Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

OSINT

5 sources

OSINTAssessment tier A

theHarvester

theHarvester maintainers and contributors

Visit source : theHarvester

theHarvester is a GPL-2.0-only open-source tool for gathering domain and organization intelligence from search engines, certificate-transparency logs, DNS datasets, code repositories, and threat-intelligence providers. Its command line, local HarvestView interface, REST API, and structured exports can normalize hostnames, emails, IPs, URLs, ASNs, people, and breach names with source provenance. Passive providers and selected DNS or direct actions have different traffic and authorization implications. Results are time-bound observations, not proof of ownership, reachability, vulnerability, or permission to expand scope.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

theHarvester supports the early reconnaissance stage of an authorized security assessment by querying many public or account-backed providers for information associated with a domain or organization. Current documentation separates passive provider lookups from DNS activity and direct target interaction, and can return normalized hostnames, email addresses, IP addresses, URLs, ASNs, people, and breach names. Operators can run one-off command-line collections or use the local HarvestView application and authenticated REST API; JSONL and SQLite preserve source outcomes and provenance more completely than the legacy JSON and XML reports. This structure is useful for repeatable attack-surface inventory, scoping review, enrichment, and comparison of provider yield. It does not make provider assertions authoritative. APIs change, quotas and credentials constrain coverage, search results can be stale, shared infrastructure can create misleading associations, and a discovered hostname or network relationship does not prove ownership, control, or authorization. Select only approved targets and source classes, review whether an option performs passive, DNS, or direct activity, and never promote a discovered relationship into scope automatically. Protect API keys and exports, minimize personal data, timestamp observations, resolve and validate findings separately, and corroborate material conclusions before reporting or acting on them.

Strengths

  • Aggregates many public providers while normalizing multiple result types and preserving provenance
  • Explicit activity classes distinguish passive lookups, DNS actions, and direct target interaction
  • CLI, local web workflow, REST API, and structured exports support repeatable collection

Limitations

  • Coverage and reliability depend on changing third-party APIs, credentials, quotas, schemas, and search indexes
  • Returned identifiers and relationships can be stale or ambiguous and never establish ownership, compromise, or authorization to expand scope

Best for

  • authorized domain footprinting
  • attack-surface inventory enrichment
  • certificate and DNS discovery
  • repeatable reconnaissance evidence collection

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.9/5
  • Transparency 5/5

Aggregates many public providers while normalizing multiple result types and preserving provenance; principal limitation: Coverage and reliability depend on changing third-party APIs, credentials, quotas, schemas, and search indexes.

Audience

  • penetration testers
  • attack-surface analysts
  • red teams
  • CTI analysts
  • security researchers

Formats

  • command-line tool
  • local web application
  • REST API
  • github repository
  • technical documentation
  • structured data exports

Keywords

  • osint
  • reconnaissance
  • attack-surface
  • subdomain-enumeration
  • email-discovery
  • certificate-transparency
  • data-provenance
  • privacy
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

OSINTAssessment tier A

Trace Labs

Trace Labs

Visit source : Trace Labs

Trace Labs is a nonprofit that crowdsources open-source intelligence to support law-enforcement work on missing-person cases while training investigators. Its Search Party events, ongoing operations, field manual, participant documentation, write-ups, and maintained OSINT virtual machine provide unusually concrete, people-centered practice. The program is not a general-purpose intelligence feed: cases involve real and potentially vulnerable people. Participants must follow the current rules of engagement, use passive zero-touch research, avoid contact or account interference, protect case data, and submit only relevant, verifiable findings through authorized channels.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Trace Labs applies OSINT to real missing-person investigations through nonprofit-led Search Party events and ongoing operations. Participants work from a defined case, collect relevant public information, document direct source links and context, and submit potential leads for coaching and review before Trace Labs compiles intelligence for its law-enforcement partners. The organization also publishes participant guidance, a people-focused OSINT field manual, training material, historical write-ups, and an actively maintained OSINT virtual machine, making it valuable for learning research discipline, evidence handling, and the human consequences of investigative work. Its rules are much narrower than ordinary capture-the-flag exercises. Research must remain passive and zero-touch: participants may view but may not contact, tag, follow, like, reset passwords for, attempt logins to, or otherwise interact with a missing person, their contacts, media, or law enforcement. Investigators must use only the case and channels Trace Labs authorizes, follow the current event rules rather than treating this profile as permission, and avoid speculation or vigilantism. Because the subjects are real and vulnerable, minimize collection, separate facts from inference, mask personal information in public write-ups, retain verifiable provenance, restrict case-data access, and report findings only through the designated workflow.

Strengths

  • Ethically governed, real-world people-centered OSINT practice with a public-interest mission
  • Explicit passive-reconnaissance rules and coached review emphasize verifiability and non-interference
  • Free field manual, guidance, write-ups, training, and maintained OSINT VM support skill development

Limitations

  • The program is purpose-specific to authorized missing-person cases and is not a general CTI source or independent investigative mandate
  • Work concerns real vulnerable people, so a rule breach, speculative claim, or data leak can harm subjects, families, and active investigations

Best for

  • ethical people-centered OSINT training
  • passive-reconnaissance discipline
  • verifiable lead documentation
  • investigator evidence-handling practice

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.9/5
  • Transparency 4.5/5

Ethically governed, real-world people-centered OSINT practice with a public-interest mission; principal limitation: The program is purpose-specific to authorized missing-person cases and is not a general CTI source or independent investigative mandate.

Audience

  • OSINT investigators
  • volunteer analysts
  • law-enforcement partners
  • students
  • investigation coaches

Formats

  • search-party events
  • participant guides
  • field manual
  • training videos
  • case-workflow platform
  • OSINT virtual machine

Keywords

  • osint
  • missing-persons
  • passive-reconnaissance
  • digital-investigations
  • training
  • ctf
  • evidence-handling
  • privacy
  • ethics

Link validation: Automated access restricted · checked 2026-09-07 · HTTP 403

OSINTAssessment tier A

Maltego

Maltego Technologies GmbH

Visit source : Maltego

Maltego is a commercial digital-investigation platform from Maltego Technologies GmbH, owned by Charlesbank funds since 2023. Maltego Graph represents domains, addresses, people, accounts, and other entities as linked nodes, while Transforms retrieve related data from public, commercial, or investigator-controlled sources. Its free Basic plan includes Graph Community Edition after Maltego ID registration, with usage and data limits. Graphs organize hypotheses, not facts: analysts must verify every relationship and govern personal data, provider terms, query exposure, retention, and lawful authority.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Maltego is a visual link-analysis platform for organizing entities and exploring relationships through Transforms. An analyst can begin with a domain, IP address, email, alias, telephone number, person, company, cryptocurrency address, or an internal record, then query compatible public, commercial, or custom data sources and inspect the returned entities as a graph. The platform supports infrastructure research, person-of-interest work, cyber-threat intelligence, fraud analysis, and collaborative case development. Maltego’s current free Basic plan includes Graph Community Edition after creation of a Maltego ID; the documented Community Edition limits include 10,000 entities per graph, 24 results per Transform, limited connectors, and a monthly data-credit allowance, so current plan terms should be checked before adoption. Transforms may send the selected identifier to Maltego or a third-party provider, and a visually persuasive edge may reflect name similarity, reused infrastructure, stale data, or an inferred association rather than ownership or wrongdoing. Define an authorized purpose, minimize personal data, review each provider’s terms and query behavior, protect case files and credentials, document provenance and timestamps, and corroborate decisive relationships with independent primary evidence.

Strengths

  • Combines visual entity-link analysis with a large Transform and connector ecosystem
  • Supports public, commercial, and investigator-controlled data in one graph workflow
  • Useful export, collaboration, and custom-Transform options support repeatable investigations

Limitations

  • The free plan requires registration and imposes credit, result, connector, and data-access limits that can change
  • Graph edges and aggregated records can be stale, ambiguous, or sensitive and require source-level verification and privacy governance

Best for

  • infrastructure relationship mapping
  • person-of-interest link analysis
  • cyber-threat intelligence enrichment
  • collaborative investigation visualization

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.9/5
  • Transparency 3.5/5

Combines visual entity-link analysis with a large Transform and connector ecosystem; principal limitation: The free plan requires registration and imposes credit, result, connector, and data-access limits that can change.

Audience

  • OSINT investigators
  • CTI analysts
  • fraud investigators
  • law-enforcement analysts
  • security consultants

Formats

  • desktop application
  • graph workspace
  • data connectors
  • transforms
  • technical documentation
  • training materials

Keywords

  • osint
  • link-analysis
  • graph-analysis
  • digital-investigations
  • infrastructure-reconnaissance
  • identity-research
  • data-enrichment
  • privacy
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

OSINTAssessment tier B

Bellingcat Online Investigation Toolkit

Bellingcat

Visit source : Bellingcat Online Investigation Toolkit

Bellingcat’s Online Investigation Toolkit is a free, collaborative directory for open-source researchers. It organizes tools for maps and satellite imagery, geolocation, image and video verification, social media, people, websites, corporate records, transport, conflict research, archiving, and data analysis. Individual entries can describe cost, requirements, limitations, ethical considerations, and practical guides, while Bellingcat staff review community contributions. The toolkit supports discovery and method selection; third-party tools and their outputs still require current access checks, independent verification, proportionate use, and privacy review.

Source type
Nonprofit Technical
Access
Free
Evidence use
Secondary Corroborating
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Bellingcat’s Online Investigation Toolkit is a curated catalog designed to help researchers choose tools for digital investigations. Its categories span mapping and satellite imagery, geolocation, image and video verification, social platforms, people and company research, transport, conflict monitoring, environmental investigations, web archiving, and data organization. Entries can record what a tool does, whether it is free, its difficulty and requirements, known limitations, relevant ethical considerations, and links to demonstrations or investigations; the catalog can also be downloaded by category as CSV. The current edition is maintained collaboratively by Bellingcat staff and identified volunteers, with staff checking entries before publication and contributors expected to revisit descriptions regularly. That editorial layer is valuable, but it does not make every external tool authoritative or continuously available. Platform APIs, prices, accounts, geographic coverage, and collection behavior change, while automated search or recognition can produce false matches. Use the toolkit to select a method, then validate the tool against its current first-party documentation, preserve original material and provenance, and corroborate conclusions. Public availability is not blanket consent: minimize collection, assess possible harm, protect vulnerable people, and publish only information necessary for a legitimate public-interest or authorized purpose.

Strengths

  • Broad, clearly categorized coverage of practical open-source investigation tasks
  • Entries combine tool discovery with cost, requirements, limitations, ethics, and guide context
  • Bellingcat staff review a transparent community-maintenance process

Limitations

  • Third-party tool access, pricing, platform compatibility, and collection behavior can change between reviews
  • Catalog inclusion and automated outputs do not replace independent verification, provenance, consent, or harm assessment

Best for

  • selecting tools for open-source investigations
  • image, video, and geolocation verification planning
  • web and social-media research workflows
  • investigator safety and ethics orientation

Quality dimensions

  • Authority 3.5/5
  • Originality 3/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 4.5/5

Broad, clearly categorized coverage of practical open-source investigation tasks; principal limitation: Third-party tool access, pricing, platform compatibility, and collection behavior can change between reviews.

Audience

  • open-source investigators
  • journalists
  • fact-checkers
  • human-rights researchers
  • CTI analysts

Formats

  • curated tool directory
  • tool assessments
  • investigation guides
  • csv exports
  • safety resources

Keywords

  • osint
  • digital-investigations
  • geolocation
  • media-verification
  • social-media-research
  • web-archiving
  • investigative-methods
  • privacy
  • verification

Link validation: Reachable · checked 2026-09-07 · HTTP 200

OSINTAssessment tier C

SpiderFoot

Steve Micallef / Intel 471

Visit source : SpiderFoot

SpiderFoot is an MIT-licensed OSINT automation platform for threat intelligence, digital investigations, and external attack-surface mapping. Its open-source edition supplies a web interface, command line, correlation rules, exports, and more than 200 modules that pivot among technical, identity, breach, social, registry, and threat-data sources. Intel 471 acquired SpiderFoot in 2022 and commercialized related capabilities, while the public edition’s latest tag remains version 4.0 and its default branch has not merged substantive updates since November 2023. Pin, isolate, and validate it before operational use.

Source type
Open Core
Access
Freemium
Evidence use
Mixed
Maintenance
Stale
Skill level
Intermediate, Advanced
Detailed assessment

Description

SpiderFoot automates collection and correlation across more than 200 OSINT modules from a domain, IP address, network, ASN, email address, username, person, phone number, or cryptocurrency address. The MIT-licensed open-source edition provides browser and command-line interfaces, SQLite storage, CSV, JSON, and GEXF exports, and configurable correlation rules. Its use-case selectors include passive research, footprinting, and investigation, and individual modules can query remote APIs, scrape services, resolve or transfer DNS data, scan ports, grab banners, or enumerate storage. That breadth supports attack-surface discovery and investigative triage, but also makes execution behavior and data quality highly module-dependent. Intel 471 acquired SpiderFoot in November 2022 and later described its technology as a foundation for commercial Attack Surface Protection. The public repository remains available, but its latest tagged release is 4.0 from 2022 and the default branch’s latest merged commits are from November 2023; recent pull-request activity does not equal a maintained release. Treat the edition as maintenance-stale: pin dependencies, isolate deployment, audit modules and API destinations, test outputs, and review security exposure. Use only authorized targets, prefer reviewed passive modules when non-contact is required, protect keys and sensitive scan data, and corroborate every automated relationship.

Strengths

  • Automates broad multi-source OSINT collection and correlation from many seed types
  • Open-source web, CLI, storage, visualization, and export capabilities support flexible analysis
  • Module and use-case controls can support both threat-intelligence and attack-surface workflows

Limitations

  • The open-source edition is maintenance-stale, with no tagged release since 2022 and no substantive default-branch merge since November 2023
  • Modules vary in activity, credential requirements, external dependencies, freshness, and accuracy, while correlations are not proof of ownership or maliciousness

Best for

  • external attack-surface discovery
  • multi-source OSINT enrichment
  • relationship and correlation triage
  • controlled reconnaissance labs

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 2/5
  • Practical_value 4.9/5
  • Transparency 4/5

Automates broad multi-source OSINT collection and correlation from many seed types; principal limitation: The open-source edition is maintenance-stale, with no tagged release since 2022 and no substantive default-branch merge since November 2023.

Audience

  • OSINT investigators
  • attack-surface analysts
  • CTI analysts
  • penetration testers
  • security researchers

Formats

  • software platform
  • web interface
  • command-line tool
  • github repository
  • correlation rules
  • technical documentation

Keywords

  • osint
  • reconnaissance
  • attack-surface
  • data-enrichment
  • correlation
  • cti
  • privacy
  • dual-use
  • maintenance-stale

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.