Cyber Knowledge · Reference index

Cyber Knowledge Source Index

A transparent inventory of the external material referenced by the field guides, grouped by source class and linked to its publisher.

Referenced sources

178 unique external destinations cited by the ten guides. Classification is descriptive; normative authority depends on the exact document and claim.

1200km research

1200km.com

"Why IOC-Only Detection Fails"

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

AdversaryGraph RAG/MCP

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

ATT&CK as a Working Tool

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

Attribution Methodology

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

CTI Analyst Field Manual

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

CTI as a Code

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

Endpoint Threat Hunting

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

Foundations

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

Handala Hack Group

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

HexStrike documentation

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

Infrastructure Pivoting

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

AdversaryGraph workflow

Used in: CTI, Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

malware-family behavior mapping

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

MuddyWater / Seedworm

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

Operation Desert Hydra

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

Sandworm / APT44

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

SpiderFoot

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

The Intelligent Shield: OpenCTI

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

1200km.com

theHarvester

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

First-party or practitioner reference

clang.llvm.org

AddressSanitizer

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

caldera.mitre.org

Adversary Emulation

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.aicpa-cima.com

AICPA SOC suite

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

mitre-attack.github.io

ATT&CK Navigator

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.aws.amazon.com

AWS shared-responsibility model

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

learn.microsoft.com

Azure shared responsibility

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

learn.microsoft.com

Azure Well-Architected Security Pillar

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

censys.com

Censys

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.censys.com

Censys Platform quick start

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.cisecurity.org

CIS Controls v8.1

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

consumer implementation guide

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.coso.org

COSO Enterprise Risk Management

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

cloudsecurityalliance.org

CSA Cloud Controls Matrix 4.1

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.cve.org

CVE Program

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

CVSS v4.0

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

CVSS v4.0 user guide

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

cyclonedx.org

CycloneDX SBOM

Used in: Secure Code

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

eur-lex.europa.eu

DORA

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

EPSS data definition

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

EPSS user guide

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

FIRST CSIRT Services Framework 2.1

Used in: DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.aws.amazon.com

forensics-in-IR guidance

Used in: DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

sourceware.org

GDB manual

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

eur-lex.europa.eu

GDPR

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

ghidra.re

Ghidra

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

ghidra.re

Ghidra Debugger courseware

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.icann.org

ICANN RDAP

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

ISAC / ISAO

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

kubernetes.io

Kubernetes auditing

Used in: Blue Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

kubernetes.io

Kubernetes Security Checklist

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

kubernetes.io

Kubernetes Security documentation

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.kernel.org

Linux kernel self-protection

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

llvm.org

LLVM libFuzzer

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.maltego.com

Maltego

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

learn.microsoft.com

Microsoft exploit protection reference

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

learn.microsoft.com

Microsoft Process Monitor

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

learn.microsoft.com

Microsoft Sysmon

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.misp-project.org

MISP

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

d3fend.mitre.org

MITRE D3FEND

Used in: CTI, Blue Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

eur-lex.europa.eu

NIS2

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

ocsf.io

OCSF

Used in: Blue Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

searchlibrary.ohchr.org

Berkeley Protocol

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.opencti.io

OpenCTI

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.scorecard.dev

OpenSSF Scorecard

Used in: Secure Code

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

opentelemetry.io

OpenTelemetry logs

Used in: Blue Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

osquery.io

osquery

Used in: DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

google.github.io

OSS-Fuzz

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

google.github.io

OSS-Fuzz getting started

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

genai.owasp.org

OWASP Agentic Security Initiative

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

genai.owasp.org

OWASP GenAI Security Project

Used in: AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

mas.owasp.org

OWASP MASVS

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

genai.owasp.org

OWASP Prompt Injection

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

genai.owasp.org

OWASP Top 10 for LLM Applications 2025

Used in: Secure Code, AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.pcisecuritystandards.org

PCI DSS v4.0.1 library

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

kubernetes.io

RBAC Good Practices

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.remnux.org

REMnux documentation

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

datatracker.ietf.org

RFC 3227

Used in: DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.shodan.io

Shodan

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

help.shodan.io

Shodan Help Center

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

help.shodan.io

Shodan query fundamentals

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

sigmahq.io

Sigma rule documentation

Used in: Blue Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

slsa.dev

SLSA 1.2

Used in: Secure Code

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

oasis-open.github.io

STIX / TAXII

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.first.org

Traffic Light Protocol (TLP)

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

clang.llvm.org

UBSan

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.urlscan.io

urlscan Documentation Hub

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.urlscan.io

urlscan Search API

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.urlscan.io

urlscan search semantics

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.velociraptor.app

Velociraptor

Used in: DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

verisframework.org

VERIS

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.virustotal.com

VirusTotal

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

docs.virustotal.com

VirusTotal relationship model

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

volatility3.readthedocs.io

Volatility 3 documentation

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

virustotal.github.io

YARA

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

yara.readthedocs.io

YARA 4.5 documentation

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

Framework

attack.mitre.org

ATT&CK detection strategies

Used in: Blue Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

attack.mitre.org

MITRE adversary-emulation plans

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

atlas.mitre.org

MITRE ATLAS

Used in: CTI, AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

attack.mitre.org

MITRE ATT&CK

Used in: CTI, Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

attack.mitre.org

MITRE ATT&CK Cloud Matrix

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

attack.mitre.org

MITRE ATT&CK Reconnaissance tactic

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

attack.mitre.org

MITRE ATT&CK Software

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

cwe.mitre.org

CWE

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

cwe.mitre.org

MITRE vulnerability theory

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

Government

www.cisa.gov

CISA BOD 23-01

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.cisa.gov

CISA KEV

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.cisa.gov

CISA logging guidance

Used in: Blue Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.nist.gov

CSF Quick Start Guides

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.nist.gov

NIST AI 600-1 GenAI Profile

Used in: AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

airc.nist.gov

NIST AI Resource Center

Used in: Blue Team, AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.nist.gov

NIST AI RMF

Used in: GRC, AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.nist.gov

NIST CSF 2.0

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.nist.gov

NIST CSF 2.0

Used in: Blue Team, DFIR, GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST OSCAL

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.nist.gov

NIST Privacy Framework

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-115

Used in: Red Team, OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-161 Rev. 1

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-190

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-207

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-216

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-218A

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

SP 800-30 Rev. 1

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

SP 800-37 Rev. 2

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

SP 800-53A Rev. 5

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-61r3

Used in: Blue Team, DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-83 Rev. 1

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SP 800-86

Used in: DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

NIST SSDF 1.1

Used in: Vulnerability R&D, Secure Code, GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

csrc.nist.gov

SP 800-207A

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

Source repository

github.com

AIDebug

Used in: Secure Code

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

Atomic Red Team

Used in: CTI

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

AuditAI

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

FileInfo project

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

FLARE Learning Hub

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

GitHub (opens in a new tab) ↗

Used in: CTI, Red Team, Blue Team, Vulnerability R&D, Malware Analysis, Secure Code, DFIR, Cloud Security, GRC, OSINT, AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

HexStrike repository

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

Malware Behavior Catalog

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

Mandiant capa

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

Mandiant FLARE-VM

Used in: Malware Analysis

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

MCP trust model

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

StratusAI

Used in: Cloud Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

String Analyzer source

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

Volatility 3 project

Used in: DFIR

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

github.com

Vulnerable APK source

Used in: Vulnerability R&D

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

Standard or framework

www.iso.org

ISO/IEC 23894 AI risk management

Used in: AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.iso.org

ISO/IEC 27000 family

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.iso.org

ISO/IEC 27001:2022

Used in: GRC

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

www.iso.org

ISO/IEC 42001 AI management systems

Used in: AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

owasp.org

OWASP Amass

Used in: OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

owasp.org

OWASP API Security Top 10:2023

Used in: Secure Code

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

owasp.org

OWASP ASVS

Used in: Red Team, Secure Code

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

owasp.org

OWASP LLMSVS

Used in: Secure Code, AI Security

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

owasp.org

OWASP TCASVS

Used in: Red Team

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

owasp.org

OWASP Top 10:2025

Used in: Secure Code

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.

owasp.org

OWASP WSTG

Used in: Red Team, OSINT

Referenced as of 2026-07-27. Use the destination’s own version and supersession notice for normative decisions.