Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Government

1 source

GovernmentAssessment tier A

Cyber Security Agency of Singapore

Cyber Security Agency of Singapore

Visit source : Cyber Security Agency of Singapore

The Cyber Security Agency of Singapore’s publications library provides official national threat landscapes, technical and governance guidance, education material, and sector-focused resources. Recent coverage includes AI and agentic systems, software bills of materials, private 5G, smart buildings, quantum-safe migration, and Singapore’s annual cyber landscape. The source is valuable for Asia-Pacific regional context and practical policy-to-engineering guidance in English. Publication-level depth varies, and Singapore-specific regulatory, sector, and threat assumptions must be separated from generally reusable technical recommendations.

Source type
Government
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The Cyber Security Agency of Singapore’s publications library provides official national threat landscapes, technical and governance guidance, education material, and sector-focused resources. Recent coverage includes AI and agentic systems, software bills of materials, private 5G, smart buildings, quantum-safe migration, and Singapore’s annual cyber landscape. The source is valuable for Asia-Pacific regional context and practical policy-to-engineering guidance in English. Organizations can use the technical guides to seed architecture requirements and assessment questions, while leaders can use landscape reports to compare Singapore-focused trends with their own threat model. Check each publication’s target audience, status, and referenced standards, then map reusable recommendations to locally applicable regulations and technology documentation. For emerging topics, distinguish proposed practices and readiness guidance from tested control effectiveness. Cross-reference regional observations with JPCERT/CC, ENISA, other national CERTs, and direct incident evidence. Publication-level depth varies, and Singapore-specific regulatory, sector, and threat assumptions must be separated from generally reusable technical recommendations.

Strengths

  • Official English-language source for Singapore’s cyber landscape and national guidance
  • Timely coverage of emerging technologies alongside organizational and sector security
  • Balances strategic reports, practical guides, and public education resources

Limitations

  • Some guidance and findings are specific to Singapore’s policy and operating context
  • The publication library is selective and not a substitute for continuous operational threat feeds

Best for

  • Singapore and Asia-Pacific cyber context
  • Emerging-technology security guidance
  • National threat-landscape comparison
  • Public and organizational cybersecurity education

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.9/5
  • Transparency 5/5

Official English-language source for Singapore’s cyber landscape and national guidance; principal limitation: Some guidance and findings are specific to Singapore’s policy and operating context.

Audience

  • Singapore organizations
  • security leaders
  • policy makers
  • security architects
  • educators

Formats

  • government publications
  • threat landscapes
  • technical guides
  • discussion papers
  • self-assessment tools
  • education guides

Keywords

  • government
  • national-cert
  • threat-reports
  • security-guidance
  • ai-security
  • critical-infrastructure
  • cyber-resilience
  • singapore

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Incident Response

2 sources

Incident ResponseAssessment tier A

CERT-EU Publications

CERT-EU

Visit source : CERT-EU Publications

CERT-EU’s publications portal exposes selected security advisories, pragmatic guidance, cyber briefs, and threat-landscape reporting from the cybersecurity service for European Union institutions, bodies, offices, and agencies. Advisories prioritize major vulnerabilities and include actionable patching or mitigation recommendations; intelligence products focus on activity affecting Union entities and their ecosystem. This makes the source valuable for EU institutional and policy context. Public material is only part of CERT-EU’s constituency service, and its prioritization and victimology should not be assumed to represent every European organization or sector.

Source type
Government
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

CERT-EU’s publications portal exposes selected security advisories, pragmatic guidance, cyber briefs, and threat-landscape reporting from the cybersecurity service for European Union institutions, bodies, offices, and agencies. Advisories prioritize major vulnerabilities and include actionable patching or mitigation recommendations; intelligence products focus on activity affecting Union entities and their ecosystem. This makes the source valuable for EU institutional and policy context. Vulnerability teams can use an advisory as a prioritization lead, then confirm affected versions and remediation through the vendor notice, CVE record, KEV, and local inventory. CTI teams can compare cyber briefs with ENISA, national CSIRTs, and vendor research to identify common reporting and Union-specific emphasis. Preserve publication date, cited evidence, and intended constituency before translating recommendations into controls or executive reporting. Public material is only part of CERT-EU’s constituency service, and its prioritization and victimology should not be assumed to represent every European organization or sector.

Strengths

  • Official operational security source for EU institutions and their ecosystem
  • Curated advisories pair vulnerability significance with practical remediation guidance
  • Threat products combine institutional context with TTPs, actors, vulnerabilities, and defensive recommendations

Limitations

  • Public releases are a subset of intelligence and services available to CERT-EU constituents
  • Threat prioritization is centered on Union entities and may not generalize to other environments

Best for

  • EU institutional threat awareness
  • Prioritized vulnerability advisories
  • European public-sector security guidance
  • Threat-landscape comparison

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Official operational security source for EU institutions and their ecosystem; principal limitation: Public releases are a subset of intelligence and services available to CERT-EU constituents.

Audience

  • EU institutions
  • security operations teams
  • incident responders
  • cti analysts
  • public-sector security leaders

Formats

  • security advisories
  • security guidance
  • cyber briefs
  • threat-landscape reports
  • annual reports

Keywords

  • csirt
  • eu-csirt
  • european-union
  • vulnerability-advisories
  • threat-reports
  • incident-response
  • cti
  • public-sector

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Incident ResponseAssessment tier A

JPCERT/CC

JPCERT Coordination Center

Visit source : JPCERT/CC

JPCERT/CC is an independent Japanese nonprofit CSIRT that serves as Japan’s point of contact for incident coordination and performs early warning, vulnerability coordination, artifact analysis, and industrial-control-system security work. Its English portal provides alerts, quarterly incident reports, technical analyses, tools, and selected translations of Japanese research. JPCERT/CC also works with IPA on Japan Vulnerability Notes and coordinates disclosures with vendors and international partners. It is a primary source for Japanese threat activity and response practice, although English material may be less complete or timely than Japanese-language material.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

JPCERT/CC is an independent Japanese nonprofit CSIRT that serves as Japan’s point of contact for incident coordination and performs early warning, vulnerability coordination, artifact analysis, and industrial-control-system security work. Its English portal provides alerts, quarterly incident reports, technical analyses, tools, and selected translations of Japanese research. JPCERT/CC also works with IPA on Japan Vulnerability Notes and coordinates disclosures with vendors and international partners. Responders can use alerts and analysis reports to understand regionally observed tradecraft, extract artifacts for controlled hunting, and find the appropriate coordination path for incidents involving Japan. Malware analysts can reproduce documented artifact-decoding or persistence findings against authorized samples, while ICS teams can use sector material to frame defensive reviews. Cross-check identifiers and fixes in vendor advisories or JVN, and preserve whether an observation came from a case, survey, or public report. It is a primary source for Japanese threat activity and response practice, although English material may be less complete or timely than Japanese-language material.

Strengths

  • Primary Japanese point of contact for incident coordination, alerts, and technical analysis
  • Publishes artifact and malware analysis grounded in operational cases
  • Combines vulnerability coordination, ICS expertise, early warning, and international CSIRT collaboration

Limitations

  • English translations and summaries may lag or omit material available on the Japanese site
  • Regional incident data and priorities should not be treated as globally representative

Best for

  • Japanese and East Asian threat context
  • Incident and malware analysis
  • Coordinated vulnerability disclosure research
  • ICS security awareness

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.9/5
  • Transparency 4.5/5

Primary Japanese point of contact for incident coordination, alerts, and technical analysis; principal limitation: English translations and summaries may lag or omit material available on the Japanese site.

Audience

  • incident responders
  • cti analysts
  • malware analysts
  • vulnerability coordinators
  • ICS defenders

Formats

  • security alerts
  • quarterly reports
  • technical reports
  • analysis tools
  • vulnerability notes
  • conference materials

Keywords

  • csirt
  • independent-nonprofit
  • incident-response
  • malware-analysis
  • vulnerability-disclosure
  • ics-security
  • threat-reports
  • japan

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Threat Reports

2 sources

Threat ReportsAssessment tier B

Verizon Data Breach Investigations Report

Verizon Business

Visit source : Verizon Data Breach Investigations Report

The Verizon Data Breach Investigations Report is an annual analysis of security incidents and confirmed data breaches contributed by law enforcement, forensic firms, insurers, sharing groups, Verizon cases, and other partners. Records are normalized into the VERIS framework, anonymized, aggregated, and analyzed by industry, region, actor, action, asset, and pattern. Its transparent methodology makes it valuable for benchmarking and risk communication. The DBIR explicitly describes a sample, not every breach; contributor composition, missing data, classification decisions, and small subsets limit generalization to a specific organization.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The Verizon Data Breach Investigations Report is an annual analysis of security incidents and confirmed data breaches contributed by law enforcement, forensic firms, insurers, sharing groups, Verizon cases, and other partners. Records are normalized into the VERIS framework, anonymized, aggregated, and analyzed by industry, region, actor, action, asset, and pattern. Its transparent methodology makes it valuable for benchmarking and risk communication. Risk teams can use the industry and pattern sections to challenge priorities, explain common breach paths, and identify questions for local control testing. Analysts can study VERIS categories to understand how cases were classified and avoid mixing incidents with confirmed breaches. When comparing years, account for changing contributors, definitions, data completeness, and sample sizes; a percentage change may reflect the collection as well as the underlying threat. Cross-use DBIR findings with current threat intelligence and the organization’s own incidents, assets, and exposure. The DBIR explicitly describes a sample, not every breach; contributor composition, missing data, classification decisions, and small subsets limit generalization to a specific organization.

Strengths

  • Large multi-contributor dataset normalized with a documented incident-classification framework
  • Transparent methodology, caveats, confidence treatment, and industry breakdowns
  • Long-running annual series supports cautious trend comparison

Limitations

  • Contributor and case-selection bias mean findings are not representative of all breaches or organizations
  • Annual aggregate patterns cannot replace a local threat model or current operational intelligence

Best for

  • Breach-pattern benchmarking
  • Executive and board risk communication
  • Industry threat comparisons
  • Security-awareness and program planning

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4/5
  • Practical_value 4.9/5
  • Transparency 3.5/5

Large multi-contributor dataset normalized with a documented incident-classification framework; principal limitation: Contributor and case-selection bias mean findings are not representative of all breaches or organizations.

Audience

  • security leaders
  • risk managers
  • cti analysts
  • incident responders
  • policy makers

Formats

  • annual report
  • methodology appendix
  • executive summary
  • industry snapshots
  • infographics
  • webinars

Keywords

  • threat-reports
  • data-breaches
  • incident-data
  • veris
  • risk-management
  • ransomware
  • social-engineering
  • benchmarking

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Threat ReportsAssessment tier B

CrowdStrike Global Threat Report

CrowdStrike

Visit source : CrowdStrike Global Threat Report

CrowdStrike’s Global Threat Report is an annual synthesis of adversary activity and intrusion trends observed by its Counter Adversary Operations team. It emphasizes named actors, motivations, breakout time, malware-free activity, identity, cloud, initial access, and changes in attacker tradecraft, supported by CrowdStrike’s proprietary telemetry and investigations. The report is useful for strategic planning and threat-model updates rather than case-level attribution. Its sample is not the whole internet, vendor naming differs from other taxonomies, and headline percentages need their stated period, definitions, and methodology.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

CrowdStrike’s Global Threat Report is an annual synthesis of adversary activity and intrusion trends observed by its Counter Adversary Operations team. It emphasizes named actors, motivations, breakout time, malware-free activity, identity, cloud, initial access, and changes in attacker tradecraft, supported by CrowdStrike’s proprietary telemetry and investigations. The report is useful for strategic planning and threat-model updates rather than case-level attribution. Security leaders can compare its reported patterns with their own threat profile, while CTI and detection teams can turn relevant behaviors into collection and validation questions. Record the report year, observation window, definitions, and population before comparing metrics across editions. Map CrowdStrike actor names to other vendor aliases cautiously and follow detailed claims to cited research where available. Pair annual trends with current advisories and local incident data, because attacker behavior and visibility change between reporting periods. Its sample is not the whole internet, vendor naming differs from other taxonomies, and headline percentages need their stated period, definitions, and methodology.

Strengths

  • Annual synthesis of current adversary tradecraft from a large operational telemetry base
  • Connects strategic trends with actor, identity, endpoint, SaaS, and cloud observations
  • Useful for leadership briefings and updating threat assumptions

Limitations

  • Proprietary telemetry and client exposure create sample and visibility bias
  • Annual aggregates and vendor actor names are not substitutes for case-specific evidence or cross-vendor mapping

Best for

  • Annual threat-model refreshes
  • Executive threat briefings
  • Adversary trend analysis
  • Security strategy prioritization

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 4/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Annual synthesis of current adversary tradecraft from a large operational telemetry base; principal limitation: Proprietary telemetry and client exposure create sample and visibility bias.

Audience

  • security leaders
  • cti analysts
  • risk managers
  • security architects
  • incident-response leaders

Formats

  • annual report
  • executive summary
  • web presentation
  • charts
  • webinars

Keywords

  • threat-reports
  • threat-landscape
  • adversary-tracking
  • identity-security
  • cloud-security
  • cybercrime
  • nation-state
  • vendor-research

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Vulnerability

3 sources

VulnerabilityAssessment tier A

CVE Program

CVE Program

Visit source : CVE Program

The CVE Program coordinates a global network of CVE Numbering Authorities that assign stable identifiers and publish CVE Records for publicly disclosed vulnerabilities. A record gives people and tools a common reference for the same vulnerability and may include affected products, descriptions, problem types, references, and structured CNA or enrichment data. CVE is foundational interoperability infrastructure, not a severity score, exploitability prediction, patch database, or guarantee of completeness. Record detail and timeliness vary by assigning authority, and users should follow vendor advisories and downstream enrichment.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The CVE Program coordinates a global network of CVE Numbering Authorities that assign stable identifiers and publish CVE Records for publicly disclosed vulnerabilities. A record gives people and tools a common reference for the same vulnerability and may include affected products, descriptions, problem types, references, and structured CNA or enrichment data. CVE is foundational interoperability infrastructure, not a severity score, exploitability prediction, patch database, or guarantee of completeness. Analysts should use the identifier to join vendor notices, NVD enrichment, KEV exploitation evidence, scanners, SBOM results, and remediation tickets while retaining the source of each assertion. Inspect record state, assigning CNA, affected-product statements, references, and update history; rejected or disputed records require special handling. Confirm local applicability through actual product and version evidence and obtain fixed-version guidance from the responsible vendor or project. Record detail and timeliness vary by assigning authority, and users should follow vendor advisories and downstream enrichment.

Strengths

  • Global identifier system makes vulnerability information linkable across vendors, tools, and databases
  • Distributed CNA model lets qualified organizations publish first-party records
  • Machine-readable records preserve attribution, references, status, and update history

Limitations

  • Record completeness, wording, affected-version precision, and publication timing vary among CNAs
  • A CVE identifier provides neither severity nor proof of exploitation or applicability to a local asset

Best for

  • Canonical vulnerability identification
  • Linking advisories and security tools
  • Vulnerability-data integration
  • Finding the assigning authority and primary references

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 4.5/5

Global identifier system makes vulnerability information linkable across vendors, tools, and databases; principal limitation: Record completeness, wording, affected-version precision, and publication timing vary among CNAs.

Audience

  • vulnerability managers
  • product security teams
  • security tool developers
  • researchers
  • incident responders

Formats

  • vulnerability records
  • json data
  • search interface
  • program documentation
  • api

Keywords

  • vulnerability-management
  • cve
  • vulnerability-identifiers
  • coordinated-disclosure
  • machine-readable-data
  • standards
  • cna

Link validation: Reachable · checked 2026-09-07 · HTTP 200

VulnerabilityAssessment tier A

FIRST EPSS

FIRST EPSS Special Interest Group

Visit source : FIRST EPSS

The Exploit Prediction Scoring System publishes a daily, data-driven probability that exploitation activity for a CVE will be observed within the next 30 days, together with a percentile ranking. FIRST provides methodology, calibration and performance material, usage guidance, research, historical data, CSV downloads, and an API. EPSS helps concentrate remediation effort when direct exploitation evidence is absent. It is neither severity nor complete risk: it omits local exposure and business impact, can miss newly changing conditions, and should be combined with KEV, CVSS, asset context, and compensating controls.

Source type
Standards Body
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Exploit Prediction Scoring System publishes a daily, data-driven probability that exploitation activity for a CVE will be observed within the next 30 days, together with a percentile ranking. FIRST provides methodology, calibration and performance material, usage guidance, research, historical data, CSV downloads, and an API. EPSS helps concentrate remediation effort when direct exploitation evidence is absent. Vulnerability teams can retrieve the score at decision time, combine it with exposure, asset criticality, technical impact, and remediation cost, and define measurable prioritization thresholds. The probability answers a specific population-level question; the percentile only shows relative rank among scored CVEs. Preserve the score date because values change as inputs and conditions evolve, and evaluate thresholds against organizational capacity and missed-risk tolerance. A KEV listing or incident observation is stronger direct exploitation evidence. It is neither severity nor complete risk: it omits local exposure and business impact, can miss newly changing conditions, and should be combined with KEV, CVSS, asset context, and compensating controls.

Strengths

  • Open, empirically evaluated probability model focused on near-term exploitation likelihood
  • Daily scores, percentiles, history, CSV data, and API support operational prioritization
  • Published methodology and calibration guidance make the model’s claims testable

Limitations

  • EPSS does not measure technical impact, local exposure, business criticality, or complete risk
  • Predictions are probabilistic; confirmed exploitation evidence such as KEV should supersede them

Best for

  • Risk-based vulnerability prioritization
  • Reducing patch backlogs
  • Quantitative remediation-threshold analysis
  • Enriching vulnerability-management tickets

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 5/5

Open, empirically evaluated probability model focused on near-term exploitation likelihood; principal limitation: EPSS does not measure technical impact, local exposure, business criticality, or complete risk.

Audience

  • vulnerability managers
  • risk analysts
  • security operations teams
  • security engineers
  • researchers

Formats

  • daily scores
  • api
  • csv data
  • methodology
  • research papers
  • usage guidance

Keywords

  • vulnerability-management
  • exploit-prediction
  • patch-prioritization
  • machine-learning
  • risk-analysis
  • cve
  • api
  • machine-readable-data

Link validation: Reachable · checked 2026-09-07 · HTTP 200

VulnerabilityAssessment tier A

National Vulnerability Database

National Institute of Standards and Technology

Visit source : National Vulnerability Database

The National Vulnerability Database is the U.S. government repository of standards-based vulnerability-management data. It ingests CVE Records and adds analysis such as CVSS scores, CWE classifications, CPE product matching, references, change history, and searchable or API-accessible metadata that supports automation, measurement, and compliance. NVD is an enrichment source rather than the original disclosure authority. Its analysis can lag publication or misidentify affected configurations, so practitioners should verify product applicability, fixed versions, exploit status, and remediation against vendor advisories, CVE data, KEV, and local asset evidence.

Source type
Government
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The National Vulnerability Database is the U.S. government repository of standards-based vulnerability-management data. It ingests CVE Records and adds analysis such as CVSS scores, CWE classifications, CPE product matching, references, change history, and searchable or API-accessible metadata that supports automation, measurement, and compliance. NVD is an enrichment source rather than the original disclosure authority. Vulnerability platforms can use its API and feeds to normalize identifiers, severity vectors, weakness classes, and product names, but should retain publication and modification timestamps and handle later corrections. Analysts should inspect the full CVSS vector and CPE configuration logic instead of relying on a score or product-name match alone. Cross-reference the assigning CNA and vendor advisory for affected and fixed versions, KEV for confirmed exploitation, and EPSS for probabilistic prioritization. Its analysis can lag publication or misidentify affected configurations, so practitioners should verify product applicability, fixed versions, exploit status, and remediation against vendor advisories, CVE data, KEV, and local asset evidence.

Strengths

  • Broad standards-based enrichment of CVE records for vulnerability-management automation
  • Search, APIs, data feeds, CVSS, CWE, and CPE fields support large-scale correlation
  • Public change history and references make records traceable to supporting material

Limitations

  • Enrichment may be delayed, incomplete, or inaccurate for complex product and version configurations
  • NVD scores and CPE mappings do not replace vendor advisories, asset validation, or exploit evidence

Best for

  • Vulnerability data enrichment
  • CVE search and API integration
  • CVSS, CWE, and CPE correlation
  • Security measurement and reporting

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 5/5

Broad standards-based enrichment of CVE records for vulnerability-management automation; principal limitation: Enrichment may be delayed, incomplete, or inaccurate for complex product and version configurations.

Audience

  • vulnerability managers
  • security engineers
  • tool developers
  • risk analysts
  • researchers

Formats

  • vulnerability database
  • api
  • json feeds
  • search interface
  • cvss data
  • cpe data

Keywords

  • vulnerability-management
  • cve
  • cvss
  • cwe
  • cpe
  • vulnerability-database
  • api
  • government

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.