Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

DFIR

1 source

DFIRAssessment tier A

The Sleuth Kit

Sleuth Kit Labs

Visit source : The Sleuth Kit

The Sleuth Kit is an open-source collection of command-line utilities and a C library for examining disk images, volume systems, file systems, metadata, and recoverable file content. It supplies the low-level forensic engine used by Autopsy and other open-source or commercial tools, while remaining useful directly in scripted and repeatable investigations. The official site provides downloads, file-system documentation, release information, and community support. Its command-oriented workflow assumes knowledge of storage structures and evidence handling; unsupported formats or damaged media may require additional tools and manual validation.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

The Sleuth Kit, maintained by Sleuth Kit Labs and contributors, is an open-source collection of command-line forensic utilities plus a C library for examining storage evidence. Its tools expose image, volume-system, file-system, inode or metadata, allocation, and recoverable-content views, allowing investigators to inspect disk images without relying solely on a graphical abstraction. It also provides the low-level engine used by Autopsy and several other forensic products. Experienced examiners use its focused commands to enumerate partitions, resolve file-system structures, recover content, verify a GUI finding, or script repeatable extraction across evidence sets. The official site documents supported formats, releases, utilities, and file-system concepts. This direct access is powerful but assumes knowledge of offsets, allocation state, storage structures, shell handling, and chain-of-custody requirements. Incorrect parameters can produce incomplete or misleading output, while encryption, unsupported formats, damaged media, modern storage behavior, or proprietary containers may require additional tooling. Analysts should operate on verified forensic copies, record commands and versions, preserve offsets and source identifiers, compare consequential findings with raw structures or another implementation, and keep interpretation separate from what the utility directly reports.

Strengths

  • Low-level, scriptable access to disk and file-system evidence
  • Mature library underpins Autopsy and other forensic applications
  • Command-line tools support repeatable and automatable examinations

Limitations

  • Requires file-system expertise and careful interpretation of recovered artifacts
  • Does not provide Autopsy's integrated GUI and broader case workflow

Best for

  • disk-image analysis
  • file recovery
  • forensic automation
  • tool and plugin development

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Low-level, scriptable access to disk and file-system evidence; principal limitation: Requires file-system expertise and careful interpretation of recovered artifacts.

Audience

  • digital forensic examiners
  • forensic developers
  • incident responders
  • advanced students

Formats

  • command-line tools
  • c library
  • documentation
  • source code
  • release notes

Keywords

  • dfir
  • disk-forensics
  • file-system-analysis
  • file-recovery
  • forensic-automation
  • command-line
  • evidence-analysis

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Malware Analysis

6 sources

Malware AnalysisAssessment tier A

YARA

VirusTotal

Visit source : YARA

YARA is an open-source pattern-matching engine for identifying and classifying files, memory, or other byte sequences through readable rules. Rules combine text strings, hexadecimal patterns, regular expressions, metadata, modules, and Boolean conditions, making YARA a common language for malware-family signatures and hunting logic. Official documentation covers syntax, modules, command-line use, and Python integration, while YARA-CI can test rule repositories. Rules are hypotheses rather than verdicts: brittle patterns create misses, generic strings create false positives, and scanning untrusted samples still requires safe evidence-handling controls.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

YARA is an open-source pattern-matching engine maintained within the VirusTotal ecosystem for identifying and classifying files, process memory, or other byte sequences. Rules combine literal strings, hexadecimal patterns, regular expressions, metadata, external variables, modules, and Boolean conditions in a readable format that supports review and reuse. Malware analysts derive stable traits from related samples, test candidate rules against known malicious and benign corpora, document family and confidence metadata, and deploy validated logic in scanners, sandboxes, repositories, or incident-response workflows. Official documentation covers syntax, modules, command-line operation, performance considerations, and Python integration, while YARA-CI can help test shared rule repositories. Malpedia can provide curated family context and selected rules; REMnux and Ghidra help analysts understand the artifacts behind a pattern. A match is evidence of selected bytes or structure, not proof of malware, identity, intent, or attribution. Overly generic strings generate false positives, tightly coupled patterns miss variants, and adversaries can alter matched features. Rule authors should preserve provenance, avoid confidential indicators, constrain expensive expressions, test representative corpora, assign version and confidence metadata, and review both misses and unexpected matches before operational deployment.

Strengths

  • Expressive, reviewable rule language for textual and binary patterns
  • Cross-platform command-line and Python integrations support automation
  • Broad ecosystem adoption enables exchange of malware-classification logic

Limitations

  • Rule accuracy depends on representative samples and careful pattern selection
  • Matches alone do not establish malware identity, behavior, or attribution

Best for

  • malware-family classification
  • file and memory hunting
  • signature research
  • automated triage pipelines

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Expressive, reviewable rule language for textual and binary patterns; principal limitation: Rule accuracy depends on representative samples and careful pattern selection.

Audience

  • malware analysts
  • threat hunters
  • detection engineers
  • incident responders

Formats

  • open-source software
  • rule language
  • documentation
  • command-line tool
  • python library

Keywords

  • malware-analysis
  • yara
  • pattern-matching
  • file-scanning
  • memory-scanning
  • threat-hunting
  • signature-development
  • automation

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Malware AnalysisAssessment tier A

FLARE-VM

Mandiant

Visit source : FLARE-VM

FLARE-VM is Mandiant's open-source set of PowerShell and package-management scripts for building and maintaining a Windows reverse-engineering virtual machine. Its configurable installer assembles debuggers, disassemblers, unpacking utilities, document tools, scripting environments, and other analyst software into a repeatable workstation. The project solves tool curation rather than analysis itself, and package updates are best effort. Official guidance requires installation only in a virtual machine, recommends snapshots and host-only networking, and notes that endpoint protections may be disabled, making isolation and safe sample handling essential.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

FLARE-VM is Mandiant's open-source collection of PowerShell and package-management scripts for constructing a Windows reverse-engineering and malware-analysis virtual machine. Its configurable installer assembles debuggers, disassemblers, decompilers, unpacking and document-analysis utilities, scripting runtimes, network tools, and supporting packages into a repeatable analyst workstation. Teams use it to standardize lab builds, take a clean snapshot, perform Windows-focused static and dynamic triage, and move significant code into tools such as Ghidra, IDA, or Binary Ninja. REMnux provides a complementary Linux-oriented environment, while YARA and vetted intelligence services support classification and enrichment. FLARE-VM solves installation and tool curation rather than determining which tool or conclusion is correct. Packages have independent maintainers and licenses, upgrades are best effort, and a large toolset increases supply-chain and configuration surface. Official guidance confines installation to a virtual machine and warns that security controls may be disabled. Analysts should isolate networking, remove shared folders and clipboard paths where necessary, protect the host and hypervisor, verify snapshots, restrict sample movement, and record tool versions. A prebuilt analysis environment still requires authorization, disciplined evidence handling, and expert validation of outputs.

Strengths

  • Automates a repeatable Windows reverse-engineering workstation build
  • Curates complementary tools while permitting custom package configurations
  • Open installation scripts make environment changes inspectable

Limitations

  • Third-party package updates can fail or introduce version inconsistency
  • Reduced host protections and live samples demand strict VM and network isolation

Best for

  • Windows malware-analysis labs
  • reverse-engineering workstation setup
  • analyst onboarding
  • repeatable training environments

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.6/5
  • Transparency 5/5

Automates a repeatable Windows reverse-engineering workstation build; principal limitation: Third-party package updates can fail or introduce version inconsistency.

Audience

  • malware analysts
  • reverse engineers
  • incident responders
  • security researchers

Formats

  • github repository
  • powershell installer
  • package configuration
  • documentation

Keywords

  • malware-analysis
  • reverse-engineering
  • windows
  • analysis-lab
  • virtual-machine
  • tool-curation
  • sample-handling
  • powershell

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Malware AnalysisAssessment tier A

REMnux

REMnux project

Visit source : REMnux

REMnux is a Linux distribution and curated toolkit for reverse engineering and analyzing malicious software. It packages community tools for static inspection, document analysis, network-behavior examination, memory work, code analysis, and controlled service simulation, reducing the setup burden for a malware-analysis workstation. Official documentation explains installation as a virtual appliance or on compatible Ubuntu systems and provides usage guidance for included tools. REMnux does not make malware safe: analysts should use isolated virtual machines, snapshots, restricted networking, and disciplined sample-transfer procedures before opening or executing untrusted content.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

REMnux is a Linux distribution and curated malware-analysis toolkit maintained by its project community. Distributed as a virtual appliance or installable on compatible Ubuntu systems, it assembles utilities for static file inspection, malicious-document analysis, code and string examination, memory work, packet and network-behavior review, data decoding, and controlled simulation of common services. Analysts use REMnux to establish a reproducible workstation, triage an unknown sample, extract indicators and configuration, observe network requests under controlled conditions, and move selected binaries into Ghidra or another specialist tool for deeper reverse engineering. YARA supports repeatable pattern matching, while VirusTotal, MalwareBazaar, and Malpedia can add context when data-sharing rules permit. REMnux curates tools and documentation; it does not validate every tool result or make malicious content safe. Packages evolve independently, and outputs can conflict or be fooled by packing, obfuscation, malformed files, and anti-analysis behavior. Use a dedicated virtual machine with snapshots, minimal shared resources, restricted or simulated networking, and disciplined sample transfer. Never expose live malware to production networks or upload confidential samples without authorization, and preserve hashes, versions, commands, and raw observations for later review.

Strengths

  • Curated Linux environment reduces malware-analysis tool setup time
  • Covers complementary static, document, network, and reverse-engineering workflows
  • Documentation and update tooling support repeatable lab maintenance

Limitations

  • A large toolkit still requires analysts to understand each tool and artifact
  • Handling live samples demands isolation, snapshots, and controlled networking

Best for

  • malware-analysis labs
  • malicious document triage
  • network behavior analysis
  • reverse-engineering workstation setup

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Curated Linux environment reduces malware-analysis tool setup time; principal limitation: A large toolkit still requires analysts to understand each tool and artifact.

Audience

  • malware analysts
  • incident responders
  • reverse engineers
  • DFIR students

Formats

  • linux distribution
  • virtual appliance
  • documentation
  • tool collection
  • training material

Keywords

  • malware-analysis
  • reverse-engineering
  • dfir
  • malicious-documents
  • network-analysis
  • analysis-lab
  • sample-handling
  • linux

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Malware AnalysisAssessment tier A

MalwareBazaar

abuse.ch and Spamhaus

Visit source : MalwareBazaar

MalwareBazaar is a community malware-sample exchange operated by abuse.ch with Spamhaus. Researchers can browse metadata, query hashes and families, submit samples, configure alerts, and use APIs for automated intelligence workflows. The service is valuable for obtaining recent specimens and correlating sample-level signals with wider abuse.ch data. It is not a benign download catalog or a complete prevalence dataset: labels and community submissions need corroboration, access may be governed by terms and authentication, and downloaded files are live malware that must remain inside an authorized, isolated analysis environment.

Source type
Independent Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Advanced
Detailed assessment

Description

MalwareBazaar is a community malware-sample exchange operated by abuse.ch with Spamhaus support. Its web interface and APIs expose hashes, file metadata, signatures, family labels, tags, submission information, related analysis signals, alerts, and controlled sample access. Malware researchers use it to locate recent specimens, enrich a hash from an incident, assemble carefully governed research corpora, and correlate a sample with other abuse.ch datasets or independent intelligence. A defensible workflow records the sample hash and provenance, corroborates labels through Malpedia or cited reporting, performs static triage in an isolated REMnux or FLARE-VM environment, and develops narrowly tested YARA logic if appropriate. MalwareBazaar is neither a clean software repository nor a representative census of malware prevalence. Community labels can be incomplete, inconsistent, or wrong; submission volume reflects contributor behavior; APIs and downloads have authentication and usage conditions; and a missing hash proves nothing about safety. Every downloaded object must be treated as live malicious code. Access only for legitimate, authorized work, isolate storage and analysis systems, disable unsafe sharing paths, control retention, never execute samples on production assets, and do not redistribute material contrary to law or service terms.

Strengths

  • Timely community-contributed malware samples with searchable metadata
  • API and alerting capabilities support repeatable enrichment workflows
  • Connects sample sharing with broader abuse.ch and Spamhaus intelligence

Limitations

  • Community labels and sample context can be incomplete or incorrect
  • Live malware downloads present substantial handling, legal, and operational risk

Best for

  • authorized malware acquisition
  • sample enrichment
  • malware-family tracking
  • threat-intelligence automation

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4/5

Timely community-contributed malware samples with searchable metadata; principal limitation: Community labels and sample context can be incomplete or incorrect.

Audience

  • malware researchers
  • threat-intelligence analysts
  • antivirus researchers
  • incident responders

Formats

  • sample database
  • api
  • alerts
  • hash metadata
  • malware downloads

Keywords

  • malware-analysis
  • malware-samples
  • cti
  • hash-lookup
  • api
  • sample-sharing
  • sample-handling
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Malware AnalysisAssessment tier B

Malpedia

Fraunhofer FKIE

Visit source : Malpedia

Malpedia is a curated malware knowledge base operated by Fraunhofer FKIE for rapid identification and contextual research. It organizes families across Windows, Linux, Android, macOS, and other platforms, recording aliases, references, taxonomy, YARA rules, and selected samples where access permits. Curated contributions and synonym mapping make it particularly useful for reconciling vendor naming. Public visibility is incomplete: full data, non-public rules, and samples may require membership in its invite-only trust group. Family assertions and aliases should still be traced to cited reports and corroborated before attribution.

Source type
Nonprofit Technical
Access
Free
Evidence use
Mixed
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Malpedia is a curated malware knowledge base operated by Fraunhofer FKIE to support identification, family research, and naming reconciliation. Entries organize malware across Windows, Linux, Android, macOS, and other platforms and may include family descriptions, aliases, taxonomy, references, YARA rules, and selected samples under controlled access. Analysts often begin with a suspected family or vendor label, compare synonyms, follow primary reports, examine public rules, and use the resulting context to guide deeper static or dynamic analysis. It complements MalwareBazaar as a sample source, VirusTotal as a multi-engine and relationship service, and YARA as the underlying matching language for many published rules. Curation improves consistency, but an entry is not a definitive attribution record and visibility differs between anonymous users and members of the invite-only trust group. Samples, complete data, or non-public rules may be restricted; family names can remain contested; inherited aliases may collapse distinct clusters; and references vary in evidentiary depth. Researchers should cite the underlying reports, record access date and rule provenance, validate matches against code and behavior, separate family classification from actor attribution, and follow membership, licensing, handling, and redistribution requirements.

Strengths

  • Curated family taxonomy and alias mapping reduce naming ambiguity
  • Links malware entries to references, YARA rules, and available samples
  • Accountable contribution model supports reproducible malware research

Limitations

  • Some samples, rules, and contextual data are restricted to trusted members
  • Family membership and vendor aliases still require case-specific corroboration

Best for

  • malware-family identification
  • vendor-name reconciliation
  • reference discovery
  • YARA research

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Curated family taxonomy and alias mapping reduce naming ambiguity; principal limitation: Some samples, rules, and contextual data are restricted to trusted members.

Audience

  • malware analysts
  • reverse engineers
  • threat-intelligence analysts
  • detection researchers

Formats

  • knowledge base
  • family profiles
  • yara rules
  • references
  • restricted samples

Keywords

  • malware-analysis
  • malware-families
  • malware-taxonomy
  • yara
  • cti
  • sample-catalog
  • alias-mapping

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Malware AnalysisAssessment tier B

VirusTotal

VirusTotal

Visit source : VirusTotal

VirusTotal aggregates antivirus, sandbox, reputation, metadata, relationship, and community signals for files, URLs, domains, and IP addresses through a web interface and APIs. Analysts use hash lookups and relationship graphs to enrich incidents, compare vendor detections, pivot across infrastructure, and prioritize deeper analysis. Results are multi-source observations, not a consensus verdict: detection names conflict, benign items can be flagged, and absence of detections does not establish safety. Uploading also shares submitted content with VirusTotal partners, so confidential files, internal URLs, or regulated data must not be submitted casually.

Source type
Commercial Technical
Access
Freemium
Evidence use
Mixed
Maintenance
Continuous
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

VirusTotal, operated by Google, aggregates antivirus, sandbox, reputation, metadata, relationship, and community observations for files, URLs, domains, and IP addresses through web and API access. Responders commonly look up an existing hash, inspect first-seen and analysis metadata, compare vendor labels, review contacted infrastructure, pivot through relationships, and use those leads to prioritize internal evidence collection. Malware analysts may combine its context with Malpedia family references, MalwareBazaar provenance, local YARA results, and independent static or dynamic examination. The service is valuable because it collocates many observations; it does not turn their count into a reliable verdict. Engines share lineage, labels conflict, harmless software can trigger detections, targeted or new malware may produce none, and relationship data can reflect shared infrastructure without shared ownership. Results also vary by access tier, freshness, and submitted artifact. Uploading a file or URL distributes information to VirusTotal and participating partners, which can disclose confidential documents, internal hostnames, customer data, or an active investigation. Prefer hash-only lookup when policy requires it, confirm sharing rules before submission, preserve timestamps and identifiers, corroborate important conclusions locally, and never equate no detections with safety or vendor labels with attribution.

Strengths

  • Broad aggregation of scanner, reputation, metadata, and relationship signals
  • Fast hash and infrastructure enrichment through web and API workflows
  • Historical observations and pivots support malware and incident investigations

Limitations

  • Aggregated detections are signals rather than proof of maliciousness or safety
  • Uploads may expose sensitive content to partners; premium capabilities and quotas vary

Best for

  • file and URL triage
  • indicator enrichment
  • malware relationship analysis
  • threat-intelligence pivots

Quality dimensions

  • Authority 4/5
  • Originality 4/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Broad aggregation of scanner, reputation, metadata, and relationship signals; principal limitation: Aggregated detections are signals rather than proof of maliciousness or safety.

Audience

  • malware analysts
  • SOC analysts
  • incident responders
  • threat-intelligence analysts

Formats

  • web application
  • api
  • analysis reports
  • relationship graph
  • community comments

Keywords

  • malware-analysis
  • file-reputation
  • url-analysis
  • indicator-enrichment
  • cti
  • sandboxing
  • api
  • data-handling

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Reverse Engineering

1 source

Reverse EngineeringAssessment tier A

Ghidra

National Security Agency

Visit source : Ghidra

Ghidra is the National Security Agency's open-source software reverse-engineering framework for disassembly, decompilation, program analysis, scripting, and collaborative work. It supports many processor architectures and executable formats, exposes Java and Python-compatible scripting interfaces, and permits extensions for loaders, analyzers, data types, and processors. Its decompiler and analysis database make it useful for malware, vulnerability, and firmware research. Automated analysis can infer incorrect functions, types, or control flow, especially for optimized, obfuscated, or unsupported code, so conclusions require manual verification and often dynamic analysis.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

Ghidra is the National Security Agency's open-source software reverse-engineering framework for disassembly, decompilation, program analysis, scripting, and team collaboration. It supports many processors and executable formats, maintains a navigable analysis database, and provides cross-references, symbols, data types, function graphs, patching support, and extensible loaders and analyzers. Java and Python-compatible scripting interfaces let researchers automate repetitive classification or extraction tasks. Malware analysts typically import a preserved sample, configure language and loader options, run selected analyzers, rename functions and structures as evidence develops, and correlate static findings with debugger, memory, or network observations. Vulnerability and firmware researchers use similar workflows to understand input handling and unfamiliar architectures. REMnux or FLARE-VM can host surrounding analysis utilities, while YARA captures sufficiently stable traits discovered during review. Decompiled C-like output is an approximation, not recovered source code. Optimized, obfuscated, packed, self-modifying, or unsupported binaries can produce incorrect boundaries, types, call graphs, and control flow. Analysts should verify critical logic in disassembly, inspect raw bytes and runtime behavior, document manual assumptions, treat untrusted extensions and project files cautiously, and conduct dual-use research only on software and systems they are authorized to examine.

Strengths

  • Free, open-source framework with broad architecture and format support
  • Integrated disassembly, decompilation, scripting, and extension mechanisms
  • Supports collaborative projects and repeatable analysis automation

Limitations

  • Automated analysis and decompilation can produce plausible but incorrect interpretations
  • Large or heavily obfuscated binaries require significant expertise and tuning

Best for

  • static binary analysis
  • malware reverse engineering
  • firmware research
  • custom analysis scripting

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Free, open-source framework with broad architecture and format support; principal limitation: Automated analysis and decompilation can produce plausible but incorrect interpretations.

Audience

  • reverse engineers
  • malware analysts
  • vulnerability researchers
  • firmware analysts

Formats

  • desktop software
  • source code
  • documentation
  • training material
  • extension api

Keywords

  • reverse-engineering
  • disassembly
  • decompilation
  • static-analysis
  • malware-analysis
  • binary-analysis
  • firmware
  • scripting

Link validation: Automated access restricted · checked 2026-09-07 · HTTP 403

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.