A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.
Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.
Local directory search
Find a knowledge source
Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.
Browse by domain
Category index
32 categories organize sources by their primary use.
The OASIS Open CTI documentation is the official learning and reference entry point for STIX and TAXII. STIX 2.1 defines JSON objects, relationships, observables, and patterning for representing cyber threat intelligence; TAXII 2.1 defines HTTPS APIs for discovering and exchanging collections of intelligence. The site provides specifications, introductions, examples, walkthroughs, schemas, and validator links. It is essential for interoperable CTI engineering but is not an intelligence feed or analytic methodology, and valid syntax does not ensure accurate sourcing, confidence, handling, or useful intelligence content.
The OASIS Open CTI documentation is the official learning and reference entry point for STIX and TAXII. STIX 2.1 defines JSON objects, relationships, observables, and patterning for representing cyber threat intelligence; TAXII 2.1 defines HTTPS APIs for discovering and exchanging collections of intelligence. The site provides specifications, introductions, examples, walkthroughs, schemas, and validator links. Engineers should use the normative specifications when implementing producers or consumers, the examples for orientation, and schemas or validators to catch structural errors. Model provenance, confidence, markings, identities, relationships, and time explicitly so downstream users can judge intelligence rather than receive disconnected indicators. Test exchange behavior between actual platforms, including pagination, filtering, versioning, and collection permissions. MISP and OpenCTI can operationalize parts of this ecosystem, but their extensions and import decisions still require review. It is essential for interoperable CTI engineering but is not an intelligence feed or analytic methodology, and valid syntax does not ensure accurate sourcing, confidence, handling, or useful intelligence content.
Strengths
Canonical documentation for widely implemented CTI representation and transport standards
Combines normative specifications with examples, walkthroughs, schemas, and validators
Supports interoperable, machine-readable intelligence exchange across tools and organizations
Limitations
Standards compliance does not guarantee intelligence quality, provenance, relevance, or safe sharing
The full object and relationship models can be complex for first-time implementers
Best for
STIX 2.1 data modeling
TAXII 2.1 client and server implementation
CTI platform integration
Validating machine-readable intelligence
Quality dimensions
Authority5/5
Originality5/5
Maintenance4.5/5
Practical_value4.9/5
Transparency5/5
Canonical documentation for widely implemented CTI representation and transport standards; principal limitation: Standards compliance does not guarantee intelligence quality, provenance, relevance, or safe sharing.
MISP is an open-source platform and data-model ecosystem for collecting, correlating, analyzing, and sharing threat intelligence within organizations and trust communities. It supports granular distribution rules, taxonomies, galaxies, sightings, synchronization, REST automation, and exports to formats including STIX and network-detection rules. MISP is especially useful for collaborative indicator and event workflows while retaining context and handling controls. The software is not itself a guarantee of good intelligence: value depends on source quality, analyst curation, taxonomy discipline, access governance, and lawful sharing of sensitive data.
MISP is an open-source platform and data-model ecosystem for collecting, correlating, analyzing, and sharing threat intelligence within organizations and trust communities. It supports granular distribution rules, taxonomies, galaxies, sightings, synchronization, REST automation, and exports to formats including STIX and network-detection rules. MISP is especially useful for collaborative indicator and event workflows while retaining context and handling controls. Analysts can organize observations into events and objects, record source and confidence context, apply sharing markings, correlate related attributes, and publish only to authorized communities. Automation through the REST API can enrich or distribute approved data, while sightings help distinguish local observations from inherited assertions. Define taxonomy, retention, review, and distribution policies before connecting feeds or peers; otherwise duplicates and low-confidence indicators can propagate quickly. STIX exports support interoperability but may not preserve every MISP-specific semantic. The software is not itself a guarantee of good intelligence: value depends on source quality, analyst curation, taxonomy discipline, access governance, and lawful sharing of sensitive data.
Strengths
Mature open-source platform for structured intelligence sharing, correlation, and collaboration
Flexible sharing groups, taxonomies, galaxies, sightings, APIs, and import-export formats
Large practitioner community and reusable open data-model resources
Limitations
Deployment, data governance, deduplication, and taxonomy management require sustained expertise
Imported indicators can be stale, false-positive, sensitive, or legally restricted unless curated
Best for
Organizational threat-intelligence management
Trust-group information sharing
Indicator correlation and enrichment
Automating intelligence-to-detection workflows
Quality dimensions
Authority4.5/5
Originality5/5
Maintenance5/5
Practical_value4.9/5
Transparency5/5
Mature open-source platform for structured intelligence sharing, correlation, and collaboration; principal limitation: Deployment, data governance, deduplication, and taxonomy management require sustained expertise.
OpenCTI is an open-source platform for structuring, storing, visualizing, and operationalizing technical and non-technical threat intelligence as a knowledge graph. Its data model is based on STIX 2.1, with extensions, connectors, feeds, streams, TAXII collections, enrichment, dashboards, and role-based administration. It is strong for linking actors, campaigns, malware, vulnerabilities, observables, reports, and organizational context. OpenCTI is infrastructure rather than an authoritative feed: accuracy depends on connector behavior, source licensing, deduplication, confidence handling, analyst review, and secure deployment of a complex service stack.
OpenCTI is an open-source platform for structuring, storing, visualizing, and operationalizing technical and non-technical threat intelligence as a knowledge graph. Its data model is based on STIX 2.1, with extensions, connectors, feeds, streams, TAXII collections, enrichment, dashboards, and role-based administration. It is strong for linking actors, campaigns, malware, vulnerabilities, observables, reports, and organizational context. A CTI team can ingest selected sources through connectors, preserve reports and relationships, reconcile entities, enrich observables, and publish curated views or collections to consumers. Design source priorities, confidence rules, marking policies, identity resolution, and retention before scaling ingestion; a visually connected graph can still contain conflicting or weak assertions. Review connector permissions and outbound data paths, and monitor imports for schema or licensing changes. Cross-check important relationships against their source reports and use STIX/TAXII documentation when exchanging data. OpenCTI is infrastructure rather than an authoritative feed: accuracy depends on connector behavior, source licensing, deduplication, confidence handling, analyst review, and secure deployment of a complex service stack.
Strengths
Knowledge-graph model supports relationships across strategic, operational, and technical intelligence
Combines analyst workflows, dashboards, enrichment, sharing, and access controls
Limitations
The multi-service platform and connector ecosystem require operational, security, and data-governance expertise
Source ingestion does not guarantee accuracy, lawful use, deduplication, or analytic confidence
Best for
Building an organizational CTI knowledge base
Connecting reports, observables, actors, and vulnerabilities
Integrating intelligence with SIEM and response systems
Collaborative intelligence analysis
Quality dimensions
Authority4.5/5
Originality5/5
Maintenance5/5
Practical_value4.9/5
Transparency4/5
Knowledge-graph model supports relationships across strategic, operational, and technical intelligence; principal limitation: The multi-service platform and connector ecosystem require operational, security, and data-governance expertise.
ThreatFox is a community platform operated by abuse.ch and Spamhaus for sharing indicators associated with malware and botnet activity. Analysts can search submissions and consume recent indicators through downloadable exports and an API, with malware-family, confidence, reporter, and time context where available. It is useful for enrichment, hunting, research, and feed prototyping because the data is openly accessible and operationally current. Indicators are observations, not verdicts: domains, IP addresses, and URLs can change ownership or host mixed content, so age, confidence, context, and local evidence must be checked before blocking.
ThreatFox is a community platform operated by abuse.ch and Spamhaus for sharing indicators associated with malware and botnet activity. Analysts can search submissions and consume recent indicators through downloadable exports and an API, with malware-family, confidence, reporter, and time context where available. It is useful for enrichment, hunting, research, and feed prototyping because the data is openly accessible and operationally current. Defenders can pivot from a suspicious observable to associated malware labels and reports, or ingest recent records into a staging pipeline that enforces age, type, confidence, and allow-list rules. Preserve first-seen and last-seen context, validate hits against DNS, proxy, endpoint, and case evidence, and expire indicators according to type and observed persistence. Compare malware naming with vendor research because family labels and aliases are not universally consistent. Indicators are observations, not verdicts: domains, IP addresses, and URLs can change ownership or host mixed content, so age, confidence, context, and local evidence must be checked before blocking.
Strengths
Open, machine-readable stream of malware-associated indicators with useful context
Community submissions are searchable and available through API and export formats
Integrates readily with CTI platforms and defensive workflows
Limitations
Indicator quality, scope, and confidence vary with submissions and available evidence
Infrastructure indicators decay and can cause collateral damage if blocked without validation
Best for
IOC enrichment and pivoting
Threat hunting
Malware infrastructure research
Testing CTI ingestion workflows
Quality dimensions
Authority4/5
Originality4/5
Maintenance5/5
Practical_value4.8/5
Transparency4/5
Open, machine-readable stream of malware-associated indicators with useful context; principal limitation: Indicator quality, scope, and confidence vary with submissions and available evidence.
URLhaus is operated by abuse.ch and Spamhaus to collect and share URLs used to distribute malware. Its searchable database, API, downloads, and specialized feeds support incident enrichment, malware-campaign tracking, takedown coordination, and defensive automation. Records can connect URLs with payload hashes, malware families, hosting details, status, and submission history. The project’s scope is malicious payload distribution rather than every form of phishing or harmful web activity. URLs are dangerous and time-sensitive; never open them on production systems, and distinguish purpose-built IOC datasets from broader feeds that URLhaus says are not blocklists.
URLhaus is operated by abuse.ch and Spamhaus to collect and share URLs used to distribute malware. Its searchable database, API, downloads, and specialized feeds support incident enrichment, malware-campaign tracking, takedown coordination, and defensive automation. Records can connect URLs with payload hashes, malware families, hosting details, status, and submission history. Responders can query a URL observed in proxy or email telemetry, pivot to delivered payload hashes, compare submission timing, and search endpoint evidence for related execution. Feed consumers should choose the dataset designed for their control, normalize URL syntax carefully, enforce expiry and exception handling, and validate local matches before containment. Investigate content only in an isolated analysis environment with appropriate authorization; an inactive status does not make historical payloads safe. The project’s scope is malicious payload distribution rather than every form of phishing or harmful web activity. URLs are dangerous and time-sensitive; never open them on production systems, and distinguish purpose-built IOC datasets from broader feeds that URLhaus says are not blocklists.
Strengths
Focused operational dataset for malware-distribution URLs and associated payload context
Offers APIs and downloadable datasets suited to automation and research
Supports abuse reporting and disruption as well as defensive consumption
Limitations
It does not aim to catalog all phishing, fraud, or malicious web infrastructure
URLs can be hazardous, short-lived, or hosted on shared infrastructure and require controlled handling
Best for
Malware-delivery investigation
IOC enrichment
Network hunting and retrospective analysis
Researching malicious hosting infrastructure
Quality dimensions
Authority4/5
Originality4/5
Maintenance5/5
Practical_value4.8/5
Transparency4/5
Focused operational dataset for malware-distribution URLs and associated payload context; principal limitation: It does not aim to catalog all phishing, fraud, or malicious web infrastructure.
Google Threat Intelligence is a commercial intelligence platform combining Google security telemetry, Mandiant’s incident-response and analyst research, and VirusTotal’s contributed files, URLs, and community context. It supports indicator enrichment, actor and campaign research, malware analysis, hunting, collections, graph pivoting, APIs, and intelligence-assisted prioritization. The combination can provide unusually broad context, but detailed capabilities and API access depend on paid subscription tiers. Coverage and verdicts remain proprietary and visibility-biased; AI-generated summaries, attribution, prevalence, and unified scores should be checked against underlying evidence and independent sources.
Google Threat Intelligence is a commercial intelligence platform combining Google security telemetry, Mandiant’s incident-response and analyst research, and VirusTotal’s contributed files, URLs, and community context. It supports indicator enrichment, actor and campaign research, malware analysis, hunting, collections, graph pivoting, APIs, and intelligence-assisted prioritization. Analysts can begin with an observable or report, traverse related files, infrastructure, actors, and campaigns, and preserve cited relationships as leads for local searches. Use underlying detections, timestamps, submissions, and report evidence to distinguish direct observations from automated association or narrative assessment. Before uploading files, URLs, or private indicators, confirm organizational data-handling policy because submitted material may be shared or retained according to service terms. The combination can provide unusually broad context, but detailed capabilities and API access depend on paid subscription tiers. Coverage and verdicts remain proprietary and visibility-biased; AI-generated summaries, attribution, prevalence, and unified scores should be checked against underlying evidence and independent sources.
Strengths
Combines frontline Mandiant research, VirusTotal context, and large-scale Google telemetry
Supports technical pivoting, actor research, campaign context, and operational integrations
Connects strategic intelligence with indicator and malware investigation workflows
Limitations
Most operational capabilities are commercial, with pricing and limits tied to subscription tiers
Proprietary visibility, verdict logic, attribution, and AI summaries require independent corroboration
Best for
Enterprise CTI programs
Indicator and malware enrichment
Threat-actor and campaign research
Intelligence-led hunting and prioritization
Quality dimensions
Authority4/5
Originality4/5
Maintenance5/5
Practical_value4.9/5
Transparency3.5/5
Combines frontline Mandiant research, VirusTotal context, and large-scale Google telemetry; principal limitation: Most operational capabilities are commercial, with pricing and limits tied to subscription tiers.
Cisco Talos publishes threat intelligence, malware and campaign research, vulnerability disclosures, reputation data, and defensive content informed by Cisco telemetry and open-source projects such as Snort and ClamAV. Its vulnerability reports document coordinated disclosures, while research articles connect attacker behavior to technical artifacts and protections. The portal is useful for analysts who need both narrative context and operational indicators. Cisco’s product ecosystem influences visibility and remediation framing, so global prevalence, attribution, and product-protection claims should be corroborated with vendor advisories and independent research.
Cisco Talos publishes threat intelligence, malware and campaign research, vulnerability disclosures, reputation data, and defensive content informed by Cisco telemetry and open-source projects such as Snort and ClamAV. Its vulnerability reports document coordinated disclosures, while research articles connect attacker behavior to technical artifacts and protections. The portal is useful for analysts who need both narrative context and operational indicators. Incident responders can use report timelines, infrastructure, samples, and behaviors to develop scoped searches; vulnerability researchers can trace Talos disclosure identifiers to affected products and vendor fixes. Where a post references Snort or ClamAV coverage, inspect the corresponding rule or signature and test it against representative traffic or files instead of inferring complete protection. Record publication date and indicator context, then corroborate actor naming and campaign scope across independent reporting. Cisco’s product ecosystem influences visibility and remediation framing, so global prevalence, attribution, and product-protection claims should be corroborated with vendor advisories and independent research.
Strengths
Original malware, campaign, and coordinated vulnerability research
Connects research findings with reputation data and open-source detection ecosystems
Provides both high-level reporting and detailed technical advisories
Limitations
Telemetry coverage and defensive recommendations reflect Cisco’s products and customer visibility
Attribution, prevalence, and protection claims require independent corroboration
Best for
Threat and malware investigation
Vulnerability disclosure research
Network detection context
IOC and reputation enrichment
Quality dimensions
Authority4.5/5
Originality5/5
Maintenance5/5
Practical_value4.9/5
Transparency3.5/5
Original malware, campaign, and coordinated vulnerability research; principal limitation: Telemetry coverage and defensive recommendations reflect Cisco’s products and customer visibility.
Unit 42 is Palo Alto Networks’ threat-intelligence and incident-response research organization. Its public portal publishes malware and campaign analysis, high-profile threat briefs, vulnerability research, ransomware and cloud reporting, actor tracking, and lessons from incident-response cases. Articles often provide TTPs, indicators, affected technologies, and mitigation guidance useful for investigations and detections. The source benefits from large commercial telemetry and frontline engagements, but that also shapes its sample and framing. Readers should distinguish confirmed observations from attribution or trend inference and corroborate product-specific recommendations independently.
Unit 42 is Palo Alto Networks’ threat-intelligence and incident-response research organization. Its public portal publishes malware and campaign analysis, high-profile threat briefs, vulnerability research, ransomware and cloud reporting, actor tracking, and lessons from incident-response cases. Articles often provide TTPs, indicators, affected technologies, and mitigation guidance useful for investigations and detections. Analysts can extract a report’s timeline, infrastructure, malware behaviors, affected services, and ATT&CK mappings, then compare those leads with local endpoint, network, identity, or cloud telemetry. Incident-response trend reports can inform planning and tabletop scenarios, but aggregated client cases do not predict one organization’s likelihood. Validate indicator freshness and provenance, follow vulnerability claims to primary advisories, and test proposed mitigations in the relevant architecture. The source benefits from large commercial telemetry and frontline engagements, but that also shapes its sample and framing. Readers should distinguish confirmed observations from attribution or trend inference and corroborate product-specific recommendations independently.
Strengths
Combines original threat research with lessons from incident-response engagements
Strong technical coverage of malware, vulnerabilities, cloud, ransomware, and actor activity
Threat briefs commonly include concrete indicators, TTPs, and mitigations
Limitations
Research visibility and recommendations are influenced by Palo Alto Networks telemetry and products
Attribution and ecosystem-wide trend conclusions should be corroborated with independent evidence
Best for
Incident and campaign investigation
Malware and vulnerability research
Threat-informed detection planning
Ransomware and cloud threat analysis
Quality dimensions
Authority4.5/5
Originality5/5
Maintenance5/5
Practical_value4.9/5
Transparency3.5/5
Combines original threat research with lessons from incident-response engagements; principal limitation: Research visibility and recommendations are influenced by Palo Alto Networks telemetry and products.
Link validation: Reachable · checked 2026-09-07 · HTTP 200
Assessment boundary
How to interpret this directory
Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.
Five quality dimensions
Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.
Evidence before reputation
A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.
Links are not endorsements
Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.
Validation is time-bounded
URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.
This curated catalog assesses reusable knowledge providers. For references cited across all 1200km articles and guides, use the site-wide citation inventory; for the narrower set cited inside Cyber Knowledge practitioner guides, use the Cyber Knowledge source index. For correction and evidence rules, read the editorial and source policy.