Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Detection Engineering

3 sources

Detection EngineeringAssessment tier A

Sigma

SigmaHQ

Visit source : Sigma

Sigma defines an open, structured format for describing log-based detections independently of a specific SIEM query language. Its specification, documentation, command-line conversion tooling, and community rule repository let teams exchange detection logic and translate rules into supported back ends. The format is especially valuable for expressing log sources, selections, filters, conditions, false positives, and severity in reviewable files. A converted rule is only a starting point: field mappings, log availability, back-end behavior, performance, and local false positives must be tested before production use.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Sigma, maintained by SigmaHQ, is an open specification and ecosystem for expressing log-based detection logic without binding the rule author to one SIEM query language. YAML rules document the relevant log source, field selections, filters, Boolean condition, status, severity, references, false positives, and often ATT&CK mappings. Detection teams use the format to review analytics in version control, exchange ideas across organizations, convert supported rules through command-line tooling, and build detections-as-code pipelines with linting and tests. The community repository supplies a large body of examples; Elastic, Splunk, Sentinel, and other content collections help analysts compare platform-native implementations. Sigma captures detection intent, however, not a universal executable query. Back ends differ in operators, correlation features, case handling, aggregation, and field semantics, while local telemetry may not match the declared taxonomy. Community rules also vary in evidence, maturity, and performance. Before production, engineers must confirm data collection, map fields, inspect conversion output, tune exclusions, test against known benign and controlled malicious activity, measure cost, and preserve provenance rather than treating a successful conversion as validated coverage.

Strengths

  • Vendor-neutral rule format improves portability and peer review
  • Open specification and tooling support detections-as-code workflows
  • Community rules provide broad examples mapped to common behaviors

Limitations

  • Back-end conversion cannot resolve missing telemetry or semantic field mismatches
  • Community rules vary in maturity and require local tuning and validation

Best for

  • portable detection authoring
  • rule migration
  • detections-as-code pipelines
  • detection engineering education

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Vendor-neutral rule format improves portability and peer review; principal limitation: Back-end conversion cannot resolve missing telemetry or semantic field mismatches.

Audience

  • detection engineers
  • SOC content teams
  • threat hunters
  • SIEM engineers

Formats

  • specification
  • documentation
  • yaml rules
  • command-line tooling
  • github repositories

Keywords

  • detection-engineering
  • sigma
  • siem
  • log-analysis
  • detections-as-code
  • rule-conversion
  • threat-hunting
  • mitre-attack

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Detection EngineeringAssessment tier A

Elastic Detection Rules

Elastic

Visit source : Elastic Detection Rules

Elastic Detection Rules is the public development repository for rules used by the Elastic Security detection engine. It contains production and building-block rules, hunting content, schemas, tests, and Python tooling for creation, validation, packaging, import, and export. The repository is a concrete example of detections-as-code with unit-tested content and release workflows. Its rules assume Elastic Common Schema, Elastic query languages, and Elastic Security behavior; licensing is Elastic License 2.0, and new repository changes may precede released product content, so deployment compatibility and tuning must be checked.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Elastic Detection Rules is Elastic's public development repository for detection content used by the Elastic Security detection engine. It exposes production rules, building-block rules, hunting queries, schemas, tests, release metadata, and Python tooling for authoring, validating, packaging, importing, and exporting content. Elastic users can trace an analytic from source-controlled definition through review and test workflows, study EQL and KQL patterns, evaluate required integrations and fields, and adapt content to their own telemetry. More broadly, detection engineers can use the repository as a concrete detections-as-code reference and compare its implementations with Sigma, Atomic Red Team tests, ATT&CK behaviors, and case evidence from The DFIR Report. The content is not portable without translation: rules assume Elastic Common Schema, Elastic query semantics, product features, integration versions, and specific data quality. Repository changes may precede released product packages, and Elastic License 2.0 obligations matter for reuse. A rule's presence or passing repository tests does not establish local coverage. Validate compatible versions, required indices and fields, execution cost, expected alerts, exceptions, and false positives before enabling it in production.

Strengths

  • Transparent production rule lifecycle with validation and test tooling
  • Rich detections-as-code implementation beyond static rule files
  • Includes hunting queries and building-block analytics

Limitations

  • Strongly coupled to Elastic Security, ECS, KQL, EQL, and product versions
  • Elastic License 2.0 and unreleased changes require deployment review

Best for

  • Elastic Security content engineering
  • detections-as-code design
  • rule-testing patterns
  • threat-hunting content

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Transparent production rule lifecycle with validation and test tooling; principal limitation: Strongly coupled to Elastic Security, ECS, KQL, EQL, and product versions.

Audience

  • Elastic detection engineers
  • SOC content developers
  • threat hunters
  • security automation engineers

Formats

  • github repository
  • toml rules
  • python tooling
  • tests
  • technical documentation

Keywords

  • detection-engineering
  • elastic-security
  • detections-as-code
  • ecs
  • kql
  • eql
  • threat-hunting
  • rule-testing

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Detection EngineeringAssessment tier A

Splunk Security Content

Splunk

Visit source : Splunk Security Content

Splunk Security Content publishes first-party detections, Analytic Stories, response playbooks, data-source guidance, and ATT&CK coverage views for Splunk security products. Analytic Stories connect threat context with searches, investigations, and available Splunk SOAR actions, making the portal useful for tracing a use case from behavior to operational response. Content is inspectable and frequently updated, but most analytics depend on Splunk search semantics, specific data models, macros, or product applications. Counts and ATT&CK coverage describe available content, not validated coverage in a reader's environment.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Splunk Security Content is Splunk's public catalog of first-party detections, Analytic Stories, threat-hunting searches, response playbooks, data-source guidance, and ATT&CK coverage for its security products. An Analytic Story groups behavior context with concrete searches, required data, investigation guidance, and sometimes Splunk SOAR actions, allowing a content team to follow a use case from hypothesis through triage and response. Splunk practitioners use the catalog to plan onboarding, inspect SPL, identify macros and data-model dependencies, import supported content, and tune analytics with local baselines. Sigma offers a vendor-neutral comparison point, while Atomic Red Team and incident case studies can provide controlled or observed evidence for validation. Most content assumes Splunk search semantics, the Common Information Model, named macros, specific applications, or product capabilities; copying a query into an unrelated deployment may fail silently or produce misleading results. Published ATT&CK mappings and catalog counts show intended content coverage, not effective detection coverage. Teams must verify ingestion, normalization, permissions, scheduling, performance, alert thresholds, suppression, and playbook safety in their own environment before operational use.

Strengths

  • Connects detections, threat context, data sources, and response playbooks
  • First-party content exposes concrete Splunk searches and ATT&CK mappings
  • Searchable catalog supports investigation and content-development workflows

Limitations

  • Analytics often depend on Splunk-specific schemas, macros, and applications
  • Catalog coverage does not demonstrate effective local detection coverage

Best for

  • Splunk detection engineering
  • SOC use-case development
  • SOAR playbook research
  • ATT&CK coverage reviews

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Connects detections, threat context, data sources, and response playbooks; principal limitation: Analytics often depend on Splunk-specific schemas, macros, and applications.

Audience

  • Splunk security analysts
  • detection engineers
  • SOC architects
  • SOAR engineers

Formats

  • detection catalog
  • search queries
  • analytic stories
  • playbooks
  • coverage maps

Keywords

  • detection-engineering
  • splunk
  • siem
  • soar
  • analytic-stories
  • mitre-attack
  • incident-response
  • threat-hunting

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Exploit Development

1 source

Exploit DevelopmentAssessment tier B

Exploit Database

OffSec

Visit source : Exploit Database

Exploit Database is OffSec's public archive of exploits, proof-of-concept code, shellcode, vulnerability-research papers, and Google Hacking Database queries. Entries can be searched by CVE, platform, type, author, port, and verification status, and the downloadable archive is available locally through SearchSploit. It is useful for studying how disclosed vulnerabilities are exercised and for authorized validation against known vulnerable software. It is not an advisory or patch-prioritization service: code quality, safety, applicability, and claimed impact vary, and execution requires isolated targets, source review, and explicit permission.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Advanced
Detailed assessment

Description

Exploit Database is OffSec's public archive of vulnerability proof-of-concept code, exploits, shellcode, research papers, and Google Hacking Database queries. Search filters cover CVE identifiers, platform, type, author, port, and verification status, while SearchSploit provides a locally searchable copy for offline research. Defenders use the archive to understand technical prerequisites and observable behavior after first consulting an authoritative advisory, affected-version statement, and vendor remediation. Authorized testers may review an entry, compare the target build and configuration, inspect every code path, and validate exposure only in an isolated lab or explicitly scoped system. Metasploit documentation can illustrate a more structured module lifecycle, and Nmap can help confirm service inventory without proving vulnerability. Exploit Database is not a canonical vulnerability record, patch-prioritization system, safety review, or guarantee that code works as claimed. Entries differ in age, quality, provenance, reliability, side effects, and applicability; verification status has a limited meaning and does not establish harmlessness. Never run downloaded code blindly. Preserve its hash and source, remove embedded callbacks or destructive actions where appropriate, use disposable targets, obtain written permission, avoid real data, monitor effects, and base remediation decisions on vendor and authoritative vulnerability guidance.

Strengths

  • Searchable archive connects public exploit code with vulnerable platforms and CVEs
  • SearchSploit enables offline research and reproducible local queries
  • Includes proof-of-concepts, shellcode, papers, and curated search queries

Limitations

  • Entries vary in reliability, documentation, safety, and applicability
  • Public exploit code is dual-use and must not be run without review and authorization

Best for

  • exploit research
  • authorized vulnerability validation
  • historical proof-of-concept study
  • defensive reproduction labs

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Searchable archive connects public exploit code with vulnerable platforms and CVEs; principal limitation: Entries vary in reliability, documentation, safety, and applicability.

Audience

  • vulnerability researchers
  • penetration testers
  • exploit developers
  • defensive researchers

Formats

  • exploit archive
  • proof-of-concept code
  • shellcode
  • technical papers
  • search database

Keywords

  • exploit-development
  • vulnerability-research
  • proof-of-concept
  • cve
  • searchsploit
  • shellcode
  • penetration-testing
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Vulnerability

4 sources

VulnerabilityAssessment tier A

CERT/CC Vulnerability Notes

CERT Coordination Center, Carnegie Mellon University Software Engineering Institute

Visit source : CERT/CC Vulnerability Notes

The CERT/CC Vulnerability Notes Database publishes coordinated disclosures and analysis for vulnerabilities, especially complex cases involving multiple vendors, protocols, supply chains, or uncertain ownership. Notes can document affected products, technical impact, vendor status, remediation, references, disclosure history, and a CERT vulnerability identifier, supported by CERT/CC’s coordination guidance and VINCE workflow. The database is valuable when a CVE record is too terse or coordination itself matters. It is selective rather than exhaustive, and older notes may describe obsolete products or mitigations that require fresh vendor verification.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The CERT/CC Vulnerability Notes Database publishes coordinated disclosures and analysis for vulnerabilities, especially complex cases involving multiple vendors, protocols, supply chains, or uncertain ownership. Notes can document affected products, technical impact, vendor status, remediation, references, disclosure history, and a CERT vulnerability identifier, supported by CERT/CC’s coordination guidance and VINCE workflow. The database is valuable when a CVE record is too terse or coordination itself matters. Researchers can use a note to understand shared root cause, vendor responses, disclosure timing, and interim workarounds across an ecosystem. Defenders should identify their precise implementation or downstream product, then follow the relevant vendor statement and test the recommended remediation. The coordination guidance also helps researchers plan authorized reporting when many parties may be affected. Treat status tables as dated evidence and distinguish confirmed, affected, and unknown entries. It is selective rather than exhaustive, and older notes may describe obsolete products or mitigations that require fresh vendor verification.

Strengths

  • Experienced neutral coordination for complex and multi-party vulnerability disclosures
  • Notes can capture vendor status, technical analysis, workarounds, and disclosure context beyond a CVE record
  • Publishes practical coordinated-vulnerability-disclosure guidance

Limitations

  • The notes database is selective and should not be treated as a comprehensive vulnerability catalog
  • Historical entries and mitigations require current product and vendor validation before use

Best for

  • Complex vulnerability research
  • Coordinated disclosure practice
  • Multi-vendor impact analysis
  • Finding historical vulnerability context

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 4.5/5

Experienced neutral coordination for complex and multi-party vulnerability disclosures; principal limitation: The notes database is selective and should not be treated as a comprehensive vulnerability catalog.

Audience

  • vulnerability researchers
  • product security teams
  • vendors
  • incident responders
  • disclosure coordinators

Formats

  • vulnerability notes
  • search database
  • disclosure guidance
  • vendor statements
  • coordination platform

Keywords

  • vulnerability-research
  • coordinated-disclosure
  • vulnerability-advisories
  • vendor-coordination
  • incident-response
  • cve
  • csirt

Link validation: Reachable · checked 2026-09-07 · HTTP 200

VulnerabilityAssessment tier A

Zero Day Initiative

Trend Micro Zero Day Initiative

Visit source : Zero Day Initiative

The Zero Day Initiative is a vulnerability acquisition and coordinated-disclosure program operated by Trend Micro. Its published advisory archive documents vulnerabilities reported through the program, typically including affected products, technical impact, CVSS information, discovery credit, identifiers, disclosure timelines, and vendor coordination status. It offers useful primary context for browser, document, enterprise, and industrial-product flaws. The archive is not a complete vulnerability database, and technical details can be dual-use or intentionally limited before remediation. Testing must remain confined to systems you own or are explicitly authorized to assess.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Zero Day Initiative is a vulnerability acquisition and coordinated-disclosure program operated by Trend Micro. Its published advisory archive documents vulnerabilities reported through the program, typically including affected products, technical impact, CVSS information, discovery credit, identifiers, disclosure timelines, and vendor coordination status. It offers useful primary context for browser, document, enterprise, and industrial-product flaws. Vulnerability analysts can connect a ZDI identifier to its CVE and vendor bulletin, compare disclosed impact with affected-version evidence, and use the timeline to study coordination outcomes. Technical details may help defenders understand the weakness class and reachable attack surface, but they should become lab validation and mitigation checks rather than unapproved exploitation. Confirm whether a fix, workaround, or only a disclosure notice existed on the date being studied. The archive is not a complete vulnerability database, and technical details can be dual-use or intentionally limited before remediation. Testing must remain confined to systems you own or are explicitly authorized to assess.

Strengths

  • Primary advisories from a mature vulnerability research and vendor-coordination program
  • Disclosure timelines and researcher credits add provenance beyond generic database records
  • Strong coverage of technically significant client, enterprise, and industrial product flaws

Limitations

  • The archive reflects vulnerabilities submitted to or purchased by ZDI, not the full vulnerability landscape
  • Advisory detail varies, and exploit-relevant information is dual-use and must be handled lawfully

Best for

  • Vulnerability research case studies
  • Coordinated-disclosure timelines
  • Tracking ZDI-originated CVEs
  • Understanding vulnerability classes and impact

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.8/5
  • Transparency 3.5/5

Primary advisories from a mature vulnerability research and vendor-coordination program; principal limitation: The archive reflects vulnerabilities submitted to or purchased by ZDI, not the full vulnerability landscape.

Audience

  • vulnerability researchers
  • product security teams
  • security engineers
  • incident responders
  • exploit mitigations researchers

Formats

  • vulnerability advisories
  • disclosure timelines
  • research articles
  • contest materials
  • researcher program documentation

Keywords

  • vulnerability-research
  • coordinated-disclosure
  • zero-day
  • exploit-research
  • vulnerability-advisories
  • cve
  • vendor-research
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

VulnerabilityAssessment tier A

Open Source Vulnerabilities

Google Open Source Security Team and OSV contributors

Visit source : Open Source Vulnerabilities

OSV is an open, distributed vulnerability database and schema designed to map vulnerabilities precisely to open-source package versions or commit hashes. OSV.dev aggregates records from participating ecosystem databases, enriches version and alias information, exposes query and batch APIs, publishes downloadable data, and supports the first-party OSV-Scanner. It is especially effective for software-composition and dependency workflows where generic CPE matching is imprecise. Coverage and correctness inherit upstream database quality, ecosystem participation, and version metadata; missing results do not prove a dependency is secure, and source advisories remain authoritative.

Source type
Open Source Project
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

OSV is an open, distributed vulnerability database and schema designed to map vulnerabilities precisely to open-source package versions or commit hashes. OSV.dev aggregates records from participating ecosystem databases, enriches version and alias information, exposes query and batch APIs, publishes downloadable data, and supports the first-party OSV-Scanner. It is especially effective for software-composition and dependency workflows where generic CPE matching is imprecise. Developers can query an ecosystem, package, and version, scan supported manifests or lockfiles, and follow aliases to source advisories and fixes. The event-based affected ranges help model repository history and package releases, but the result still needs dependency-resolution, reachability, configuration, and deployment context. Integrators should preserve upstream database identity, modification time, and withdrawn status and should deduplicate aliases without discarding provenance. Pair OSV results with SBOM inventory, build evidence, and project security notices. Coverage and correctness inherit upstream database quality, ecosystem participation, and version metadata; missing results do not prove a dependency is secure, and source advisories remain authoritative.

Strengths

  • Package- and commit-aware schema provides precise open-source affected-version matching
  • Open API, bulk data, scanner, and distributed source model support automation
  • Aggregates multiple language and operating-system ecosystems with aliases and references

Limitations

  • Coverage varies by ecosystem and depends on the quality and timeliness of upstream databases
  • Automated matches still require reachability, configuration, exploitability, and business-context analysis

Best for

  • Open-source dependency vulnerability lookup
  • SBOM and lockfile scanning
  • Software-composition analysis integrations
  • Publishing ecosystem-native advisories

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 5/5

Package- and commit-aware schema provides precise open-source affected-version matching; principal limitation: Coverage varies by ecosystem and depends on the quality and timeliness of upstream databases.

Audience

  • application security teams
  • software developers
  • product security teams
  • security tool developers
  • open-source maintainers

Formats

  • vulnerability database
  • json schema
  • api
  • bulk data
  • scanner
  • technical documentation

Keywords

  • vulnerability-management
  • open-source-security
  • dependency-security
  • software-composition-analysis
  • sbom
  • api
  • machine-readable-data
  • osv

Link validation: Reachable · checked 2026-09-07 · HTTP 200

VulnerabilityAssessment tier B

GitHub Advisory Database

GitHub

Visit source : GitHub Advisory Database

The GitHub Advisory Database aggregates CVEs, GitHub Security Advisories, ecosystem databases, community contributions, and malware advisories for open-source packages. GitHub-reviewed records are curated for validity and mapped to supported ecosystems and packages; unreviewed records are imported automatically and explicitly carry a lower assurance level. Advisories are published in OSV format through an open repository and can feed Dependabot and API workflows. It is strong for dependency remediation, but review status matters, ecosystem coverage is uneven, and package presence does not prove vulnerable code is reachable in an application.

Source type
Commercial Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

The GitHub Advisory Database aggregates CVEs, GitHub Security Advisories, ecosystem databases, community contributions, and malware advisories for open-source packages. GitHub-reviewed records are curated for validity and mapped to supported ecosystems and packages; unreviewed records are imported automatically and explicitly carry a lower assurance level. Advisories are published in OSV format through an open repository and can feed Dependabot and API workflows. Developers and product-security teams can trace a dependency alert to affected ranges, patched versions, references, and review status, then confirm the resolved dependency graph and whether vulnerable functionality is reachable. The public repository supports corrections and downstream ingestion, while repository security advisories provide a path for coordinated disclosure by maintainers. Distinguish vulnerabilities from malicious-package records and retain ecosystem identifiers when reconciling CVE aliases. Cross-check disputed, unreviewed, or operationally consequential findings against the project and upstream sources. It is strong for dependency remediation, but review status matters, ecosystem coverage is uneven, and package presence does not prove vulnerable code is reachable in an application.

Strengths

  • Package-aware reviewed advisories integrate directly with developer and Dependabot workflows
  • Open OSV-format repository supports community corrections, APIs, and downstream reuse
  • Covers vulnerabilities and malicious packages across multiple popular ecosystems

Limitations

  • Unreviewed advisories have not been assessed by GitHub and do not carry the same integration guarantees
  • Dependency matches require reachability, configuration, fixed-version, and application-context validation

Best for

  • Open-source dependency remediation
  • GitHub-native security workflows
  • Package advisory research
  • Machine-readable advisory integration

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.9/5
  • Transparency 3.5/5

Package-aware reviewed advisories integrate directly with developer and Dependabot workflows; principal limitation: Unreviewed advisories have not been assessed by GitHub and do not carry the same integration guarantees.

Audience

  • software developers
  • application security teams
  • open-source maintainers
  • product security teams
  • security tool developers

Formats

  • advisory database
  • osv json
  • git repository
  • graphql api
  • search interface
  • malware advisories

Keywords

  • vulnerability-management
  • open-source-security
  • dependency-security
  • security-advisories
  • malicious-packages
  • osv
  • github
  • machine-readable-data

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.