Cyber Knowledge · Curated source ecosystem

Cybersecurity Knowledge Sources

A practical directory of authoritative guidance, original research, frameworks, tools, datasets, and hands-on learning. Every source includes an independent scope assessment, evidence-use guidance, limitations, tags, and related reading.

165
assessed sources
32
categories
54
controlled tags
775
source crosslinks

Choose sources for the claim or task

Quality scores describe usefulness within a source’s stated scope; they do not make every page equally authoritative. Prefer primary standards, first-party documentation, original research, or operational evidence for the claim at hand. Use practitioner and vendor material for implementation detail, then corroborate attribution, prevalence, performance, and risk conclusions when the decision requires it.

Find a knowledge source

Search names, organizations, descriptions, audiences, use cases, tags, formats, and keywords.

More filters

Category index

32 categories organize sources by their primary use.

Tag index54 tags

Choose a tag to filter the directory. Each source uses only terms from this controlled vocabulary.

Quick source index165 sources

Every entry links to a stable assessment anchor that can be shared directly.

  1. ADSecurity.org — read assessment
  2. Android Security — read assessment
  3. ANSSI France — read assessment
  4. ANY.RUN — read assessment
  5. Apache Caldera — read assessment
  6. Apple Platform Security — read assessment
  7. Arkime — read assessment
  8. arXiv Cryptography and Security — read assessment
  9. ASD Essential Eight — read assessment
  10. Atomic Red Team — read assessment
  11. Autopsy — read assessment
  12. AWS Security Best Practices — read assessment
  13. Bellingcat Online Investigation Toolkit — read assessment
  14. Binary Ninja — read assessment
  15. BloodHound — read assessment
  16. BSI Germany IT-Grundschutz — read assessment
  17. Canadian Centre for Cyber Security — read assessment
  18. capa — read assessment
  19. Center for Threat-Informed Defense — read assessment
  20. CERT-EU Publications — read assessment
  21. CERT/CC Vulnerability Notes — read assessment
  22. Check Point Research — read assessment
  23. CIS Critical Security Controls — read assessment
  24. CIS Kubernetes Benchmark — read assessment
  25. CISA ICS Advisories — read assessment
  26. CISA Known Exploited Vulnerabilities Catalog — read assessment
  27. Cisco Talos Intelligence — read assessment
  28. Cloud Security Alliance Cloud Controls Matrix — read assessment
  29. CodeQL — read assessment
  30. CrowdStrike Global Threat Report — read assessment
  31. CSA AI Controls Matrix — read assessment
  32. Cutter — read assessment
  33. CVE Program — read assessment
  34. Cyber Security Agency of Singapore — read assessment
  35. CyberDefenders — read assessment
  36. Dragos — read assessment
  37. Elastic Detection Rules — read assessment
  38. ENISA Publications — read assessment
  39. Eric Zimmerman Tools / KAPE — read assessment
  40. Exploit Database — read assessment
  41. Falco — read assessment
  42. FIRST CVSS v4.0 — read assessment
  43. FIRST EPSS — read assessment
  44. FLARE-VM — read assessment
  45. Frida — read assessment
  46. garak — read assessment
  47. Ghidra — read assessment
  48. GitHub Advisory Database — read assessment
  49. Google Cloud Security Best Practices — read assessment
  50. Google Project Zero — read assessment
  51. Google SecOps Community Rules — read assessment
  52. Google Secure AI Framework — read assessment
  53. Google Threat Intelligence — read assessment
  54. GreyNoise — read assessment
  55. GTFOBins — read assessment
  56. Hack The Box Academy — read assessment
  57. HackTricks — read assessment
  58. IBM X-Force Threat Intelligence Index — read assessment
  59. IDA Free — read assessment
  60. Israel National Cyber Directorate — read assessment
  61. JPCERT/CC — read assessment
  62. Kubernetes Security Documentation — read assessment
  63. Kubescape — read assessment
  64. LetsDefend — read assessment
  65. LiveOverflow — read assessment
  66. LOLBAS — read assessment
  67. Malpedia — read assessment
  68. Maltego — read assessment
  69. Malware-Traffic-Analysis.net — read assessment
  70. MalwareBazaar — read assessment
  71. Metasploit Documentation — read assessment
  72. Microsoft Azure Security Documentation — read assessment
  73. Microsoft Digital Defense Report — read assessment
  74. Microsoft Entra Documentation — read assessment
  75. Microsoft Sentinel Content Hub — read assessment
  76. Microsoft Threat Intelligence blog — read assessment
  77. MISP — read assessment
  78. MITRE ATLAS — read assessment
  79. MITRE ATT&CK — read assessment
  80. MITRE D3FEND — read assessment
  81. MobSF — read assessment
  82. National Vulnerability Database — read assessment
  83. NCSC AI Security Guidance — read assessment
  84. NCSC Cyber Assessment Framework — read assessment
  85. NCSC Ireland Guidance — read assessment
  86. NCSC UK Guidance — read assessment
  87. NDSS Symposium — read assessment
  88. NIST AI Risk Management Framework — read assessment
  89. NIST Cybersecurity Framework — read assessment
  90. NIST SP 800-207 Zero Trust Architecture — read assessment
  91. NIST SP 800-53 — read assessment
  92. NIST SP 800-61 Rev. 3 — read assessment
  93. Nmap Documentation — read assessment
  94. OASIS Open CTI Documentation — read assessment
  95. Open Source Vulnerabilities — read assessment
  96. OpenCTI — read assessment
  97. OpenSecurityTraining2 — read assessment
  98. OpenSSF — read assessment
  99. OSINT Framework — read assessment
  100. OSS-Fuzz — read assessment
  101. OverTheWire — read assessment
  102. OWASP API Security Project — read assessment
  103. OWASP ASVS — read assessment
  104. OWASP Cheat Sheet Series — read assessment
  105. OWASP GenAI Security Project — read assessment
  106. OWASP MASTG — read assessment
  107. OWASP MASVS — read assessment
  108. OWASP Top 10 — read assessment
  109. OWASP Web Security Testing Guide — read assessment
  110. PayloadsAllTheThings — read assessment
  111. PentesterLab — read assessment
  112. PingCastle — read assessment
  113. Plaso — read assessment
  114. PortSwigger Research — read assessment
  115. PortSwigger Web Security Academy — read assessment
  116. Promptfoo — read assessment
  117. Prowler — read assessment
  118. Purple Knight — read assessment
  119. pwntools — read assessment
  120. PyRIT — read assessment
  121. Rapid7 Vulnerability & Exploit Database — read assessment
  122. Recorded Future Triage — read assessment
  123. Red Canary Threat Detection Report — read assessment
  124. REMnux — read assessment
  125. ROP Emporium — read assessment
  126. SANS Internet Storm Center — read assessment
  127. Security Onion — read assessment
  128. Semgrep — read assessment
  129. SentinelOne Labs — read assessment
  130. Shodan — read assessment
  131. Sigma — read assessment
  132. Sigstore — read assessment
  133. SLSA — read assessment
  134. Snort — read assessment
  135. SpecterOps Research — read assessment
  136. SpiderFoot — read assessment
  137. Splunk Security Content — read assessment
  138. Stratosphere IPS Datasets — read assessment
  139. Stratus Red Team — read assessment
  140. Suricata — read assessment
  141. The DFIR Report — read assessment
  142. The Sleuth Kit — read assessment
  143. theHarvester — read assessment
  144. ThreatFox — read assessment
  145. Timesketch — read assessment
  146. Trace Labs — read assessment
  147. Trivy — read assessment
  148. TryHackMe — read assessment
  149. UNB CIC Datasets — read assessment
  150. Unit 42 — read assessment
  151. URLhaus — read assessment
  152. USENIX Security Symposium — read assessment
  153. Velociraptor — read assessment
  154. Verizon Data Breach Investigations Report — read assessment
  155. VirusTotal — read assessment
  156. Volatility Foundation — read assessment
  157. VulnCheck KEV — read assessment
  158. VX-Underground — read assessment
  159. Wazuh — read assessment
  160. Wireshark — read assessment
  161. x64dbg — read assessment
  162. YARA — read assessment
  163. Zeek — read assessment
  164. Zero Day Initiative — read assessment

Detailed directory

Open an assessment for detailed use guidance, quality dimensions, limitations, audiences, formats, keywords, and related sources.

Category

Exploit Development

2 sources

Exploit DevelopmentAssessment tier A

pwntools

Gallopsled and pwntools contributors

Visit source : pwntools

pwntools is a Python framework and library for rapid exploit-development and capture-the-flag workflows. Its modules simplify process and socket interaction, binary parsing, assembly, shellcode generation, packing, cyclic patterns, return-oriented programming, debugging integration, and protocol scripting. The official documentation offers stable, beta, and development references with examples and API details. It reduces repetitive plumbing but does not replace understanding of architectures, mitigations, calling conventions, or network behavior. Scripts and generated payloads are dual-use and should be exercised only against authorized challenges, research targets, or isolated vulnerable systems.

Source type
Open Source Project
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

pwntools is an open-source Python framework maintained by Gallopsled and contributors for exploit-development education, capture-the-flag challenges, and authorized vulnerability research. Its modules standardize local process and remote socket interaction, ELF inspection, assembly and disassembly, byte packing, cyclic-pattern generation, return-oriented programming, debugger integration, shellcode handling, logging, and protocol scripting. Learners commonly use it to turn a manual laboratory proof of concept into a repeatable script: identify an offset, inspect the supplied binary, construct inputs with explicit architecture and endianness, launch locally under a debugger, and then test against an authorized challenge endpoint. ROP Emporium supplies suitable exercises, while Ghidra or another reverse-engineering tool explains the code being manipulated. Stable, beta, and development documentation provide API references and examples, but version choice matters because interfaces and behavior can change. pwntools removes repetitive transport and encoding work; it does not explain root cause, defeat mitigations automatically, or make generated payloads reliable or safe. Scripts are materially dual-use. Keep them in isolated labs, pin dependencies, inspect helper behavior, avoid embedding real credentials, preserve scope evidence, and never connect to or test a system without explicit permission.

Strengths

  • High-level Python APIs accelerate exploit prototyping and interaction
  • Integrates binary, assembly, ROP, shellcode, transport, and debugging utilities
  • Well suited to reproducible challenge solutions and research harnesses

Limitations

  • Convenient abstractions can hide architectural or protocol mistakes
  • Payload and exploitation features require explicit authorization and isolated testing

Best for

  • exploit prototyping
  • CTF automation
  • binary interaction scripts
  • vulnerability research harnesses

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.6/5
  • Transparency 5/5

High-level Python APIs accelerate exploit prototyping and interaction; principal limitation: Convenient abstractions can hide architectural or protocol mistakes.

Audience

  • exploit developers
  • CTF participants
  • vulnerability researchers
  • security students

Formats

  • python library
  • api documentation
  • code examples
  • command-line utilities

Keywords

  • exploit-development
  • pwntools
  • python
  • binary-exploitation
  • rop
  • shellcode
  • ctf
  • automation
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Exploit DevelopmentAssessment tier B

ROP Emporium

ROP Emporium

Visit source : ROP Emporium

ROP Emporium is a focused set of downloadable binary challenges for learning return-oriented programming. Its ordered exercises progress from redirecting control flow through calling functions, writing data, handling bad characters, stack pivots, and sparse-gadget techniques, with variants for common architectures and links to a beginner guide. The narrow, repeatable challenge design isolates ROP concepts better than a broad capture-the-flag platform. It assumes familiarity with assembly, calling conventions, debugging, and basic memory corruption, and it does not teach vulnerability discovery, modern mitigations, kernel exploitation, or production exploit reliability comprehensively.

Source type
Independent Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Periodic
Skill level
Intermediate, Advanced
Detailed assessment

Description

ROP Emporium is a focused educational collection of downloadable binary challenges for learning return-oriented programming in a deliberately controlled setting. The sequence begins with basic control-flow redirection and progresses through calling functions, passing arguments, writing data, handling bad characters, stack pivots, ret2csu-style constraints, and sparse gadget sets. Variants for common architectures let learners compare calling conventions and instruction behavior, while the linked beginner material supplies initial orientation. A productive workflow solves challenges in order, records the crash and offset, studies available gadgets and binary protections, constructs a minimal chain, and explains why each transition works. Ghidra, Cutter, or IDA can support static review, and pwntools can make interaction and packing reproducible. The narrow design isolates ROP mechanics more clearly than a broad capture-the-flag event, but it assumes prior assembly, debugging, memory-corruption, and calling-convention knowledge. It does not comprehensively teach vulnerability discovery, heap or kernel exploitation, contemporary exploit mitigations, target-specific reliability, or ethical scoping. Challenge success should not be generalized to production software. Run binaries in a disposable lab, use only provided or authorized targets, and focus documentation on concepts rather than repurposing chains against real systems.

Strengths

  • Progressive challenges isolate specific return-oriented programming concepts
  • Downloadable binaries enable repeatable debugger and scripting practice
  • Architecture variants expose calling-convention and gadget differences

Limitations

  • Deliberately artificial challenges cover only one part of exploit development
  • Requires prior assembly, debugging, and memory-corruption foundations

Best for

  • ROP fundamentals
  • binary-exploitation practice
  • debugger exercises
  • exploit-script development

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4/5
  • Practical_value 4.6/5
  • Transparency 4/5

Progressive challenges isolate specific return-oriented programming concepts; principal limitation: Deliberately artificial challenges cover only one part of exploit development.

Audience

  • exploit-development students
  • CTF participants
  • vulnerability researchers
  • reverse engineers

Formats

  • binary challenges
  • beginner guide
  • downloadable exercises
  • challenge notes

Keywords

  • exploit-development
  • return-oriented-programming
  • binary-exploitation
  • memory-corruption
  • calling-conventions
  • stack-pivot
  • ctf
  • hands-on-labs

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Penetration Testing

1 source

Penetration TestingAssessment tier A

Metasploit Documentation

Rapid7 and the Metasploit community

Visit source : Metasploit Documentation

Metasploit Documentation is the official technical guide for using and contributing to the open-source Metasploit Framework. It covers installation, console workflows, modules, payloads, Meterpreter, development environments, module quality rules, exploit reliability, side effects, testing, reporting, and contribution practices. The material is valuable both for authorized penetration testing and for understanding how repeatable exploit modules are engineered. It is not a substitute for target-specific validation or rules of engagement: modules and payloads can alter systems, evade controls, or expose data, so testing belongs in isolated or explicitly authorized environments.

Source type
Open Core
Access
Free
Evidence use
Primary Authoritative
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Metasploit Documentation is the official technical reference for using and contributing to the open-source Metasploit Framework maintained by Rapid7 and its community. It covers installation, console concepts, workspaces, modules, payloads, sessions, Meterpreter, development environments, module quality expectations, exploit reliability, side effects, testing, reporting, and contribution workflows. Authorized penetration testers use the documentation to understand module options and check behavior, reproduce a finding in a controlled target, record evidence, and select the least disruptive validation method permitted by the rules of engagement. Defenders can study module structure and observable behavior to improve laboratory detections, while Exploit Database and vendor advisories provide separate provenance and affected-version context. The documentation explains the framework; it does not guarantee that a module is safe, applicable, current, or representative of real adversaries. Payloads and post-exploitation functions can execute commands, alter systems, collect data, disable controls, or create persistence. Users must confirm target ownership, exact scope, maintenance windows, data-handling rules, and cleanup requirements before use. Prefer disposable replicas, review module source and references, avoid production exploitation when non-invasive evidence suffices, and never treat an automated session as permission to expand testing beyond the agreed boundary.

Strengths

  • Primary guidance for framework operation, module development, and contribution
  • Documents reliability, side effects, cleanup, and module-quality expectations
  • Covers exploitation, auxiliary testing, payloads, and post-exploitation architecture

Limitations

  • Assumes substantial networking, vulnerability, and operating-system knowledge
  • Framework capabilities are dual-use and can cause compromise or disruption

Best for

  • authorized penetration testing
  • Metasploit module development
  • exploit validation labs
  • framework internals study

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.6/5
  • Transparency 4/5

Primary guidance for framework operation, module development, and contribution; principal limitation: Assumes substantial networking, vulnerability, and operating-system knowledge.

Audience

  • penetration testers
  • exploit developers
  • red teams
  • security researchers

Formats

  • technical documentation
  • development guides
  • module examples
  • github repository links

Keywords

  • penetration-testing
  • metasploit
  • exploit-development
  • payloads
  • post-exploitation
  • module-development
  • red-team
  • dual-use

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Reverse Engineering

3 sources

Reverse EngineeringAssessment tier A

Cutter

Cutter and Rizin projects

Visit source : Cutter

Cutter is a free, GPLv3-licensed, cross-platform reverse-engineering application built on the Rizin analysis engine. It combines graph and linear disassembly views, hexadecimal editing, binary patching, Python and native plugins, an integrated Ghidra decompiler, emulation, and beta local or remote debugging in a modern graphical interface. It is an approachable open-source alternative for exploring binaries while retaining access to Rizin commands. Some advanced components remain experimental, and analysis accuracy depends on the underlying engine, architecture support, binary quality, and manual validation of inferred code and data.

Source type
Open Source Project
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

Cutter is a free, GPLv3-licensed, cross-platform reverse-engineering application built on the open-source Rizin analysis engine. Its graphical workspace combines linear and graph disassembly, cross-references, strings, hexadecimal editing, binary patching, emulation, an integrated Ghidra decompiler, plugins, and beta local or remote debugging. Researchers can open an unfamiliar binary, review analysis settings, navigate functions and data, rename discoveries, inspect decompiler output, and drop into Rizin commands when the interface does not expose enough detail. Python and native plugin support allow workflow extensions, while Ghidra, IDA, and Binary Ninja provide independent comparisons for difficult code. Cutter is approachable, but the graphical layer inherits the capabilities and limitations of Rizin, architecture support, loaders, and connected components. Experimental debugging or emulation may behave differently across targets, plugin quality varies, and inferred functions, types, and references can be wrong for packed, optimized, obfuscated, or malformed binaries. Patching modifies evidence unless performed on a working copy. Analysts should preserve original hashes, use isolated environments for hostile files, vet plugins and project inputs, document versions and settings, verify important conclusions in raw instructions or runtime traces, and examine only software they are authorized to analyze.

Strengths

  • Free graphical interface exposes extensive Rizin analysis capabilities
  • Integrates Ghidra decompilation, graphing, patching, scripting, and plugins
  • Cross-platform design supports accessible reverse-engineering labs

Limitations

  • Debugger and some advanced features may be less mature or platform dependent
  • Automated disassembly and decompilation require manual validation

Best for

  • open-source binary analysis
  • malware-analysis labs
  • binary patching practice
  • Rizin-assisted reverse engineering

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 5/5

Free graphical interface exposes extensive Rizin analysis capabilities; principal limitation: Debugger and some advanced features may be less mature or platform dependent.

Audience

  • reverse engineers
  • malware analysts
  • students
  • CTF participants

Formats

  • desktop software
  • documentation
  • plugins
  • python scripting
  • blog

Keywords

  • reverse-engineering
  • cutter
  • rizin
  • disassembly
  • decompilation
  • binary-patching
  • debugging
  • open-source

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Reverse EngineeringAssessment tier A

Binary Ninja

Vector 35

Visit source : Binary Ninja

Binary Ninja is a commercial interactive platform for disassembly, decompilation, debugging, and programmable binary analysis. Its Binary Ninja Intermediate Language family provides several abstraction levels for program semantics, while Python and C++ APIs and experimental Rust bindings support automation. Vector 35 also provides a no-cost local Free edition and Binary Ninja Cloud; the local edition is restricted to non-commercial use and omits APIs and plugins, while the cloud edition requires uploading binaries. Paid editions add broader architecture support, APIs, plugins, and enterprise options. Automated analysis remains fallible, and sensitive binaries require careful handling.

Source type
Commercial Technical
Access
Freemium
Evidence use
Primary Operational
Maintenance
Continuous
Skill level
Intermediate, Advanced
Detailed assessment

Description

Binary Ninja is Vector 35's interactive platform for disassembly, decompilation, debugging, and programmable binary analysis. Its Binary Ninja Intermediate Language family represents program behavior at several abstraction levels, giving researchers a consistent basis for inspecting data flow, control flow, variables, and lifted instructions. Paid editions expose Python and C++ APIs, plugins, broader architecture support, and enterprise deployment options; experimental Rust bindings extend automation choices. Analysts use the platform to triage a binary, refine function signatures and types, navigate cross-references, debug behavior, and encode repeatable analysis in scripts. Ghidra, IDA, and Cutter provide useful comparison points because their loaders, intermediate representations, and decompilers may resolve ambiguous code differently. Vector 35 also offers a restricted local Free edition for non-commercial use and a browser-based cloud option. The local edition omits APIs and plugins, while cloud analysis requires uploading binaries, which may be inappropriate for confidential, licensed, export-controlled, or incident-sensitive material. Automated lifting and decompilation remain fallible for optimized, obfuscated, malformed, or unsupported code. Confirm current edition terms, protect sample provenance, vet plugins, validate decisive conclusions against instructions and runtime evidence, and restrict analysis to authorized targets.

Strengths

  • Consistent intermediate-language architecture supports analysis and automation
  • Strong Python and C++ APIs, with experimental Rust bindings, for custom workflows
  • Integrated decompilation, debugging, visualization, and optional collaboration

Limitations

  • Most sustained professional use requires a paid license
  • Architecture support and automated semantic recovery require manual verification; cloud use also requires authorization and review of confidentiality and data-use terms

Best for

  • interactive binary analysis
  • reverse-engineering automation
  • vulnerability research
  • collaborative analysis teams

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 5/5
  • Practical_value 4.7/5
  • Transparency 3.5/5

Consistent intermediate-language architecture supports analysis and automation; principal limitation: Most sustained professional use requires a paid license.

Audience

  • reverse engineers
  • vulnerability researchers
  • malware analysts
  • binary-tool developers

Formats

  • desktop software
  • cloud application
  • api documentation
  • plugins
  • debugger

Keywords

  • reverse-engineering
  • binary-ninja
  • disassembly
  • decompilation
  • intermediate-language
  • debugging
  • automation
  • vulnerability-research
  • data-handling

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Reverse EngineeringAssessment tier A

IDA Free

Hex-Rays

Visit source : IDA Free

IDA Free is Hex-Rays' no-cost, non-commercial edition of the IDA disassembler and decompiler. It supports x86 and x86-64 applications, saving analysis databases, local x86/x64 debugging, and cloud-based decompilation, giving learners access to core IDA workflows and a widely recognized interface. It is deliberately constrained relative to paid editions: processor coverage is narrow, commercial use is prohibited, the decompiler requires cloud access, and IDAPython and C++ development kits are unavailable. Analysts working with other architectures, offline requirements, automation, or professional cases need another edition or tool.

Source type
Commercial Technical
Access
Free
Evidence use
Primary Authoritative
Maintenance
Active
Skill level
Beginner, Intermediate
Detailed assessment

Description

IDA Free is Hex-Rays' no-cost, non-commercial edition of the IDA disassembler and decompiler, intended for learning and limited research workflows. It supports analysis of x86 and x86-64 applications, saved databases, local debugging for those architectures, navigation through functions and cross-references, and cloud-backed decompilation. Students and independent researchers can use it to learn the interface common to professional IDA deployments: import a binary, inspect auto-analysis, label functions and data, compare graph and linear views, debug selected behavior, and record hypotheses. Ghidra and Cutter provide open-source alternatives, while paid IDA editions extend the familiar workflow to broader processors, local decompilers, automation, and development kits. The free edition's boundaries are operationally important: its license prohibits commercial use, architecture coverage is narrow, decompilation requires sending relevant material to a cloud service, and IDAPython plus C++ SDK support is unavailable. Sensitive or proprietary binaries may therefore be unsuitable even when technically supported. Like every decompiler, it can infer incorrect types, functions, and control flow. Review current license and privacy terms, preserve original hashes, verify conclusions in assembly or runtime evidence, and analyze only binaries you may lawfully examine.

Strengths

  • No-cost access to core IDA disassembly and x86 cloud decompilation
  • Supports saved analysis databases and local x86/x64 debugging
  • Useful preparation for workflows common in commercial IDA deployments

Limitations

  • Restricted to non-commercial use with limited processor and decompiler support
  • No IDAPython or C++ SDK, and decompilation depends on a cloud service

Best for

  • x86 reverse-engineering practice
  • malware-analysis education
  • IDA workflow evaluation
  • CTF binary analysis

Quality dimensions

  • Authority 5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.6/5
  • Transparency 3.5/5

No-cost access to core IDA disassembly and x86 cloud decompilation; principal limitation: Restricted to non-commercial use with limited processor and decompiler support.

Audience

  • reverse-engineering students
  • malware-analysis learners
  • CTF participants
  • tool evaluators

Formats

  • desktop software
  • cloud decompiler
  • documentation
  • community forum

Keywords

  • reverse-engineering
  • ida
  • disassembly
  • decompilation
  • x86
  • debugging
  • malware-analysis
  • non-commercial

Link validation: Reachable · checked 2026-09-07 · HTTP 200

Category

Training

2 sources

TrainingAssessment tier A

OpenSecurityTraining2

OpenSecurityTraining2

Visit source : OpenSecurityTraining2

OpenSecurityTraining2 is a free technical course platform emphasizing foundational knowledge needed for advanced security engineering and research. Its catalog includes x86-64 and RISC-V architecture, operating-system internals, WinDbg, GDB, Ghidra, IDA, Binary Ninja, software vulnerabilities, exploitation, fuzzing, firmware, trusted computing, and reverse engineering. Courses commonly combine lectures with supporting material and exercises, offering depth rarely available without paid training. Many tracks assume programming, assembly, debugging, and systems prerequisites, and course completeness or instructional style varies by volunteer-led offering.

Source type
Nonprofit Technical
Access
Free
Evidence use
Primary Operational
Maintenance
Active
Skill level
Intermediate, Advanced
Detailed assessment

Description

OpenSecurityTraining2 is a free technical course platform emphasizing foundational knowledge needed for advanced security engineering and research. Its catalog includes x86-64 and RISC-V architecture, operating-system internals, WinDbg, GDB, Ghidra, IDA, Binary Ninja, software vulnerabilities, exploitation, fuzzing, firmware, trusted computing, and reverse engineering. Courses commonly combine lectures with supporting material and exercises, offering depth rarely available without paid training. Many tracks assume programming, assembly, debugging, and systems prerequisites, and course completeness or instructional style varies by volunteer-led offering. Learners can select a foundational architecture or programming path, reproduce demonstrations in a local lab, complete exercises, and then progress into vulnerability analysis or reverse engineering. Researchers can revisit modules as reference for calling conventions, memory, operating-system mechanisms, or debugger workflows. Course pages and videos are freely accessible, but prerequisites, tool versions, links, and lab images should be checked per offering; not every course forms a complete sequence or receives frequent updates. Use disposable virtual machines for exploit and malware-adjacent exercises, verify downloads, and keep targets isolated. The platform builds conceptual and technical depth, but students still need current vendor documentation, independent practice, and ethical authorization before applying dual-use methods beyond supplied labs.

Strengths

  • Provides unusually deep systems-security and reverse-engineering education without tuition cost.
  • Builds prerequisite architecture and debugger knowledge instead of teaching only tool recipes.
  • Offers sequenced course identifiers and learning paths across related advanced topics.

Limitations

  • Many courses have steep prerequisites and require substantial independent lab setup and persistence.
  • Coverage, polish, exercise support, and update cadence vary between instructor-led contributions.

Best for

  • systems security foundations
  • reverse engineering education
  • debugger training
  • exploit-development prerequisites

Quality dimensions

  • Authority 4.5/5
  • Originality 5/5
  • Maintenance 4.5/5
  • Practical_value 4.7/5
  • Transparency 4.5/5

Provides unusually deep systems-security and reverse-engineering education without tuition cost; principal limitation: Many courses have steep prerequisites and require substantial independent lab setup and persistence.

Audience

  • security researchers
  • reverse engineers
  • exploit developers
  • systems programmers

Formats

  • online courses
  • video lectures
  • slides
  • lab exercises
  • learning paths

Keywords

  • security-training
  • reverse-engineering
  • exploit-development
  • debugging
  • computer-architecture
  • operating-system-internals
  • fuzzing

Link validation: Reachable · checked 2026-09-07 · HTTP 200

TrainingAssessment tier C

LiveOverflow

LiveOverflow / Security Flag GmbH

Visit source : LiveOverflow

LiveOverflow publishes free, explanation-driven security videos and companion pages on capture-the-flag challenges, web hacking, memory corruption, browser exploitation, game hacking, reverse engineering, fuzzing, and real vulnerability case studies. The strongest material walks through the research process and underlying technical concepts rather than presenting commands without context, making difficult topics approachable to motivated learners. It is an expert educational publication rather than a formal, versioned curriculum; topic coverage is selective, series may be episodic, and viewers still need independent labs and primary documentation to develop operational competence.

Source type
Independent Technical
Access
Free
Evidence use
Secondary Corroborating
Maintenance
Periodic
Skill level
Beginner, Intermediate, Advanced
Detailed assessment

Description

LiveOverflow publishes free, explanation-driven security videos and companion pages on capture-the-flag challenges, web hacking, memory corruption, browser exploitation, game hacking, reverse engineering, fuzzing, and real vulnerability case studies. The strongest material walks through the research process and underlying technical concepts rather than presenting commands without context, making difficult topics approachable to motivated learners. It is an expert educational publication rather than a formal, versioned curriculum; topic coverage is selective, series may be episodic, and viewers still need independent labs and primary documentation to develop operational competence. Learners benefit most by choosing a series, pausing to reproduce each observation in a controlled target, and documenting why an exploit or bug works instead of copying the final steps. The material complements OpenSecurityTraining2 for systems foundations and Web Security Academy or wargames for structured practice. Articles and videos are free, but dates matter because browsers, compilers, mitigations, challenge infrastructure, and tools evolve; check linked source material and current documentation. Real-case explanations and game-hacking techniques are dual-use, so experiment only with owned or explicitly authorized software. A walkthrough demonstrates one reasoning path under selected conditions, not general assessment coverage, production impact, or professional readiness.

Strengths

  • Explains vulnerability research reasoning and low-level concepts in an accessible narrative style.
  • Uses real CVEs, CTFs, and intentionally vulnerable software to connect theory with practice.
  • Covers advanced browser, memory-corruption, web, and reversing topics free of charge.

Limitations

  • The archive is selective and episodic rather than a complete learning path.
  • Video walkthroughs require independent reproduction and current primary references for durable skill.

Best for

  • vulnerability research concepts
  • CTF learning
  • exploit walkthroughs
  • technical intuition building

Quality dimensions

  • Authority 3.5/5
  • Originality 3/5
  • Maintenance 4/5
  • Practical_value 4.7/5
  • Transparency 4/5

Explains vulnerability research reasoning and low-level concepts in an accessible narrative style; principal limitation: The archive is selective and episodic rather than a complete learning path.

Audience

  • security students
  • CTF participants
  • vulnerability researchers
  • reverse engineers

Formats

  • video tutorials
  • technical articles
  • walkthroughs
  • series
  • frequently asked questions

Keywords

  • security-training
  • vulnerability-research
  • exploit-development
  • web-security
  • reverse-engineering
  • ctf
  • video-learning

Link validation: Reachable · checked 2026-09-07 · HTTP 200

How to interpret this directory

Directory presentation updated 2026-09-09. This does not refresh the individual source assessments or their link-check dates.

Five quality dimensions

Authority, originality, maintenance, practical value, and transparency are each scored from 1 to 5. The A–C tiers are editorial judgments, not measured accuracy or independent certification. Historical numeric scores remain in the export for traceability; small score differences should not be interpreted as meaningful ranking. Read the rationale and limitations for each source. Audience levels overlap: a provider may offer both introductory and advanced material. Imported research provenance records how a source was discovered, not independent validation of its claims.

Evidence before reputation

A well-known source can still be secondary evidence for a particular claim. “Primary authoritative,” “primary operational,” “mixed,” and related labels describe how a source can support analysis—not a guarantee that every publication is correct.

Tool, training, malware, and offensive-security resources may require authorization, isolation, licensing review, or extra safety controls. Read each caution and the destination’s current terms before use.

Validation is time-bounded

URLs were checked on 2026-09-07. A reachable page can change, and an automated-access restriction is not the same as a broken link. Check current versions, supersession notices, and publication dates before a consequential decision.