Resource Index
Search-friendly index of cyber security resource topics across blue team, red team, DFIR, OSINT, cloud, containers, AppSec, logging, privacy, and training.
This index points common search topics to their canonical page in the guide. It is intentionally high-level: detailed links and tool lists live on the section pages.
Blue Team and SOC
Blue team resources, SOC operations, defensive security, hardening, threat hunting: Blue - Defensive Operations
Detection engineering, SIEM rules, Sigma, Sysmon, IDS/IPS, detection use cases: Event Detection
Security query languages, KQL, Splunk SPL, Sigma, YARA-L, SIEM searches: Query Languages
Packet capture, PCAP analysis, Wireshark, Zeek, Suricata, network security monitoring: Packet Analysis
Vulnerability management, exposure management, code scanning, secret scanning: Asset and Vulnerability Management
Logging and Architecture
Security logging strategy, log collection, retention, log pipelines: Logging and Security Architecture
Endpoint logging, Windows Event Logs, Linux logs, Sysmon collection: Logging - Endpoint Logs
Cloud audit logs, AWS CloudTrail, Azure activity logs, Microsoft 365 audit, Google Cloud logging: Logging - Cloud
DNS logs, HTTP logs, SMTP logs, flow data, network service logs: Logging - Network Services
Asset inventory, device discovery, CMDB context, log source evaluation: Device Discovery and Asset Monitoring
DFIR and Malware Analysis
Incident response, DFIR tools, forensic triage, evidence collection: Blue - DFIR
Windows DFIR commands, Windows event logs, process analysis, remediation commands: Windows DFIR Checks
Linux DFIR commands, macOS DFIR commands, host investigation: Linux DFIR Commands and macOS DFIR Commands
Memory forensics, Volatility, process memory, injected code: Memory Forensics
Malware analysis, sandboxing, file analysis, YARA, reverse engineering: Malware
Cyber Intelligence and OSINT
Cyber threat intelligence, CTI, intelligence cycle, indicator enrichment: Cyber Intelligence
Threat feeds, blocklists, reputation sources, MISP, OpenCTI, TAXII/STIX: Intel Feeds and Sources
Threat data, hashes, URLs, domains, IP reputation, malware lookup: Threat Data
OSINT tools, search engines, domain investigation, username and email investigation: OSINT
Shodan, Censys, ZoomEye, FOFA, internet-exposed asset search: Cyber Search Engines
Offensive Security
Penetration testing, red team operations, offensive methodology: Red - Offensive Operations
Active reconnaissance, Nmap, vulnerability scanning, recon frameworks: Reconnaissance and Scanning
Exploitation, Metasploit, payloads, shells, exploit research: Exploitation and Targets
Post-exploitation, persistence, defense evasion, credential harvesting: Post Exploitation
Active Directory attacks, lateral movement, password attacks, C2 frameworks: Attacking Active Directory
Web Application Security
Web application hacking, AppSec testing, bug bounty methodology, OWASP testing: Web App Hacking
Burp Suite, Burp extensions, web proxy testing: Burp Suite
Web app scanners, content discovery, API testing utilities: Web App Scanning Utilities
OAuth, API security, TLS, certificates, WAF testing, web technologies: Web Technologies
SQL injection, XSS, CSRF, XXE, request smuggling, IDOR, host header attacks: Attacks and Vulnerabilities
Platform and Engineering Fundamentals
Cloud security, AWS, Azure, Google Cloud, Microsoft 365, cloud testing: Cloud
Docker, Kubernetes, container security, image scanning, runtime security: Containers
Networking, sysadmin, operating systems, Active Directory basics, protocols: Yellow - NetEng/SysAdmin
Bash, PowerShell, command line, regex, scripting, data transformation: Yellow - Code and CLI
AI, machine learning, FOSS alternatives, security research datasets: Yellow - AI, Machine Learning, and FOSS
Privacy, OPSEC, and Training
Privacy, Tor, PGP, anonymity, secure communication, OPSEC: Grey - Privacy/TOR/OPSEC
Cyber security training, courses, certifications, books, labs, CTF practice: Training and Resources
Awesome lists, massive security resource collections, curated GitHub lists: The Awesome Lists
Practice labs, home labs, vulnerable environments, CTF platforms: Practice Lab
Last updated