Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Detection Engineering

2 sources

Detection EngineeringAssessment tier A

Microsoft Sentinel Content Hub

Microsoft

Visit source : Microsoft Sentinel Content Hub

Microsoft Sentinel Content Hub is the supported catalog and deployment path for Sentinel solutions and out-of-the-box content. It centralizes packaged data connectors, analytics-rule templates, hunting queries, workbooks, automation rules, and playbooks from Microsoft, partners, and the community, while exposing each item's provider and support model. The documentation is authoritative for discovery, installation, updates, dependencies, and activation. Content Hub is not a vendor-neutral rule library: using it requires a Sentinel workspace, appropriate Azure roles, configured data ingestion, cost planning, and environment-specific tuning after deployment.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Microsoft Sentinel Content Hub is Microsoft's supported discovery and deployment catalog for packaged Sentinel solutions and security content. Depending on the solution, a package can include data connectors, analytics-rule templates, hunting queries, workbooks, parsers, watchlists, automation rules, and Logic Apps playbooks supplied by Microsoft, partners, or the community. Sentinel administrators use the hub to evaluate providers and support models, review dependencies, install a solution, track available updates, configure ingestion, and then activate selected templates. The surrounding Azure security documentation explains service architecture and permissions; ATT&CK and Sigma can help compare behavioral coverage and detection intent across platforms. Content Hub is a lifecycle mechanism, not a vendor-neutral rule archive or automatic source of operational coverage. Installation alone does not connect every data source, enable analytics, establish retention, or make a playbook safe. Packages can introduce Azure resource costs, role requirements, API permissions, schemas, and version dependencies. Teams should inventory those effects, inspect templates and automation actions, minimize privileges, validate data quality, tune thresholds and entity mappings, test incident creation and response, and document provider-specific support boundaries.

Strengths

  • Authoritative deployment guidance for supported Sentinel content
  • Packages connectors, analytics, hunting, visualization, and automation components
  • Exposes provider, support model, dependencies, and update status

Limitations

  • Requires Microsoft Sentinel, Azure permissions, and associated ingestion resources
  • Installed templates still require data onboarding, activation, validation, and tuning

Best for

  • Microsoft Sentinel deployments
  • SOC solution onboarding
  • content lifecycle management
  • SIEM integration planning

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.6/5
  • Transparency 3.5/5

Authoritative deployment guidance for supported Sentinel content; principal limitation: Requires Microsoft Sentinel, Azure permissions, and associated ingestion resources.

Audience

  • Sentinel administrators
  • SOC architects
  • detection engineers
  • cloud security teams

Formats

  • product documentation
  • solution catalog
  • deployment guides
  • templates

Keywords

  • detection-engineering
  • microsoft-sentinel
  • siem
  • content-hub
  • analytics-rules
  • threat-hunting
  • soar
  • cloud-security

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Detection EngineeringAssessment tier A

Google SecOps Community Rules

Google Cloud

Visit source : Google SecOps Community Rules

Google Security Operations Community Rules is an official public repository of example YARA-L detection rules and dashboard templates for Google SecOps. It includes community and Google SecOps team contributions, a style guide, and a content-management tool that can support rule deployment through the product API. The repository explicitly distinguishes these examples from licensed Google Curated Detections and recommends testing and tuning before alerting. Its value is therefore as transparent implementation material and a starting point, not as guaranteed production coverage; use depends on Google SecOps and its Unified Data Model.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Google Security Operations Community Rules is Google Cloud's official public repository of example YARA-L detections and dashboard templates for Google SecOps. It combines community and Google SecOps team contributions with authoring conventions, metadata, sample content, and a management utility that can synchronize rules through product APIs. Detection engineers use it to learn YARA-L, study Unified Data Model fields, version rules, prototype dashboards, and seed a review-and-test pipeline before enabling alerts. Sigma and other SIEM repositories offer useful comparisons of detection intent, while YARA itself serves a different role in matching file or memory patterns rather than normalized event streams. Google explicitly separates these examples from licensed Google Curated Detections, so their public availability must not be read as equivalent support, testing, or coverage. Rules depend on correctly normalized UDM data and Google SecOps behavior; missing parsers, entity mappings, or context can change results. Contributors and deployers should inspect provenance, validate syntax, replay representative data, measure alert volume and latency, tune suppressions, restrict API credentials, and stage deployment before treating a rule as operationally reliable.

Strengths

  • Inspectable YARA-L examples with authoring guidance and dashboard templates
  • Includes tooling for detections-as-code management through Google SecOps APIs
  • Clearly documents the distinction between community examples and curated detections

Limitations

  • Rules require Google SecOps, UDM-normalized data, testing, and local tuning
  • Example content does not carry the same support or assurance as curated detections

Best for

  • YARA-L rule development
  • Google SecOps content engineering
  • detections-as-code pipelines
  • dashboard prototyping

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Inspectable YARA-L examples with authoring guidance and dashboard templates; principal limitation: Rules require Google SecOps, UDM-normalized data, testing, and local tuning.

Audience

  • Google SecOps engineers
  • detection engineers
  • SOC content teams
  • security automation engineers

Formats

  • github repository
  • yara-l rules
  • yaml dashboards
  • style guide
  • command-line tooling

Keywords

  • detection-engineering
  • google-secops
  • yara-l
  • siem
  • unified-data-model
  • detections-as-code
  • dashboards
  • rule-testing

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

DFIR

6 sources

DFIRAssessment tier A

Timesketch

Timesketch project

Visit source : Timesketch

Timesketch is an open-source collaborative platform for importing, searching, annotating, and analyzing forensic timelines. Investigators organize data into sketches, collaborate through views and comments, run analyzers, apply tags, use intelligence features, and query timelines through the web interface, command-line client, notebooks, or API. It integrates naturally with Plaso output and includes Sigma-based analysis capabilities. Timesketch improves team exploration of large event sets, but it is not an acquisition tool; administrators must manage indexing, access control, scaling, and data sensitivity, while analysts must verify findings against underlying evidence.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Timesketch is an open-source platform for collaborative exploration and analysis of forensic timelines. It imports structured events, including Plaso output, into sketches where investigators can search, save views, tag and annotate records, run analyzers, add intelligence, and coordinate findings through a web interface. Command-line, notebook, and API access support repeatable queries and automation, while Sigma-based capabilities can apply detection ideas to normalized timeline data. A typical incident workflow acquires evidence with separate tools, parses it through Plaso or another pipeline, imports selected datasets, scopes access to the case team, and records analytical conclusions with links back to events. Timesketch improves navigation across large event sets but does not perform acquisition, prove evidence integrity, or eliminate parser uncertainty. Imported timestamps retain the semantic and quality limitations of their sources, and analyzer matches remain hypotheses requiring review. Indexing sensitive histories also creates privacy, retention, access-control, and scaling obligations. Administrators should separate cases appropriately, secure authentication and storage, monitor resource use, and preserve source provenance. Analysts should verify decisive events against original artifacts rather than treating a tag, saved view, or automated analyzer result as conclusive evidence.

Strengths

  • Collaborative interface for searching and organizing forensic timelines
  • Supports analyzers, notebooks, APIs, and Sigma-assisted workflows
  • Separates shared investigation workspaces from raw timeline generation

Limitations

  • Requires separate collection and timeline-generation workflows
  • Scaling, index design, permissions, and sensitive evidence need careful administration

Best for

  • collaborative timeline analysis
  • incident chronology review
  • large-event-set exploration
  • forensic investigation workspaces

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.8/5
  • Transparency 5/5

Collaborative interface for searching and organizing forensic timelines; principal limitation: Requires separate collection and timeline-generation workflows.

Audience

  • digital forensic examiners
  • incident-response teams
  • threat hunters
  • DFIR platform administrators

Formats

  • web platform
  • documentation
  • analyzers
  • api
  • command-line client
  • notebook integration

Keywords

  • dfir
  • forensic-timeline
  • collaboration
  • event-analysis
  • incident-response
  • sigma
  • threat-hunting
  • case-management

Link validation: Reachable · checked 2026-09-07 · HTTP 200

DFIRAssessment tier A

Volatility Foundation

The Volatility Foundation

Visit source : Volatility Foundation

The Volatility Foundation maintains and promotes the open-source Volatility Framework for extracting forensic artifacts from volatile memory images. Volatility 3 and its plugin ecosystem support analysis of processes, modules, handles, network artifacts, operating-system structures, and other memory-resident evidence across investigations and malware research. The foundation also provides project information, training, community events, and a plugin contest. Effective use requires a properly acquired memory image, operating-system knowledge, and careful interpretation; plugin output is evidence to validate in context, not an automatic conclusion about compromise or attribution.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Volatility Foundation stewards the open-source Volatility Framework and supports education and research around memory forensics. Volatility 3 interprets operating-system structures in acquired memory images through plugins that enumerate processes, modules, handles, sockets, registry material, kernel objects, injected regions, and other volatile artifacts. Incident responders use it after sound acquisition to test investigative hypotheses, compare suspicious processes with network and disk evidence, extract candidate material for deeper analysis, and document reproducible commands and outputs. Malware analysts can combine its process and memory views with YARA scanning, disassembly in Ghidra, and contextual intelligence from trusted repositories. The foundation also publishes project information, training, community events, and plugin-development resources. Volatility does not acquire memory by itself, and results depend on image integrity, supported operating-system details, symbols, plugin assumptions, and analyst knowledge. Normal software can resemble malicious patterns, terminated activity may leave partial artifacts, and absence of output is not proof of absence. Examiners should preserve hashes and chain of custody, record versions and parameters, validate important findings against raw structures or independent evidence, and avoid inferring compromise or attribution from one plugin result.

Strengths

  • Primary home of a widely used open-source memory-forensics framework
  • Extensible plugins expose low-level volatile artifacts for repeatable analysis
  • Foundation sustains documentation, training, and community development

Limitations

  • Analysis quality depends on memory acquisition, supported structures, and examiner expertise
  • Artifact presence or absence must be corroborated with other forensic evidence

Best for

  • memory forensics
  • malware process investigation
  • incident-response evidence analysis
  • forensic plugin development

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Primary home of a widely used open-source memory-forensics framework; principal limitation: Analysis quality depends on memory acquisition, supported structures, and examiner expertise.

Audience

  • digital forensic examiners
  • incident responders
  • malware analysts
  • forensic researchers

Formats

  • open-source software
  • documentation
  • plugins
  • training
  • community events

Keywords

  • dfir
  • memory-forensics
  • volatile-memory
  • malware-analysis
  • incident-response
  • forensic-artifacts
  • open-source

Link validation: Reachable · checked 2026-09-07 · HTTP 200

DFIRAssessment tier A

Autopsy

Sleuth Kit Labs

Visit source : Autopsy

Autopsy is a free, open-source desktop platform for end-to-end analysis of disk images, local drives, and supported mobile evidence. Built on The Sleuth Kit, it adds a graphical case workflow, ingest modules, keyword search, timeline and file views, hash-set support, reporting, and an extension architecture for Java or Python modules. It lowers the barrier to structured forensic examination and is widely used in law-enforcement and corporate work. Some advanced training, support, and custom modules are commercial, and examiners must still validate tool output and maintain proper evidence-handling procedures.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Autopsy is a free, open-source forensic analysis application produced by Sleuth Kit Labs and built on The Sleuth Kit's storage and file-system capabilities. Its graphical case workflow supports disk images, local drives, and supported mobile evidence through ingest modules, file and timeline views, keyword search, hash-set comparison, deleted-file recovery, artifact extraction, tagging, and report generation. Examiners can create a case, attach a verified image, select appropriate ingest modules, triage results, bookmark significant artifacts, and generate a reviewable report while retaining links to source locations. Java and Python extension mechanisms support additional modules, and command-line Sleuth Kit tools can independently inspect important structures. Autopsy makes structured examination accessible, but its interface does not remove the need to understand storage formats, acquisition quality, timestamps, and evidentiary procedure. Module support and interpretation vary by data type; damaged, encrypted, or novel formats may require other tools. Some training, support, and custom capabilities are commercial. Investigators should work from forensic copies, verify hashes, document versions and settings, review module errors, validate critical findings at the source level, protect sensitive case data, and avoid presenting generated reports as conclusions without analyst interpretation.

Strengths

  • Accessible GUI integrates many disk-forensics tasks into a case workflow
  • Extensible ingest and reporting modules build on The Sleuth Kit
  • Free core platform supports practical forensic education and investigations

Limitations

  • Large cases and intensive ingest modules can demand significant time and resources
  • GUI findings do not replace source validation, chain of custody, or examiner judgment

Best for

  • disk-image examination
  • file-system investigations
  • forensic case management
  • entry-level DFIR labs

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Accessible GUI integrates many disk-forensics tasks into a case workflow; principal limitation: Large cases and intensive ingest modules can demand significant time and resources.

Audience

  • digital forensic examiners
  • law-enforcement analysts
  • incident responders
  • DFIR students

Formats

  • desktop software
  • documentation
  • training
  • plugins
  • report generation

Keywords

  • dfir
  • disk-forensics
  • file-system-analysis
  • forensic-casework
  • sleuth-kit
  • evidence-analysis
  • incident-response

Link validation: Reachable · checked 2026-09-07 · HTTP 200

DFIRAssessment tier A

Plaso

Plaso project

Visit source : Plaso

Plaso, also known through its log2timeline tooling, is a Python-based processing engine for extracting timestamped events from many disk-image, file-system, registry, database, browser, and log formats. Investigators use it to build broad super timelines or focused timelines that correlate activity across heterogeneous artifacts. Its documentation covers ingestion, filters, parsers, analysis plugins, output modules, supported formats, development, and troubleshooting. Plaso accelerates normalization and chronology building, but parsers can omit or misinterpret data, timestamps carry different semantics, and resulting events still require source-level validation and contextual analysis.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Plaso is an open-source, Python-based event extraction and processing framework best known through the log2timeline command-line workflow. Its parsers read many disk-image, file-system, registry, browser, database, application, and log formats and normalize timestamped records into a storage file for filtering, analysis, and export. Investigators use it to generate a broad super timeline during triage, narrow processing to relevant sources or periods, correlate otherwise separated artifacts, and pass results into Timesketch for collaborative exploration. The project documentation covers supported formats, parser behavior, filters, analysis plugins, output modules, development, and troubleshooting; The Sleuth Kit and other libraries may provide underlying access to storage evidence. Normalization saves substantial manual work but does not make all timestamps equivalent. Creation, modification, access, execution, ingestion, and application-generated times have different semantics, can reflect clock drift, and may be manipulated. A parser may omit unsupported records, misread damaged data, or change behavior between versions. Examiners should preserve the source image, record tool and parser versions, review warnings, retain provenance fields, confirm critical events in the original artifact, and treat an apparent chronology as an analytical model rather than a complete ground truth.

Strengths

  • Normalizes events from a broad range of forensic formats
  • Supports both comprehensive and targeted forensic timelines
  • Extensible parser, analysis-plugin, and output architecture

Limitations

  • Large timelines can be resource intensive and analytically noisy
  • Timestamp meaning and parser results require validation against original artifacts

Best for

  • forensic timeline creation
  • multi-artifact event correlation
  • incident chronology
  • forensic parser development

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Normalizes events from a broad range of forensic formats; principal limitation: Large timelines can be resource intensive and analytically noisy.

Audience

  • digital forensic examiners
  • incident responders
  • forensic tool developers
  • threat hunters

Formats

  • python software
  • documentation
  • command-line tools
  • parser reference
  • api documentation

Keywords

  • dfir
  • forensic-timeline
  • log2timeline
  • event-correlation
  • artifact-parsing
  • incident-response

Link validation: Reachable · checked 2026-09-07 · HTTP 200

DFIRAssessment tier A

Velociraptor

Rapid7 and the Velociraptor project

Visit source : Velociraptor

Velociraptor is an open-source digital-forensics and incident-response platform for collecting, monitoring, and hunting across endpoints. Its client-server architecture and Velociraptor Query Language use reusable artifacts to acquire targeted evidence, query endpoint state, watch events, and centralize results at scale. The official documentation covers deployment, artifacts, notebooks, hunts, security, and administration. Its flexibility also creates risk: broad queries can consume resources or collect sensitive data, servers and client credentials require protection, and community artifacts should be reviewed and tested before use on production fleets.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Velociraptor is an open-source digital-forensics and incident-response platform maintained by Rapid7 and the wider project community. A client-server architecture, Velociraptor Query Language, reusable artifacts, hunts, event monitoring, notebooks, and centralized result handling allow responders to ask targeted questions across one endpoint or a large fleet. Teams commonly deploy clients in advance, scope a hunt to relevant systems, collect process, file-system, registry, event-log, browser, or other artifacts, review results in notebooks, and export selected evidence for timeline or specialist analysis. Plaso and Timesketch can extend chronology work, while YARA and memory-forensics tooling can examine material collected through carefully designed workflows. The official documentation covers deployment, artifact authoring, administration, security, and scaling. Velociraptor's power also makes poor queries consequential: broad collection can overload endpoints, consume storage, cross privacy boundaries, or expose credentials and personal data. Community artifacts are executable collection logic, not inherently trusted content. Administrators should review and pin artifacts, test resource limits, apply least privilege, secure server and client keys, restrict operator access, maintain audit trails and retention rules, and validate collected findings against their original context.

Strengths

  • Scalable targeted collection and live hunting across endpoint fleets
  • Reusable artifact model makes acquisition logic transparent and customizable
  • Combines endpoint monitoring, investigation notebooks, and evidence collection

Limitations

  • Secure deployment and efficient VQL require experienced administration
  • Poorly scoped hunts or unreviewed artifacts can affect endpoints or expose sensitive data

Best for

  • enterprise DFIR collection
  • endpoint threat hunting
  • rapid incident scoping
  • custom forensic artifact development

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Scalable targeted collection and live hunting across endpoint fleets; principal limitation: Secure deployment and efficient VQL require experienced administration.

Audience

  • incident responders
  • threat hunters
  • DFIR platform engineers
  • SOC analysts

Formats

  • software platform
  • documentation
  • artifact repository
  • query examples
  • training videos

Keywords

  • dfir
  • incident-response
  • endpoint-forensics
  • threat-hunting
  • vql
  • evidence-collection
  • fleet-management
  • forensic-artifacts

Link validation: Reachable · checked 2026-09-07 · HTTP 200

DFIRAssessment tier B

The DFIR Report

The DFIR Report

Visit source : The DFIR Report

The DFIR Report publishes detailed case studies derived from observed intrusions, reconstructing initial access, execution, persistence, lateral movement, command and control, and impact through host and network evidence. Public reports commonly include timelines, ATT&CK mappings, indicators, detection ideas, and referenced tooling, making them useful bridges between incident evidence and defensive engineering. The publisher also offers commercial reports, labs, artifacts, and feeds. Each case remains a selected observation rather than a prevalence study, and indicators age quickly, so readers should prioritize behaviors and corroborate conclusions before generalizing.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

The DFIR Report is an independent publisher of evidence-rich intrusion case studies assembled from real incident investigations and controlled observations. Public reports reconstruct activity from initial access through execution, persistence, discovery, lateral movement, command and control, exfiltration, or impact using endpoint and network artifacts. Timelines, ATT&CK mappings, indicators, screenshots, tooling references, and detection ideas let incident responders practice chronology building while detection engineers trace behaviors to observable data. A realistic workflow starts with the narrative, follows cited evidence and external reporting, maps relevant techniques, then compares proposed analytics with Sigma or vendor content and validates them against local telemetry. Commercial reports, labs, artifacts, and feeds extend the public material but have separate access conditions. Each publication describes a selected case, not the frequency of a technique across the threat landscape, and the available evidence may not reveal every attacker action. Indicators decay or may be shared by unrelated activity. Readers should prioritize behavioral patterns, distinguish observed facts from analytical inference, verify attribution separately, and test any detection before production use.

Strengths

  • Evidence-rich intrusion narratives connect telemetry to attacker behavior
  • Timelines and ATT&CK mappings support detection and investigation learning
  • Public cases frequently expose actionable host and network artifacts

Limitations

  • Selected incidents cannot establish ecosystem-wide frequency or attribution
  • Indicators and tool-specific detections may become stale or environment dependent

Best for

  • incident reconstruction
  • detection hypothesis development
  • DFIR analyst training
  • threat-informed tabletop exercises

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Evidence-rich intrusion narratives connect telemetry to attacker behavior; principal limitation: Selected incidents cannot establish ecosystem-wide frequency or attribution.

Audience

  • incident responders
  • threat hunters
  • detection engineers
  • SOC analysts

Formats

  • case reports
  • timelines
  • pcap artifacts
  • indicators
  • training labs

Keywords

  • dfir
  • incident-response
  • intrusion-analysis
  • ransomware
  • threat-hunting
  • detection-engineering
  • mitre-attack
  • network-forensics

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.