Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

CTI

6 sources

CTIAssessment tier A

OASIS Open CTI Documentation

OASIS Open Cyber Threat Intelligence Technical Committee

Visit source : OASIS Open CTI Documentation

The OASIS Open CTI documentation is the official learning and reference entry point for STIX and TAXII. STIX 2.1 defines JSON objects, relationships, observables, and patterning for representing cyber threat intelligence; TAXII 2.1 defines HTTPS APIs for discovering and exchanging collections of intelligence. The site provides specifications, introductions, examples, walkthroughs, schemas, and validator links. It is essential for interoperable CTI engineering but is not an intelligence feed or analytic methodology, and valid syntax does not ensure accurate sourcing, confidence, handling, or useful intelligence content.

Source type
Standards Body
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The OASIS Open CTI documentation is the official learning and reference entry point for STIX and TAXII. STIX 2.1 defines JSON objects, relationships, observables, and patterning for representing cyber threat intelligence; TAXII 2.1 defines HTTPS APIs for discovering and exchanging collections of intelligence. The site provides specifications, introductions, examples, walkthroughs, schemas, and validator links. Engineers should use the normative specifications when implementing producers or consumers, the examples for orientation, and schemas or validators to catch structural errors. Model provenance, confidence, markings, identities, relationships, and time explicitly so downstream users can judge intelligence rather than receive disconnected indicators. Test exchange behavior between actual platforms, including pagination, filtering, versioning, and collection permissions. MISP and OpenCTI can operationalize parts of this ecosystem, but their extensions and import decisions still require review. It is essential for interoperable CTI engineering but is not an intelligence feed or analytic methodology, and valid syntax does not ensure accurate sourcing, confidence, handling, or useful intelligence content.

Strengths

  • Canonical documentation for widely implemented CTI representation and transport standards
  • Combines normative specifications with examples, walkthroughs, schemas, and validators
  • Supports interoperable, machine-readable intelligence exchange across tools and organizations

Limitations

  • Standards compliance does not guarantee intelligence quality, provenance, relevance, or safe sharing
  • The full object and relationship models can be complex for first-time implementers

Best for

  • STIX 2.1 data modeling
  • TAXII 2.1 client and server implementation
  • CTI platform integration
  • Validating machine-readable intelligence

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.9/5
  • Transparency 5/5

Canonical documentation for widely implemented CTI representation and transport standards; principal limitation: Standards compliance does not guarantee intelligence quality, provenance, relevance, or safe sharing.

Audience

  • cti engineers
  • security developers
  • cti analysts
  • platform architects
  • integration teams

Formats

  • standards
  • technical documentation
  • json examples
  • schemas
  • walkthroughs
  • validator tools

Keywords

  • cti
  • stix
  • taxii
  • standards
  • threat-sharing
  • machine-readable-data
  • api
  • interoperability

Link validation: Reachable · checked 2026-09-07 · HTTP 200

CTIAssessment tier A

MISP

MISP Project

Visit source : MISP

MISP is an open-source platform and data-model ecosystem for collecting, correlating, analyzing, and sharing threat intelligence within organizations and trust communities. It supports granular distribution rules, taxonomies, galaxies, sightings, synchronization, REST automation, and exports to formats including STIX and network-detection rules. MISP is especially useful for collaborative indicator and event workflows while retaining context and handling controls. The software is not itself a guarantee of good intelligence: value depends on source quality, analyst curation, taxonomy discipline, access governance, and lawful sharing of sensitive data.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

MISP is an open-source platform and data-model ecosystem for collecting, correlating, analyzing, and sharing threat intelligence within organizations and trust communities. It supports granular distribution rules, taxonomies, galaxies, sightings, synchronization, REST automation, and exports to formats including STIX and network-detection rules. MISP is especially useful for collaborative indicator and event workflows while retaining context and handling controls. Analysts can organize observations into events and objects, record source and confidence context, apply sharing markings, correlate related attributes, and publish only to authorized communities. Automation through the REST API can enrich or distribute approved data, while sightings help distinguish local observations from inherited assertions. Define taxonomy, retention, review, and distribution policies before connecting feeds or peers; otherwise duplicates and low-confidence indicators can propagate quickly. STIX exports support interoperability but may not preserve every MISP-specific semantic. The software is not itself a guarantee of good intelligence: value depends on source quality, analyst curation, taxonomy discipline, access governance, and lawful sharing of sensitive data.

Strengths

  • Mature open-source platform for structured intelligence sharing, correlation, and collaboration
  • Flexible sharing groups, taxonomies, galaxies, sightings, APIs, and import-export formats
  • Large practitioner community and reusable open data-model resources

Limitations

  • Deployment, data governance, deduplication, and taxonomy management require sustained expertise
  • Imported indicators can be stale, false-positive, sensitive, or legally restricted unless curated

Best for

  • Organizational threat-intelligence management
  • Trust-group information sharing
  • Indicator correlation and enrichment
  • Automating intelligence-to-detection workflows

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 5/5

Mature open-source platform for structured intelligence sharing, correlation, and collaboration; principal limitation: Deployment, data governance, deduplication, and taxonomy management require sustained expertise.

Audience

  • cti analysts
  • incident responders
  • security operations teams
  • malware analysts
  • cti platform administrators

Formats

  • open-source software
  • technical documentation
  • rest api
  • taxonomies
  • galaxies
  • training materials

Keywords

  • cti
  • threat-sharing
  • threat-intelligence-platform
  • indicators-of-compromise
  • correlation
  • taxonomies
  • automation
  • open-source

Link validation: Reachable · checked 2026-09-07 · HTTP 200

CTIAssessment tier A

OpenCTI

Filigran

Visit source : OpenCTI

OpenCTI is an open-source platform for structuring, storing, visualizing, and operationalizing technical and non-technical threat intelligence as a knowledge graph. Its data model is based on STIX 2.1, with extensions, connectors, feeds, streams, TAXII collections, enrichment, dashboards, and role-based administration. It is strong for linking actors, campaigns, malware, vulnerabilities, observables, reports, and organizational context. OpenCTI is infrastructure rather than an authoritative feed: accuracy depends on connector behavior, source licensing, deduplication, confidence handling, analyst review, and secure deployment of a complex service stack.

Source type
Open Core
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

OpenCTI is an open-source platform for structuring, storing, visualizing, and operationalizing technical and non-technical threat intelligence as a knowledge graph. Its data model is based on STIX 2.1, with extensions, connectors, feeds, streams, TAXII collections, enrichment, dashboards, and role-based administration. It is strong for linking actors, campaigns, malware, vulnerabilities, observables, reports, and organizational context. A CTI team can ingest selected sources through connectors, preserve reports and relationships, reconcile entities, enrich observables, and publish curated views or collections to consumers. Design source priorities, confidence rules, marking policies, identity resolution, and retention before scaling ingestion; a visually connected graph can still contain conflicting or weak assertions. Review connector permissions and outbound data paths, and monitor imports for schema or licensing changes. Cross-check important relationships against their source reports and use STIX/TAXII documentation when exchanging data. OpenCTI is infrastructure rather than an authoritative feed: accuracy depends on connector behavior, source licensing, deduplication, confidence handling, analyst review, and secure deployment of a complex service stack.

Strengths

  • Knowledge-graph model supports relationships across strategic, operational, and technical intelligence
  • STIX 2.1-based imports, exports, connectors, streams, and TAXII enable broad integration
  • Combines analyst workflows, dashboards, enrichment, sharing, and access controls

Limitations

  • The multi-service platform and connector ecosystem require operational, security, and data-governance expertise
  • Source ingestion does not guarantee accuracy, lawful use, deduplication, or analytic confidence

Best for

  • Building an organizational CTI knowledge base
  • Connecting reports, observables, actors, and vulnerabilities
  • Integrating intelligence with SIEM and response systems
  • Collaborative intelligence analysis

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 4/5

Knowledge-graph model supports relationships across strategic, operational, and technical intelligence; principal limitation: The multi-service platform and connector ecosystem require operational, security, and data-governance expertise.

Audience

  • cti analysts
  • cti engineers
  • security operations teams
  • threat hunters
  • platform administrators

Formats

  • open-source software
  • technical documentation
  • knowledge graph
  • graphql api
  • stix data
  • connectors

Keywords

  • cti
  • threat-intelligence-platform
  • knowledge-graph
  • stix
  • taxii
  • threat-sharing
  • automation
  • open-source

Link validation: Reachable · checked 2026-09-07 · HTTP 200

CTIAssessment tier B

ThreatFox

abuse.ch and Spamhaus

Visit source : ThreatFox

ThreatFox is a community platform operated by abuse.ch and Spamhaus for sharing indicators associated with malware and botnet activity. Analysts can search submissions and consume recent indicators through downloadable exports and an API, with malware-family, confidence, reporter, and time context where available. It is useful for enrichment, hunting, research, and feed prototyping because the data is openly accessible and operationally current. Indicators are observations, not verdicts: domains, IP addresses, and URLs can change ownership or host mixed content, so age, confidence, context, and local evidence must be checked before blocking.

Source type
Independent Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

ThreatFox is a community platform operated by abuse.ch and Spamhaus for sharing indicators associated with malware and botnet activity. Analysts can search submissions and consume recent indicators through downloadable exports and an API, with malware-family, confidence, reporter, and time context where available. It is useful for enrichment, hunting, research, and feed prototyping because the data is openly accessible and operationally current. Defenders can pivot from a suspicious observable to associated malware labels and reports, or ingest recent records into a staging pipeline that enforces age, type, confidence, and allow-list rules. Preserve first-seen and last-seen context, validate hits against DNS, proxy, endpoint, and case evidence, and expire indicators according to type and observed persistence. Compare malware naming with vendor research because family labels and aliases are not universally consistent. Indicators are observations, not verdicts: domains, IP addresses, and URLs can change ownership or host mixed content, so age, confidence, context, and local evidence must be checked before blocking.

Strengths

  • Open, machine-readable stream of malware-associated indicators with useful context
  • Community submissions are searchable and available through API and export formats
  • Integrates readily with CTI platforms and defensive workflows

Limitations

  • Indicator quality, scope, and confidence vary with submissions and available evidence
  • Infrastructure indicators decay and can cause collateral damage if blocked without validation

Best for

  • IOC enrichment and pivoting
  • Threat hunting
  • Malware infrastructure research
  • Testing CTI ingestion workflows

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 4/5

Open, machine-readable stream of malware-associated indicators with useful context; principal limitation: Indicator quality, scope, and confidence vary with submissions and available evidence.

Audience

  • cti analysts
  • threat hunters
  • security operations teams
  • malware analysts
  • security engineers

Formats

  • ioc database
  • api
  • csv feeds
  • json data
  • search interface

Keywords

  • cti
  • indicators-of-compromise
  • malware
  • threat-feeds
  • threat-hunting
  • api
  • machine-readable-data
  • community

Link validation: Reachable · checked 2026-09-07 · HTTP 200

CTIAssessment tier B

URLhaus

abuse.ch and Spamhaus

Visit source : URLhaus

URLhaus is operated by abuse.ch and Spamhaus to collect and share URLs used to distribute malware. Its searchable database, API, downloads, and specialized feeds support incident enrichment, malware-campaign tracking, takedown coordination, and defensive automation. Records can connect URLs with payload hashes, malware families, hosting details, status, and submission history. The project’s scope is malicious payload distribution rather than every form of phishing or harmful web activity. URLs are dangerous and time-sensitive; never open them on production systems, and distinguish purpose-built IOC datasets from broader feeds that URLhaus says are not blocklists.

Source type
Independent Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

URLhaus is operated by abuse.ch and Spamhaus to collect and share URLs used to distribute malware. Its searchable database, API, downloads, and specialized feeds support incident enrichment, malware-campaign tracking, takedown coordination, and defensive automation. Records can connect URLs with payload hashes, malware families, hosting details, status, and submission history. Responders can query a URL observed in proxy or email telemetry, pivot to delivered payload hashes, compare submission timing, and search endpoint evidence for related execution. Feed consumers should choose the dataset designed for their control, normalize URL syntax carefully, enforce expiry and exception handling, and validate local matches before containment. Investigate content only in an isolated analysis environment with appropriate authorization; an inactive status does not make historical payloads safe. The project’s scope is malicious payload distribution rather than every form of phishing or harmful web activity. URLs are dangerous and time-sensitive; never open them on production systems, and distinguish purpose-built IOC datasets from broader feeds that URLhaus says are not blocklists.

Strengths

  • Focused operational dataset for malware-distribution URLs and associated payload context
  • Offers APIs and downloadable datasets suited to automation and research
  • Supports abuse reporting and disruption as well as defensive consumption

Limitations

  • It does not aim to catalog all phishing, fraud, or malicious web infrastructure
  • URLs can be hazardous, short-lived, or hosted on shared infrastructure and require controlled handling

Best for

  • Malware-delivery investigation
  • IOC enrichment
  • Network hunting and retrospective analysis
  • Researching malicious hosting infrastructure

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 4/5

Focused operational dataset for malware-distribution URLs and associated payload context; principal limitation: It does not aim to catalog all phishing, fraud, or malicious web infrastructure.

Audience

  • cti analysts
  • malware analysts
  • network defenders
  • incident responders
  • abuse teams

Formats

  • malicious-url database
  • api
  • csv feeds
  • json feeds
  • payload metadata

Keywords

  • cti
  • malware-distribution
  • malicious-urls
  • indicators-of-compromise
  • threat-feeds
  • network-security
  • api
  • abuse-reporting
  • community

Link validation: Reachable · checked 2026-09-07 · HTTP 200

CTIAssessment tier B

Google Threat Intelligence

Google Cloud Security

Visit source : Google Threat Intelligence

Google Threat Intelligence is a commercial intelligence platform combining Google security telemetry, Mandiant’s incident-response and analyst research, and VirusTotal’s contributed files, URLs, and community context. It supports indicator enrichment, actor and campaign research, malware analysis, hunting, collections, graph pivoting, APIs, and intelligence-assisted prioritization. The combination can provide unusually broad context, but detailed capabilities and API access depend on paid subscription tiers. Coverage and verdicts remain proprietary and visibility-biased; AI-generated summaries, attribution, prevalence, and unified scores should be checked against underlying evidence and independent sources.

Source type
Commercial Technical
Access
Paid
Evidence use
Mixed
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Google Threat Intelligence is a commercial intelligence platform combining Google security telemetry, Mandiant’s incident-response and analyst research, and VirusTotal’s contributed files, URLs, and community context. It supports indicator enrichment, actor and campaign research, malware analysis, hunting, collections, graph pivoting, APIs, and intelligence-assisted prioritization. Analysts can begin with an observable or report, traverse related files, infrastructure, actors, and campaigns, and preserve cited relationships as leads for local searches. Use underlying detections, timestamps, submissions, and report evidence to distinguish direct observations from automated association or narrative assessment. Before uploading files, URLs, or private indicators, confirm organizational data-handling policy because submitted material may be shared or retained according to service terms. The combination can provide unusually broad context, but detailed capabilities and API access depend on paid subscription tiers. Coverage and verdicts remain proprietary and visibility-biased; AI-generated summaries, attribution, prevalence, and unified scores should be checked against underlying evidence and independent sources.

Strengths

  • Combines frontline Mandiant research, VirusTotal context, and large-scale Google telemetry
  • Supports technical pivoting, actor research, campaign context, and operational integrations
  • Connects strategic intelligence with indicator and malware investigation workflows

Limitations

  • Most operational capabilities are commercial, with pricing and limits tied to subscription tiers
  • Proprietary visibility, verdict logic, attribution, and AI summaries require independent corroboration

Best for

  • Enterprise CTI programs
  • Indicator and malware enrichment
  • Threat-actor and campaign research
  • Intelligence-led hunting and prioritization

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 3.5/5

Combines frontline Mandiant research, VirusTotal context, and large-scale Google telemetry; principal limitation: Most operational capabilities are commercial, with pricing and limits tied to subscription tiers.

Audience

  • cti analysts
  • incident responders
  • threat hunters
  • security operations teams
  • malware analysts

Formats

  • commercial platform
  • threat reports
  • indicator data
  • malware analysis
  • api
  • knowledge graph

Keywords

  • cti
  • threat-intelligence-platform
  • malware-analysis
  • indicators-of-compromise
  • threat-hunting
  • incident-response
  • vendor-research
  • commercial

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Threat Research

2 sources

Threat ResearchAssessment tier A

Cisco Talos Intelligence

Cisco Talos

Visit source : Cisco Talos Intelligence

Cisco Talos publishes threat intelligence, malware and campaign research, vulnerability disclosures, reputation data, and defensive content informed by Cisco telemetry and open-source projects such as Snort and ClamAV. Its vulnerability reports document coordinated disclosures, while research articles connect attacker behavior to technical artifacts and protections. The portal is useful for analysts who need both narrative context and operational indicators. Cisco’s product ecosystem influences visibility and remediation framing, so global prevalence, attribution, and product-protection claims should be corroborated with vendor advisories and independent research.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Cisco Talos publishes threat intelligence, malware and campaign research, vulnerability disclosures, reputation data, and defensive content informed by Cisco telemetry and open-source projects such as Snort and ClamAV. Its vulnerability reports document coordinated disclosures, while research articles connect attacker behavior to technical artifacts and protections. The portal is useful for analysts who need both narrative context and operational indicators. Incident responders can use report timelines, infrastructure, samples, and behaviors to develop scoped searches; vulnerability researchers can trace Talos disclosure identifiers to affected products and vendor fixes. Where a post references Snort or ClamAV coverage, inspect the corresponding rule or signature and test it against representative traffic or files instead of inferring complete protection. Record publication date and indicator context, then corroborate actor naming and campaign scope across independent reporting. Cisco’s product ecosystem influences visibility and remediation framing, so global prevalence, attribution, and product-protection claims should be corroborated with vendor advisories and independent research.

Strengths

  • Original malware, campaign, and coordinated vulnerability research
  • Connects research findings with reputation data and open-source detection ecosystems
  • Provides both high-level reporting and detailed technical advisories

Limitations

  • Telemetry coverage and defensive recommendations reflect Cisco’s products and customer visibility
  • Attribution, prevalence, and protection claims require independent corroboration

Best for

  • Threat and malware investigation
  • Vulnerability disclosure research
  • Network detection context
  • IOC and reputation enrichment

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 3.5/5

Original malware, campaign, and coordinated vulnerability research; principal limitation: Telemetry coverage and defensive recommendations reflect Cisco’s products and customer visibility.

Audience

  • cti analysts
  • network defenders
  • malware analysts
  • vulnerability researchers
  • detection engineers

Formats

  • technical articles
  • vulnerability reports
  • threat reports
  • reputation data
  • podcasts
  • detection references

Keywords

  • threat-research
  • malware-analysis
  • vulnerability-research
  • network-security
  • cti
  • threat-reports
  • snort
  • vendor-research

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Threat ResearchAssessment tier A

Unit 42

Palo Alto Networks Unit 42

Visit source : Unit 42

Unit 42 is Palo Alto Networks’ threat-intelligence and incident-response research organization. Its public portal publishes malware and campaign analysis, high-profile threat briefs, vulnerability research, ransomware and cloud reporting, actor tracking, and lessons from incident-response cases. Articles often provide TTPs, indicators, affected technologies, and mitigation guidance useful for investigations and detections. The source benefits from large commercial telemetry and frontline engagements, but that also shapes its sample and framing. Readers should distinguish confirmed observations from attribution or trend inference and corroborate product-specific recommendations independently.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Unit 42 is Palo Alto Networks’ threat-intelligence and incident-response research organization. Its public portal publishes malware and campaign analysis, high-profile threat briefs, vulnerability research, ransomware and cloud reporting, actor tracking, and lessons from incident-response cases. Articles often provide TTPs, indicators, affected technologies, and mitigation guidance useful for investigations and detections. Analysts can extract a report’s timeline, infrastructure, malware behaviors, affected services, and ATT&CK mappings, then compare those leads with local endpoint, network, identity, or cloud telemetry. Incident-response trend reports can inform planning and tabletop scenarios, but aggregated client cases do not predict one organization’s likelihood. Validate indicator freshness and provenance, follow vulnerability claims to primary advisories, and test proposed mitigations in the relevant architecture. The source benefits from large commercial telemetry and frontline engagements, but that also shapes its sample and framing. Readers should distinguish confirmed observations from attribution or trend inference and corroborate product-specific recommendations independently.

Strengths

  • Combines original threat research with lessons from incident-response engagements
  • Strong technical coverage of malware, vulnerabilities, cloud, ransomware, and actor activity
  • Threat briefs commonly include concrete indicators, TTPs, and mitigations

Limitations

  • Research visibility and recommendations are influenced by Palo Alto Networks telemetry and products
  • Attribution and ecosystem-wide trend conclusions should be corroborated with independent evidence

Best for

  • Incident and campaign investigation
  • Malware and vulnerability research
  • Threat-informed detection planning
  • Ransomware and cloud threat analysis

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 3.5/5

Combines original threat research with lessons from incident-response engagements; principal limitation: Research visibility and recommendations are influenced by Palo Alto Networks telemetry and products.

Audience

  • cti analysts
  • incident responders
  • malware analysts
  • threat hunters
  • security leaders

Formats

  • technical articles
  • threat briefs
  • incident-response reports
  • malware analyses
  • webinars
  • indicator lists

Keywords

  • threat-research
  • incident-response
  • malware-analysis
  • ransomware
  • cloud-security
  • vulnerability-research
  • cti
  • vendor-research

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.