Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Adversary Emulation

2 sources

Adversary EmulationAssessment tier A

Atomic Red Team

Red Canary

Visit source : Atomic Red Team

Atomic Red Team is an open-source library of small, portable tests mapped to MITRE ATT&CK techniques. Defenders use the tests to generate controlled endpoint, cloud, container, or command-line activity, confirm telemetry, exercise analytics, and document detection gaps. Each atomic defines execution metadata and commands and may also define inputs, prerequisites, and cleanup steps. Coverage and safety vary by test; an ATT&CK mapping does not prove realistic adversary behavior, and every atomic requires review before execution because some actions can alter systems or trigger security controls.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Atomic Red Team, maintained by Red Canary and community contributors, is an open-source catalog of small security tests mapped to MITRE ATT&CK techniques. Individual atomics describe supported platforms, inputs, prerequisites, execution commands, and, where available, cleanup actions. Detection engineers and purple teams commonly select a behavior, run the corresponding test on an authorized lab or representative endpoint, confirm that expected telemetry reaches the SIEM or EDR, evaluate an analytic, and record gaps for remediation. The library pairs naturally with ATT&CK for behavioral context, Sigma or vendor rule repositories for candidate detections, and orchestration platforms such as Caldera when a team later needs chained scenarios. Its strength is repeatability at the level of one technique or observable action, not realism across a complete intrusion. Mappings, commands, prerequisites, and cleanup quality vary between contributions, and successful execution does not prove that a control detected or prevented the behavior. Every test is dual-use: review the source, scope affected systems, obtain authorization, protect credentials, monitor side effects, and restore the environment before treating results as evidence.

Strengths

  • Portable tests with explicit ATT&CK mappings and repeatable inputs
  • Useful for validating telemetry and individual analytic assumptions
  • Large community-maintained library with transparent test definitions

Limitations

  • Atomic actions do not reproduce full intrusion context or chained tradecraft
  • Tests are dual-use and may disrupt systems without review, isolation, and authorization

Best for

  • detection validation
  • purple-team exercises
  • telemetry verification
  • analyst training labs

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.6/5
  • Transparency 5/5

Portable tests with explicit ATT&CK mappings and repeatable inputs; principal limitation: Atomic actions do not reproduce full intrusion context or chained tradecraft.

Audience

  • detection engineers
  • purple teams
  • SOC analysts
  • security testers

Formats

  • github repository
  • yaml tests
  • command examples
  • wiki documentation

Keywords

  • adversary-emulation
  • mitre-attack
  • detection-validation
  • purple-team
  • endpoint-telemetry
  • security-testing
  • dual-use
  • cloud-security
  • container-security

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Adversary EmulationAssessment tier A

Apache Caldera

Apache Software Foundation

Visit source : Apache Caldera

Apache Caldera is an open-source platform for automated adversary emulation, security assessment, and red-versus-blue research. Operators define adversary profiles and abilities, deploy agents, execute ATT&CK-aligned operations, and collect results through an extensible plugin architecture. It supports chained exercises that can test sensors, analytics, alerting, and response systems more realistically than isolated commands. Caldera is an Apache Incubator project, and safe use requires a controlled network, explicit authorization, reviewed abilities, credential protection, and careful cleanup; it is a platform, not a guarantee of representative threat emulation.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Advanced
Detailed assessment

Description

Apache Caldera (incubating), originally developed by MITRE, is an open-source adversary-emulation and security-assessment project in the Apache Software Foundation Incubator. Its server, agents, plugins, abilities, adversary profiles, planners, and fact model let authorized teams assemble multi-step operations, execute ATT&CK-aligned behaviors, collect results, and adapt later actions to discovered information. Purple teams can use it to test whether telemetry survives from endpoint to SIEM, whether correlated analytics detect a sequence, and whether analysts follow investigation and response procedures. Atomic Red Team is better for isolated checks; Caldera becomes useful when scenarios need sequencing, state, automated collection, or repeatable campaign execution. ATT&CK and D3FEND can supply behavioral and defensive context, while detection repositories provide analytics to evaluate. The platform does not make an operation representative merely because abilities carry ATT&CK mappings, and automated results do not establish control effectiveness without reviewing logs and alerts. Agents, credentials, remote commands, and plugins are materially dual-use. Deploy only within an explicitly authorized scope, inspect every ability, segment infrastructure, protect keys, constrain privileges, capture evidence, and plan cleanup before execution.

Strengths

  • Automates multi-step adversary-emulation operations and evidence collection
  • Extensible plugin, agent, and ability model supports custom scenarios
  • Useful for testing end-to-end detection and response workflows

Limitations

  • Deployment and scenario design require substantial operational expertise
  • Dual-use agents and abilities create material safety and authorization risks

Best for

  • adversary-emulation programs
  • purple-team campaigns
  • control validation
  • cyber-range research

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.6/5
  • Transparency 5/5

Automates multi-step adversary-emulation operations and evidence collection; principal limitation: Deployment and scenario design require substantial operational expertise.

Audience

  • red teams
  • purple teams
  • detection engineers
  • security researchers

Formats

  • software platform
  • documentation
  • github repository
  • plugins

Keywords

  • adversary-emulation
  • automated-testing
  • mitre-attack
  • purple-team
  • detection-validation
  • red-team
  • agents
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

AI Security

1 source

AI SecurityAssessment tier A

NIST AI Risk Management Framework

National Institute of Standards and Technology

Visit source : NIST AI Risk Management Framework

The NIST AI Risk Management Framework is a voluntary, technology-neutral framework for managing risks to people, organizations, and society across the AI lifecycle. AI RMF 1.0 organizes work around Govern, Map, Measure, and Manage, with a Playbook, crosswalks, resource center, and a generative-AI profile extending implementation guidance. It is strong for governance and risk-program design, but it is not a technical attack catalog, certification scheme, or step-by-step penetration-testing guide. Organizations must tailor outcomes, metrics, and controls to context.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The NIST AI Risk Management Framework is a voluntary, technology-neutral framework for managing risks to people, organizations, and society across the AI lifecycle. AI RMF 1.0 organizes work around Govern, Map, Measure, and Manage, with a Playbook, crosswalks, resource center, and a generative-AI profile extending implementation guidance. It is strong for governance and risk-program design, but it is not a technical attack catalog, certification scheme, or step-by-step penetration-testing guide. Organizations must tailor outcomes, metrics, and controls to context. Governance, engineering, assurance, legal, and product teams can use the functions to assign ownership, document context, choose measurement methods, and track treatment decisions. The Playbook supplies optional actions rather than mandatory controls; profiles and crosswalks help connect the framework to sector or technology concerns. All materials are public, but readers should verify the current revision and profile version. Pair the framework with ATLAS or OWASP threat material and empirical evaluations, then retain assumptions, evidence, residual risk, and decision authority instead of treating completion as certification.

Strengths

  • Offers a lifecycle-wide and technology-neutral structure for trustworthy AI risk management.
  • Includes implementation aids such as a Playbook, crosswalks, profiles, and community resources.
  • Was developed through an open, consensus-oriented public process.

Limitations

  • High-level outcomes require substantial tailoring before they become testable controls.
  • It does not supply exploit procedures or comprehensive technical security requirements, and AI RMF 1.0 is under revision, so users should verify the current release status.

Best for

  • AI governance programs
  • risk assessments
  • control framework alignment
  • executive and technical coordination

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Offers a lifecycle-wide and technology-neutral structure for trustworthy AI risk management; principal limitation: High-level outcomes require substantial tailoring before they become testable controls.

Audience

  • risk managers
  • security architects
  • ai program owners
  • policy teams

Formats

  • framework
  • playbook
  • profiles
  • crosswalks
  • implementation resources

Keywords

  • ai-security
  • ai-risk-management
  • ai-governance
  • trustworthy-ai
  • risk-framework
  • generative-ai
  • control-mapping

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Framework

3 sources

FrameworkAssessment tier A

ASD Essential Eight

Australian Signals Directorate

Visit source : ASD Essential Eight

The Australian Signals Directorate’s Essential Eight is a prioritized baseline of eight mitigation strategies for internet-connected enterprise IT, covering application control, patching, macro restrictions, application hardening, administrative privileges, operating-system patching, multifactor authentication, and backups. Its maturity model defines levels zero through three based on increasing adversary tradecraft and recommends balanced implementation across all eight strategies. It is practical for baseline planning and assessment, but it is not a complete security program and was not designed specifically for operational technology or enterprise mobility environments.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The Australian Signals Directorate’s Essential Eight is a prioritized baseline of eight mitigation strategies for internet-connected enterprise IT, covering application control, patching, macro restrictions, application hardening, administrative privileges, operating-system patching, multifactor authentication, and backups. Its maturity model defines levels zero through three based on increasing adversary tradecraft and recommends balanced implementation across all eight strategies. Organizations can assess each strategy against the maturity criteria, retain configuration and test evidence, identify the lowest implemented level, and plan improvements as a coordinated package. The model is useful for communicating concrete baseline gaps to technical owners and leadership. Pair it with the broader ASD mitigation strategies, a risk framework, and platform-specific hardening guidance; do not assume that a nominal maturity level covers cloud services, custom applications, third parties, or all threat paths. It is practical for baseline planning and assessment, but it is not a complete security program and was not designed specifically for operational technology or enterprise mobility environments.

Strengths

  • Concise, threat-informed baseline of high-impact defensive practices
  • Maturity levels support staged implementation and assessment against stronger adversary tradecraft
  • Official guidance includes detailed requirements and mappings to Australia’s Information Security Manual

Limitations

  • Eight strategies do not cover the full governance, architecture, detection, and response lifecycle
  • The model targets enterprise IT and may require different controls for operational technology and mobility

Best for

  • Australian government and business baselines
  • Cyber-hygiene improvement roadmaps
  • Maturity assessments
  • Prioritizing endpoint and identity defenses

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 5/5

Concise, threat-informed baseline of high-impact defensive practices; principal limitation: Eight strategies do not cover the full governance, architecture, detection, and response lifecycle.

Audience

  • security managers
  • system administrators
  • Australian organizations
  • assessors
  • risk owners

Formats

  • security baseline
  • maturity model
  • implementation guidance
  • pdf publications
  • control mappings

Keywords

  • government
  • security-controls
  • cyber-hygiene
  • maturity-model
  • patch-management
  • identity-security
  • backup-recovery
  • australia

Link validation: Reachable · checked 2026-09-07 · HTTP 200

FrameworkAssessment tier A

NCSC Cyber Assessment Framework

UK National Cyber Security Centre

Visit source : NCSC Cyber Assessment Framework

The NCSC Cyber Assessment Framework provides an outcome-focused method for assessing cyber risk to essential functions. Its four objectives cover managing security risk, protecting against attacks, detecting events, and minimizing incident impact; fourteen principles are evaluated through contributing outcomes and Indicators of Good Practice. It supports self-assessment and regulatory or independent assessment while allowing sector-specific profiles and target levels. The indicators inform expert judgment rather than mechanical scoring, and the NCSC explicitly leaves proportionality and regulatory targets to the relevant oversight body and organizational context.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

The NCSC Cyber Assessment Framework provides an outcome-focused method for assessing cyber risk to essential functions. Its four objectives cover managing security risk, protecting against attacks, detecting events, and minimizing incident impact; fourteen principles are evaluated through contributing outcomes and Indicators of Good Practice. It supports self-assessment and regulatory or independent assessment while allowing sector-specific profiles and target levels. Assessors should begin with the essential function and its dependencies, collect technical and governance evidence for each contributing outcome, and document why the evidence supports or fails to support the target. Sector profiles or regulator expectations determine which outcomes receive emphasis. The framework works well beside NIST CSF for program language and detailed control catalogs for implementation, but those cross-references do not replace professional judgment. The indicators inform expert judgment rather than mechanical scoring, and the NCSC explicitly leaves proportionality and regulatory targets to the relevant oversight body and organizational context.

Strengths

  • Systematic outcome-based assessment model focused on essential functions and resilience
  • Indicators of Good Practice make broad principles reviewable without reducing them to a checklist
  • Supports self-assessment, external assessment, and sector-specific profiles

Limitations

  • Assessment conclusions require expert judgment and evidence beyond the indicators
  • Regulatory targets and proportionality must be defined by the applicable authority, not inferred from the CAF

Best for

  • Critical-service resilience assessment
  • Regulatory assurance programs
  • Current-state and target-state reviews
  • Governance and control-gap analysis

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 5/5

Systematic outcome-based assessment model focused on essential functions and resilience; principal limitation: Assessment conclusions require expert judgment and evidence beyond the indicators.

Audience

  • critical-infrastructure operators
  • regulators
  • assessors
  • security leaders
  • risk managers

Formats

  • assessment framework
  • web guidance
  • indicator tables
  • consolidated guidance
  • changelog

Keywords

  • government
  • security-framework
  • cyber-resilience
  • critical-infrastructure
  • risk-assessment
  • security-controls
  • assurance
  • united-kingdom

Link validation: Reachable · checked 2026-09-07 · HTTP 200

FrameworkAssessment tier A

CIS Critical Security Controls

Center for Internet Security

Visit source : CIS Critical Security Controls

The CIS Critical Security Controls are 18 prioritized control areas supported by specific Safeguards and three Implementation Groups. The current v8 series emphasizes practical, measurable actions across enterprise assets, software, data, identity, logging, vulnerability management, incident response, application security, and service providers. Implementation Group 1 supplies an accessible essential-cyber-hygiene baseline, while higher groups add depth for greater risk and resources. The Controls simplify prioritization but still require asset context, documented exceptions, effectiveness testing, and mappings to any legal or sector-specific requirements.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The CIS Critical Security Controls are 18 prioritized control areas supported by specific Safeguards and three Implementation Groups. The current v8 series emphasizes practical, measurable actions across enterprise assets, software, data, identity, logging, vulnerability management, incident response, application security, and service providers. Implementation Group 1 supplies an accessible essential-cyber-hygiene baseline, while higher groups add depth for greater risk and resources. A team can inventory applicable Safeguards by Implementation Group, assign owners, document implementation evidence, and test whether the intended risk reduction occurs. The published mappings help relate Safeguards to NIST and other frameworks, but mapped statements may differ in scope and assurance. Use the Controls to establish a prioritized operating baseline and communicate progress, then add threat-specific, privacy, resilience, and regulatory requirements where needed. The Controls simplify prioritization but still require asset context, documented exceptions, effectiveness testing, and mappings to any legal or sector-specific requirements.

Strengths

  • Prescriptive and prioritized safeguards that are easier to operationalize than broad outcome frameworks
  • Implementation Groups provide a practical maturity and resource-sensitive adoption path
  • Mappings connect safeguards to NIST, regulatory, and industry frameworks

Limitations

  • A generic safeguard list cannot replace threat modeling or organization-specific risk decisions
  • Some downloadable resources require registration, and implementation quality still needs independent evidence

Best for

  • Building a defensive baseline
  • Small and medium organization roadmaps
  • Security control prioritization
  • Operational control assessments

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.9/5
  • Transparency 4.5/5

Prescriptive and prioritized safeguards that are easier to operationalize than broad outcome frameworks; principal limitation: A generic safeguard list cannot replace threat modeling or organization-specific risk decisions.

Audience

  • security managers
  • system administrators
  • small and medium organizations
  • risk teams
  • auditors

Formats

  • control framework
  • safeguard lists
  • implementation groups
  • spreadsheets
  • mappings
  • assessment guidance

Keywords

  • standards
  • security-controls
  • cyber-hygiene
  • risk-management
  • security-program
  • implementation-guidance
  • control-mapping

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Threat Informed Defense

2 sources

Threat Informed DefenseAssessment tier A

MITRE D3FEND

MITRE

Visit source : MITRE D3FEND

MITRE D3FEND is a knowledge graph and ontology of cybersecurity countermeasure techniques. It defines defensive concepts, digital artifacts, and relationships that can connect engineering mechanisms to offensive behaviors, including ATT&CK techniques. The site exposes a matrix, referenced knowledge-base entries, downloadable ontology data, spreadsheets, papers, and extraction tools. D3FEND is valuable for precise defensive vocabulary and architecture analysis. It does not recommend, prioritize, or validate the effectiveness of particular countermeasures, so mappings are hypotheses and design context rather than proof that a control blocks an attack.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

MITRE D3FEND is a knowledge graph and ontology of cybersecurity countermeasure techniques. It defines defensive concepts, digital artifacts, and relationships that can connect engineering mechanisms to offensive behaviors, including ATT&CK techniques. The site exposes a matrix, referenced knowledge-base entries, downloadable ontology data, spreadsheets, papers, and extraction tools. D3FEND is valuable for precise defensive vocabulary and architecture analysis. Engineers can start from a relevant ATT&CK behavior or digital artifact, inspect candidate countermeasure relationships, and translate the vocabulary into design questions, telemetry needs, or validation tests. The ontology data supports graph analysis and tooling where teams need machine-readable relationships. Cross-use it with ATT&CK procedure evidence and a control catalog to connect attacker behavior, concrete engineering mechanisms, and governance requirements without collapsing those layers. It does not recommend, prioritize, or validate the effectiveness of particular countermeasures, so mappings are hypotheses and design context rather than proof that a control blocks an attack.

Strengths

  • Semantically structured vocabulary for describing how defensive technologies operate
  • Links defensive techniques, digital artifacts, and offensive behaviors in a queryable knowledge graph
  • Provides downloadable ontology formats for research and automation

Limitations

  • It neither ranks countermeasures nor claims that mapped techniques are effective in a specific environment
  • Ontology terminology and relationships can require significant security-engineering expertise

Best for

  • Defensive architecture analysis
  • Control-capability modeling
  • Threat-to-countermeasure research
  • Security ontology and knowledge-graph projects

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 5/5
  • Transparency 4.5/5

Semantically structured vocabulary for describing how defensive technologies operate; principal limitation: It neither ranks countermeasures nor claims that mapped techniques are effective in a specific environment.

Audience

  • security architects
  • detection engineers
  • security researchers
  • technical executives
  • knowledge engineers

Formats

  • knowledge graph
  • ontology
  • matrix
  • json-ld data
  • rdf data
  • research paper
  • tools

Keywords

  • threat-informed-defense
  • defensive-techniques
  • security-architecture
  • knowledge-graph
  • ontology
  • security-controls
  • mitre-d3fend
  • mitre-attack

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Threat Informed DefenseAssessment tier A

Center for Threat-Informed Defense

Center for Threat-Informed Defense, operated by MITRE

Visit source : Center for Threat-Informed Defense

The Center for Threat-Informed Defense is a collaborative research and development consortium operated by MITRE with participation from government and industry members. It publishes openly available projects that make threat-informed defense more actionable, including adversary-emulation resources, ATT&CK mappings, Attack Flow, sensor and security-stack mappings, and analytic methodologies. Its outputs can bridge intelligence, defensive engineering, and validation. Projects are scoped research deliverables rather than a continuously comprehensive knowledge base, and users should examine each project’s assumptions, versions, contributors, and validation before operational adoption.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Center for Threat-Informed Defense is a collaborative research and development consortium operated by MITRE with participation from government and industry members. It publishes openly available projects that make threat-informed defense more actionable, including adversary-emulation resources, ATT&CK mappings, Attack Flow, sensor and security-stack mappings, and analytic methodologies. Its outputs can bridge intelligence, defensive engineering, and validation. Teams can use an emulation plan to derive authorized tests, Attack Flow to represent multi-step behavior, or mapping projects to investigate what sensors and controls could support coverage. Read each project’s documentation, data model, license, release history, and cited evidence before integrating it; projects differ in purpose and maintenance. Cross-reference ATT&CK for behavior definitions and validate proposed detections or controls against local telemetry rather than treating a mapping as tested coverage. Projects are scoped research deliverables rather than a continuously comprehensive knowledge base, and users should examine each project’s assumptions, versions, contributors, and validation before operational adoption.

Strengths

  • Produces practical, public research artifacts built through cross-industry collaboration
  • Extends ATT&CK into workflows, mappings, emulation, and defensive engineering use cases
  • Frequently publishes machine-readable data, code, methods, and documentation

Limitations

  • Individual projects have bounded scopes and may not cover every platform, vendor, or threat
  • Mappings and research outputs require local validation before they are treated as control or detection evidence

Best for

  • Threat-informed defense program design
  • Adversary-emulation planning
  • ATT&CK-based engineering projects
  • Reusable defensive research artifacts

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.9/5
  • Transparency 4.5/5

Produces practical, public research artifacts built through cross-industry collaboration; principal limitation: Individual projects have bounded scopes and may not cover every platform, vendor, or threat.

Audience

  • detection engineers
  • cti analysts
  • purple teams
  • security architects
  • security researchers

Formats

  • research projects
  • technical reports
  • datasets
  • open-source tools
  • methodologies
  • mappings

Keywords

  • threat-informed-defense
  • mitre-attack
  • adversary-emulation
  • detection-engineering
  • purple-team
  • security-research
  • open-source
  • control-mapping

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.