enrichment as leads, validate conclusions against packets and endpoint evidence, and follow sequential upgrade requirements rather than skipping major versions.

Strengths

  • Links indexed session metadata to retained full packets for retrospective investigation
  • Open-source architecture gives operators control over capture, storage, search, and integrations
  • Active documentation and releases cover deployment, scaling, compatibility, security, and upgrades

Limitations

  • Large deployments require substantial packet storage, search-cluster capacity, and operational engineering
  • Capture placement, packet loss, encryption, retention, and asymmetric routing create visibility gaps
  • Full packet data can expose credentials, personal information, and regulated content requiring strict governance

Best for

  • network forensic investigation
  • full-packet capture operations
  • retrospective threat hunting
  • session metadata analysis

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Links indexed session metadata to retained full packets for retrospective investigation; principal limitation: Large deployments require substantial packet storage, search-cluster capacity, and operational engineering.

Audience

  • network-security analysts
  • incident responders
  • threat hunters
  • security platform engineers

Formats

  • software platform
  • documentation
  • github repository
  • release packages
  • APIs

Keywords

  • network-security
  • dfir
  • incident-response
  • soc
  • blue-team
  • tools
  • repositories
  • full-packet-capture
  • network-forensics
  • threat-hunting
  • privacy

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Network SecurityAssessment tier A

Snort

Cisco and the Snort community

Visit source : Snort

Snort is Cisco's actively maintained open-source network intrusion detection and prevention engine for real-time packet analysis, logging, and inline inspection. Snort 3 adds multithreaded processing, a modular plugin architecture, service identification, and an updated rule language. Access and licensing differ by artifact: the engine and Community Rules are open source, registered rules are delayed and restricted, and current Talos subscriber rules are paid. Effective deployment depends on validated traffic visibility, tuning, performance, and ruleset provenance.

Source type
Mixed License Tool
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Snort is an open-source network intrusion detection and prevention engine maintained by Cisco with community participation. Snort 3 processes live or recorded traffic, applies protocol-aware inspection and a flexible rule language, and can operate as a packet sniffer, logger, passive IDS, or inline IPS. Its multithreaded architecture, service identification, Lua configuration, plugin system, reference documentation, and rule-writing guidance make it useful for network detection engineering and controlled packet analysis. Licensing and access must be evaluated per component. Cisco documents a dual-license strategy for the engine; the Community Ruleset is GPLv2 and freely available, the free Registered Ruleset requires an account and receives detections after a delay with additional restrictions, and the current Cisco Talos Subscriber Ruleset is paid. Do not present those rule channels as equivalent. Rules are signatures, not proof of compromise, and defaults cannot account for local protocols, encrypted traffic, asymmetric routing, packet loss, address translation, or accepted risk. Before inline deployment, test supported versions, DAQ mode, throughput, evasion cases, rule provenance, update timing, suppressions, and failure behavior. Inspect alerts against packet and endpoint evidence, and stage blocking changes to avoid operational disruption.

Strengths

  • Mature open-source IDS and IPS engine with protocol-aware real-time packet inspection
  • Snort 3 provides multithreading, modular plugins, service identification, and extensive rule documentation
  • Cisco Talos and community rule channels support current detection development at different access levels

Limitations

  • Engine, Community, Registered, and Subscriber artifacts have materially different licenses, delays, and access terms
  • Encrypted or incomplete traffic, local topology, and evasive behavior constrain network visibility
  • Rules require performance testing and local tuning, especially before any inline blocking action

Best for

  • network intrusion detection
  • packet-oriented detection engineering
  • IDS and IPS rule research
  • controlled PCAP analysis

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Mature open-source IDS and IPS engine with protocol-aware real-time packet inspection; principal limitation: Engine, Community, Registered, and Subscriber artifacts have materially different licenses, delays, and access terms.

Audience

  • network defenders
  • detection engineers
  • SOC analysts
  • security researchers

Formats

  • software engine
  • rule feeds
  • reference manuals
  • github repository
  • release packages

Keywords

  • network-security
  • detection-engineering
  • soc
  • blue-team
  • tools
  • repositories
  • feeds
  • ids
  • ips
  • packet-analysis
  • rule-authoring
  • rulesets

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Network SecurityAssessment tier A

Shodan

Shodan, LLC

Visit source : Shodan

Shodan is a proprietary search and intelligence platform for services directly reachable from the internet. It continuously collects protocol banners and related metadata and exposes them through search, maps, command-line tools, APIs, monitoring, and commercial datasets. Defenders use it to find external exposure and enrich IP investigations. Basic search is available broadly, while accounts, a paid membership, subscriptions, credits, or enterprise licensing unlock additional filters, downloads, monitoring, scans, and bulk data. Results are observations, not verified asset inventories or vulnerability proof.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Shodan is a proprietary internet-intelligence platform operated by Shodan, LLC. Its scanners collect publicly available service banners and related metadata from internet-connected systems, which users can explore through the main search engine, specialized websites, command-line tooling, developer APIs, monitoring, data downloads, and enterprise feeds. Defenders use it to discover externally visible services, compare an organization's inventory with observed exposure, estimate technology prevalence, and enrich an IP during incident or vulnerability triage. Access is tiered: some search is available without an account, free accounts provide limited capabilities, a paid lifetime membership expands individual access, and subscriptions or enterprise licenses govern higher-volume APIs, monitoring, scans, history, and bulk data. Current limits and prices can change, and Shodan's terms require appropriate attribution for derived materials. A banner is a time-stamped remote observation; it may be stale, incomplete, misleading, associated with shared infrastructure, or collected from a different network perspective. A product string or vulnerability tag does not prove ownership, reachability, or exploitability. Confirm findings with asset owners and authorized local evidence. On-demand scanning and follow-on interaction are dual-use and must be limited to systems you are permitted to assess.

Strengths

  • Large continuously refreshed corpus of internet-facing service banners and metadata
  • Search, API, monitoring, and data products support exposure discovery and IP enrichment
  • Useful independent observation for comparing declared inventory with externally visible services

Limitations

  • Banners and tags can be stale, incomplete, shared, misidentified, or collected from a different network perspective
  • Useful filters, credits, downloads, monitoring, scanning, history, and bulk access vary substantially by paid tier
  • Search results do not prove asset ownership, current reachability, vulnerability, exploitation, or compromise

Best for

  • external attack-surface discovery
  • internet-service research
  • IP and vulnerability triage
  • asset-inventory comparison

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Large continuously refreshed corpus of internet-facing service banners and metadata; principal limitation: Banners and tags can be stale, incomplete, shared, misidentified, or collected from a different network perspective.

Audience

  • attack-surface analysts
  • network defenders
  • vulnerability teams
  • threat-intelligence analysts

Formats

  • search engine
  • API
  • command-line tools
  • monitoring service
  • internet scan datasets

Keywords

  • network-security
  • cti
  • datasets
  • tools
  • vulnerability-management
  • internet-scanning
  • attack-surface-management
  • asset-discovery
  • ip-enrichment
  • freemium
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

OSINT

1 source

OSINTAssessment tier C

OSINT Framework

Justin Nordine / lockFALE

Visit source : OSINT Framework

OSINT Framework is Justin Nordine’s free, MIT-licensed discovery tree for locating open-source research tools and resources by input or investigative task. Its maintained catalog labels entries that require local installation, registration, query editing, or Google dorks, and newer metadata records status, pricing, inputs, outputs, and operational-security mode. It is most useful at the start of an investigation. Because it aggregates third-party services, every link, access condition, result, and collection method must be independently verified before use.

Source type
Independent Technical
Access
Free
Evidence use
Secondary Corroborating
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

OSINT Framework, created by Justin Nordine and maintained in lockFALE’s public repository, presents a browsable tree of open-source intelligence resources. Researchers can begin with an identifier or task—such as a username, email address, domain, IP address, social platform, document, image, map, or archive—and follow the relevant branch to candidate tools and data sources. The project’s markers distinguish local tools, registration-gated services, editable query URLs, and Google dorks; its newer structured metadata can also describe pricing, input, output, status, and whether a technique is passive or active. This makes the framework a useful discovery and planning aid, not an evidentiary authority. Each listing points to a separately operated service whose ownership, terms, coverage, accuracy, availability, and data-handling practices can change. Before using a resource, confirm its current status and lawful purpose, determine whether it contacts a subject or third party, avoid submitting unnecessary personal or confidential identifiers, and record the exact service and collection time. Corroborate all returned associations with primary records and preserve provenance before relying on them in an investigation.

Strengths

  • Broad, task-oriented discovery tree for free and partly free OSINT resources
  • Transparent MIT-licensed source repository with community contribution paths
  • Operational metadata helps distinguish registration, installation, pricing, and active-versus-passive considerations

Limitations

  • Aggregates third-party links whose ownership, access model, availability, and quality can change independently
  • A listing or tool result is not verified evidence and does not establish that a collection method is lawful, proportionate, or passive

Best for

  • discovering candidate OSINT tools
  • planning identifier-based research
  • comparing free and freemium collection options
  • teaching the breadth of OSINT workflows

Quality dimensions

  • Authority 3.5/5
  • Originality 3/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Broad, task-oriented discovery tree for free and partly free OSINT resources; principal limitation: Aggregates third-party links whose ownership, access model, availability, and quality can change independently.

Audience

  • OSINT investigators
  • CTI analysts
  • security researchers
  • journalists
  • students

Formats

  • interactive resource tree
  • tool directory
  • github repository
  • structured tool metadata

Keywords

  • osint
  • source-discovery
  • reconnaissance
  • investigative-tools
  • resource-directory
  • opsec
  • privacy
  • community
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

OT/ICS Security

1 source

OT/ICS SecurityAssessment tier A

Dragos

Dragos, Inc.

Visit source : Dragos

Dragos publishes operational-technology and industrial-control-system threat research grounded in its platform telemetry, incident response, vulnerability analysis, and field engagements. Its resource library includes annual Year in Review reports, adversary and malware research, defensive guidance, webinars, and selected community resources; its WorldView intelligence and platform are commercial. The material is highly valuable within OT, but vendor-defined threat groups, prevalence statistics, and vulnerability priorities reflect Dragos visibility and methodology and require corroboration before attribution or operational change.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Dragos is a commercial operational-technology security company whose public resource library combines annual OT/ICS Cybersecurity Year in Review reports, threat-group and malware research, vulnerability analysis, incident-response lessons, webinars, and practical guidance for industrial defenders. Its research draws on first-party platform telemetry, incident response, penetration tests, assessments, and analyst investigations, giving readers unusually detailed context about adversary behavior and defensive gaps in industrial environments. Some public materials are directly readable, while reports, OT-CERT or community programs, and other resources may require registration or eligibility; continuous WorldView intelligence and the Dragos Platform are paid offerings. Treat access conditions and permitted reuse separately for each asset. Dragos threat-group names, activity counts, prevalence figures, and vulnerability priorities are vendor assessments shaped by customer sectors, collection visibility, and analytic thresholds. Cross-check important attribution with government advisories and independent reporting, and validate vulnerability or mitigation advice against the affected vendor and local engineering constraints. OT changes can affect safety and availability: asset owners, operators, and control engineers must review proposed monitoring, segmentation, patching, or response actions before implementation rather than applying enterprise-IT guidance directly.

Strengths

  • Deep first-party OT and ICS research informed by incident response, assessments, and platform telemetry
  • Annual reports and technical publications connect threat activity, vulnerabilities, and defensive practice
  • Specialist focus supplies context often absent from enterprise-IT intelligence sources

Limitations

  • Threat-group, prevalence, and prioritization claims reflect proprietary visibility and vendor methodology
  • Some resources require registration or eligibility, while continuous intelligence and platform capabilities are paid
  • Recommendations require engineering and safety review before any change to fragile industrial environments

Best for

  • OT threat-landscape research
  • industrial incident-response planning
  • ICS vulnerability prioritization
  • critical-infrastructure defensive strategy

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Deep first-party OT and ICS research informed by incident response, assessments, and platform telemetry; principal limitation: Threat-group, prevalence, and prioritization claims reflect proprietary visibility and vendor methodology.

Audience

  • OT security analysts
  • industrial incident responders
  • control engineers
  • critical-infrastructure leaders

Formats

  • threat reports
  • technical articles
  • vulnerability research
  • webinars
  • community guidance

Keywords

  • threat-research
  • threat-reports
  • cti
  • incident-response
  • vulnerability-research
  • network-security
  • ot-security
  • ics-security
  • critical-infrastructure
  • freemium

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Reverse Engineering

1 source

Reverse EngineeringAssessment tier A

x64dbg

x64dbg Project

Visit source : x64dbg

x64dbg is an actively maintained, open-source user-mode debugger for 32-bit and 64-bit Windows, optimized for reverse engineering and malware analysis. Its GUI, disassembly, memory and module views, breakpoints, tracing, graphing, scripting, patching, and plugin interfaces support dynamic analysis of native executables and DLLs. The core is GPL-licensed with an explicit plugin exception. Debugging untrusted binaries remains hazardous, Windows-focused, and vulnerable to anti-debugging, environmental, and analyst-interpretation errors.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

x64dbg is a free, open-source user-mode debugger for 32-bit and 64-bit Windows executables and DLLs. The community project provides a graphical interface with disassembly, registers, memory maps and dumps, modules, symbols, threads, call stacks, control-flow graphs, conditional breakpoints, tracing, executable patching, scripting, and an extensible plugin API. Malware analysts use it to observe unpacking, API calls, configuration handling, memory changes, and control flow; vulnerability researchers use it to reproduce crashes and inspect native application behavior. Official documentation identifies the x64dbg core as GPL licensed, with differing licenses for bundled components and an explicit exception allowing independently licensed plugins through the provided interface, so redistribution should follow the license inventory rather than treating the bundle as one artifact. The project remains active and published an official release in May 2026. x64dbg is Windows-centric and user-mode observations do not cover every kernel, firmware, managed-code, or anti-analysis scenario. Debugger presence can change program behavior, and executable patching changes evidence. Use snapshots in a segmented lab, hash inputs and outputs, record architecture and build details, and corroborate observations with static analysis, packet capture, and operating-system telemetry.

Strengths

  • Rich Windows-native debugging interface designed for reverse engineering and malware analysis
  • Transparent source, documentation, scripting, and plugin interfaces support reproducible workflows
  • Active community maintenance includes current packaged releases

Limitations

  • Focuses on Windows user-mode native code and does not replace kernel, managed-code, or firmware tooling
  • Anti-debugging and environment-sensitive behavior can hide or alter malicious execution
  • Untrusted programs, plugins, scripts, and executable patching require strict isolation and evidence discipline

Best for

  • Windows malware dynamic analysis
  • native executable reverse engineering
  • crash reproduction
  • unpacking and control-flow investigation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Rich Windows-native debugging interface designed for reverse engineering and malware analysis; principal limitation: Focuses on Windows user-mode native code and does not replace kernel, managed-code, or firmware tooling.

Audience

  • malware analysts
  • reverse engineers
  • vulnerability researchers
  • exploit developers

Formats

  • desktop software
  • documentation
  • github repository
  • release binaries
  • plugin API

Keywords

  • reverse-engineering
  • malware-analysis
  • exploit-development
  • tools
  • repositories
  • windows
  • debugging
  • dynamic-analysis
  • binary-analysis
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Vulnerability

1 source

VulnerabilityAssessment tier B

Rapid7 Vulnerability & Exploit Database

Rapid7

Visit source : Rapid7 Vulnerability & Exploit Database

The Rapid7 Vulnerability & Exploit Database is a free, continuously updated search portal for CVE records, Rapid7 analysis, exploitation context, CVSS v3 and v4 scores, EPSS, exploited-in-the-wild indicators, and related Metasploit modules. It is the current destination for former AttackerKB URLs. The database is useful for triage and exploit-context discovery, but much of its breadth is aggregated rather than individually researched by Rapid7; every consequential claim still needs vendor, CVE, CISA KEV, and local-exposure validation.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Rapid7 Vulnerability & Exploit Database is Rapid7's current public portal for searching CVEs and connecting vulnerability records to exploit and threat context. Search results expose publication dates, CVSS v3 and v4 scores, EPSS values, exploited-in-the-wild indicators, and the presence of related Metasploit modules; selected records link to Rapid7 analyses, emergent-threat guidance, remediation context, or module documentation. The free, continuously refreshed catalog is useful for investigating a new identifier, discovering available exploit research, comparing prioritization signals, and tracing Rapid7's first-party work. It is also the maintained destination to which former AttackerKB URLs now redirect, but it is not the same community-assessment product and should not inherit descriptions of AttackerKB ratings, contributors, or API access. Database scale reflects aggregation: not every record has been independently validated or analyzed by Rapid7. Scores, exploitation flags, module mappings, and imported descriptions can change or lag upstream sources. Confirm affected products and versions with the vendor and CVE record, check CISA KEV and primary exploitation evidence, and evaluate local reachability and controls before prioritizing remediation. Exploit and Metasploit links are dual-use; use them only in an authorized isolated environment.

Strengths

  • Connects a broad CVE catalog with CVSS, EPSS, exploitation status, and Metasploit module context
  • Selected records link directly to Rapid7's original vulnerability and emergent-threat research
  • Free search supports rapid discovery without requiring a commercial Rapid7 product

Limitations

  • Most catalog records aggregate external vulnerability data rather than representing independent Rapid7 analysis
  • Scores, exploitation flags, mappings, and upstream descriptions can change or lag primary sources
  • The former AttackerKB community model and API should not be inferred from the replacement portal

Best for

  • CVE and exploit-context discovery
  • emerging-vulnerability triage
  • Metasploit module correlation
  • prioritization-signal comparison

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Connects a broad CVE catalog with CVSS, EPSS, exploitation status, and Metasploit module context; principal limitation: Most catalog records aggregate external vulnerability data rather than representing independent Rapid7 analysis.

Audience

  • vulnerability analysts
  • incident responders
  • penetration testers
  • risk-based remediation teams

Formats

  • vulnerability database
  • CVE records
  • search filters
  • technical analyses
  • exploit-module links

Keywords

  • vulnerability-management
  • vulnerability-research
  • exploit-development
  • threat-research
  • cti
  • risk-prioritization
  • cvss
  • epss
  • exploited-in-the-wild
  • metasploit
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.