<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" 
  xmlns:content="http://purl.org/rss/1.0/modules/content/" 
  xmlns:dc="http://purl.org/dc/elements/1.1/" 
  xmlns:atom="http://www.w3.org/2005/Atom" 
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
  xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>CSIRT on Untrusted Network</title>
    <link>https://untrustednetwork.net/en/category/csirt/</link>
    <description>Recent content in CSIRT on Untrusted Network</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>&amp;copy; Jan Kopriva 2015 - {year}</copyright>
    <lastBuildDate>Tue, 01 Jan 2019 11:28:23 +0100</lastBuildDate>
    <sy:updatePeriod>weekly</sy:updatePeriod>
    <sy:updateFrequency>weekly</sy:updateFrequency>
    
        <atom:link href="https://untrustednetwork.net/en/category/csirt/index.xml" rel="self" type="application/rss+xml" />
    
    
    

      
      <item>
        <title>Resources and Tools</title>
        <link>https://untrustednetwork.net/en/csirt/</link>
        <pubDate>Tue, 01 Jan 2019 11:28:23 +0100</pubDate>
        
        <atom:modified>Tue, 10 Feb 2026 16:00:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/csirt/</guid>
        <description>This page contains links to couple of interesting training resources, tools and other material useful for Incident Response, Penetration Testing, Malware Analysis and other security-related areas.
Although I&amp;rsquo;ve placed it here mainly for myself and students of my security courses, if you find it useful, it is also accessible through the easily remembered URL csirt.xyz.
Bellow, you may find materials for the following areas:
 Security Monitoring and Incident Response Threat Hunting Threat Intelligence Threat Modeling Penetration Testing and Red Teaming Purple Teaming Malware Analysis Application Security OT Security Miscellaneous  Security Monitoring and Incident Response  Standards and Best Practices  ENISA Good Practice Guide for Incident Management  NIST Computer Security Incident Handling Guide (SP 800-61r2) SIM3: Security Incident Management Maturity Model SOC-CMM Reference Security Incident Classification Taxonomy (current version) FIRST CSIRT/PSIRT Services Framework MaGMa Use Case Framework Traffic Light Protocol (TLP) Incident Response Hierarchy of Needs INTERPOL Guidelines for Digital Forensics First Responders NIST Guide to Integrating Forensic Techniques into Incident Response (NIST SP 800-86) CISA Cybersecurity Incident &amp;amp; Vulnerability Response Playbooks ENISA CSIRT Maturity Framework Google SOAR Maturity Model RFC 2350 - Expectations for Computer Security Incident Response Best practices for event logging and threat detection     Training Resources  Tutorials for Network Miner and Other Netresec Tools PCAP Files for Training - Malware Traffic Analysis FIRST Courses TRANSITS Materials Encyclopedia of evasion techniques STOic TTX Framework STOic TTX Facilitator Training Materials STOic TTX Facilitator Training Videos CISA Tabletop Exercise Packages (CTEP) ENISA Cybersecurity Exercise Methodology Blue Team CTF Challenges     Collections of Resources  Awesome Incident Response Awesome Security APIs Awesome Detection Engineering Awesome SOAR List Tool Analysis Result Sheet TriOp - Tool for quickly gathering statistical information from Shodan.</description>
        <content:encoded>&lt;p&gt;This page contains links to couple of interesting training resources, tools and other material useful for Incident Response, Penetration Testing, Malware Analysis and other security-related areas.&lt;/p&gt;
&lt;p&gt;Although I&amp;rsquo;ve placed it here mainly for myself and students of my security courses, if you find it useful, it is also accessible through the easily remembered URL &lt;a href=&#34;http://csirt.xyz/&#34;&gt;csirt.xyz&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Bellow, you may find materials for the following areas:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#monitoring_ir&#34;&gt;Security Monitoring and Incident Response&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#threat_hunting&#34;&gt;Threat Hunting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#threat_intelligence&#34;&gt;Threat Intelligence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#threat_modeling&#34;&gt;Threat Modeling&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#penetration_testing&#34;&gt;Penetration Testing and Red Teaming&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#purple_teaming&#34;&gt;Purple Teaming&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#malware_analysis&#34;&gt;Malware Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#application_security&#34;&gt;Application Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ot_security&#34;&gt;OT Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#misc&#34;&gt;Miscellaneous&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;monitoring_ir&#34;&gt;Security Monitoring and Incident Response&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Standards and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.enisa.europa.eu/publications/good-practice-guide-for-incident-management&#34;&gt;ENISA Good Practice Guide for Incident Management &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/NIST.SP.800-61r2.pdf&#34;&gt;NIST Computer Security Incident Handling Guide (SP 800-61r2)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://opencsirt.org/wp-content/uploads/2019/12/SIM3-mkXVIIIc.pdf&#34;&gt;SIM3: Security Incident Management Maturity Model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://soc-cmm.com/products/&#34;&gt;SOC-CMM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy&#34;&gt;Reference Security Incident Classification Taxonomy&lt;/a&gt; (&lt;a href=&#34;https://github.com/enisaeu/Reference-Security-Incident-Taxonomy-Task-Force/blob/master/working_copy/humanv1.md&#34;&gt;current version&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/education/service-framework&#34;&gt;FIRST CSIRT/PSIRT Services Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.betaalvereniging.nl/wp-content/uploads/FI-ISAC-Use-Case-Framework-Full-Documentation.pdf&#34;&gt;MaGMa Use Case Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/tlp/&#34;&gt;Traffic Light Protocol (TLP)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/swannman/ircapabilities&#34;&gt;Incident Response Hierarchy of Needs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.interpol.int/content/download/16243/file/Guidelines%20to%20Digital%20Forensics%20First%20Responders_V7.pdf?inLanguage=eng-GB&#34;&gt;INTERPOL Guidelines for Digital Forensics First Responders&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-86.pdf&#34;&gt;NIST Guide to Integrating Forensic Techniques into Incident Response (NIST SP 800-86)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cisa.gov/sites/default/files/publications/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf&#34;&gt;CISA Cybersecurity Incident &amp;amp; Vulnerability Response Playbooks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.enisa.europa.eu/publications/enisa-csirt-maturity-framework&#34;&gt;ENISA CSIRT Maturity Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://go.chronicle.security/hubfs/SOAR_Maturity_Model.pdf&#34;&gt;Google SOAR Maturity Model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://datatracker.ietf.org/doc/html/rfc2350&#34;&gt;RFC 2350 - Expectations for Computer Security Incident Response&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cyber.gov.au/sites/default/files/2024-08/best-practices-for-event-logging-and-threat-detection.pdf&#34;&gt;Best practices for event logging and threat detection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.netresec.com/?page=Resources&#34;&gt;Tutorials for Network Miner and Other Netresec Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.malware-traffic-analysis.net/&#34;&gt;PCAP Files for Training - Malware Traffic Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/education/trainings&#34;&gt;FIRST Courses&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://tf-csirt.org/transits/materials/&#34;&gt;TRANSITS Materials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://evasions.checkpoint.com/&#34;&gt;Encyclopedia of evasion techniques&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/stoic_ttx-framework.pdf&#34;&gt;STOic TTX Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/stoic_ttx-training.pdf&#34;&gt;STOic TTX Facilitator Training Materials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cyberscotland.com/stoic-ttx-facilitator-training-series/&#34;&gt;STOic TTX Facilitator Training Videos&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages&#34;&gt;CISA Tabletop Exercise Packages (CTEP)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.enisa.europa.eu/publications/the-enisa-cybersecurity-exercise-methodology&#34;&gt;ENISA Cybersecurity Exercise Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cyberdefenders.org/blueteam-ctf-challenges/&#34;&gt;Blue Team CTF Challenges&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/meirwah/awesome-incident-response&#34;&gt;Awesome Incident Response&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/deralexxx/security-apis&#34;&gt;Awesome Security APIs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/infosecB/awesome-detection-engineering&#34;&gt;Awesome Detection Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/correlatedsecurity/Awesome-SOAR&#34;&gt;Awesome SOAR List&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://jpcertcc.github.io/ToolAnalysisResultSheet/&#34;&gt;Tool Analysis Result Sheet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/en/triop/&#34;&gt;TriOp - Tool for quickly gathering statistical information from Shodan.io&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://gchq.github.io/CyberChef/&#34;&gt;CyberChef&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/tools/sift-workstation&#34;&gt;SIFT - SANS Forensic VM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/Neo23x0/sigma&#34;&gt;Sigma - Generic Signature Format for SIEM Systems&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://uncoder.io/&#34;&gt;Uncoder.IO: Universal Sigma Rule Converter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://sigconverter.io/&#34;&gt;sigconverter.io&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape&#34;&gt;KAPE - Kroll Artifact Parser and Extractor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/davehull/Kansa&#34;&gt;Kansa&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/mitre-attack/attack-navigator&#34;&gt;MITRE ATT&amp;amp;CK Navigator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/rabobank-cdc/DeTTECT&#34;&gt;DeTT&amp;amp;CT - Detect Tactics, Techniques &amp;amp; Combat Threats&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://virustotal.github.io/yara/&#34;&gt;YARA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.netresec.com/?page=Networkminer&#34;&gt;Network Miner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.netresec.com/?page=PolarProxy&#34;&gt;PolarProxy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://osquery.io/&#34;&gt;osquery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://docs.velociraptor.app/&#34;&gt;Velociraptor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://wazuh.com/&#34;&gt;Wazuh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://arkime.com/&#34;&gt;Arkime&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://zeek.org/&#34;&gt;Zeek&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/idaholab/Malcolm&#34;&gt;Malcolm&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://suricata.io/&#34;&gt;Suricata&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/Security-Onion-Solutions/securityonion/&#34;&gt;Security Onion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/salesforce/jarm&#34;&gt;JARM&lt;/a&gt;/&lt;a href=&#34;https://github.com/salesforce/ja3&#34;&gt;JA3/JA3S&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/FoxIO-LLC/ja4&#34;&gt;JA4+ Network Fingerprinting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/markbaggett/freq&#34;&gt;freq&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/fox-it/dissect&#34;&gt;Dissect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://what2log.com/&#34;&gt;What2Log&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/cisagov/LME&#34;&gt;Logging Made Easy (LME)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/sans-blue-team/DeepBlueCLI&#34;&gt;DeepBlueCLI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/Lookyloo/lookyloo&#34;&gt;Lookyloo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://dfir-iris.org/&#34;&gt;IRIS - Open-Source Collaborative Incident Response Platform&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://timesketch.org/&#34;&gt;Timesketch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://script-ed.org/wp-content/uploads/2016/12/13-3-cormack.pdf?d=10012020&#34;&gt;Incident Response: Protecting Individual Rights Under the General Data Protection Regulation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://script-ed.org/wp-content/uploads/2020/08/cormack.pdf?d=10012020&#34;&gt;Processing Data to Protect Data: Resolving the Breach Detection Paradox&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://script-ed.org/article/nisd2-a-common-framework-for-information-sharing-among-network-defenders/&#34;&gt;NISD2: A Common Framework for Information Sharing Among Network Defenders&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/mattnotmax/cyberchef-recipes&#34;&gt;CyberChef Recipes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://atc-project.github.io/atc-react/&#34;&gt;RE&amp;amp;CT Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/resources/papers/conf2019/Public__SOC-Metrics-for-FIRST-v07-002-.pdf&#34;&gt;Practical SOC Metrics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.soc-cmm.com/products/metrics/&#34;&gt;SOC-CMM Metrics Suite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/global/sigs/metrics/metrics_csirt_services_framework&#34;&gt;Metrics for the Computer Security Incident Response Team (CSIRT) Services Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.mitre.org/publications/technical-papers/11-strategies-world-class-cybersecurity-operations-center&#34;&gt;11 Strategies of a World-Class Cybersecurity Operations Center&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://gitlab.com/syntax-ir/playbooks&#34;&gt;Incident Response Public Playbooks and Structure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.crest-approved.org/buying-building-cyber-services/cyber-security-incident-response-maturity-assessment/&#34;&gt;CREST Cyber Security Incident Response Maturity Assessment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.vanimpe.eu/2020/12/28/how-to-support-defenders-with-the-permissible-actions-protocol/&#34;&gt;Permissible Actions Protocol (PAP)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#bkmk-appendixa&#34;&gt;Minimum recommended audit policy for Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/strategies-mitigate-cyber-security-incidents&#34;&gt;ASD Strategies to Mitigate Cyber Security Incidents&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/tsale/EDR-Telemetry&#34;&gt;EDR Telemetry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://odef.wiki/&#34;&gt;Open Detection Engineering Framework (ODEF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://ipurple.team/2024/02/21/detection-rules-development-framework/&#34;&gt;Detection Rules Development Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/posters/guide-to-security-operations/&#34;&gt;SANS Guide to Security Operations&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;threat_hunting&#34;&gt;Threat Hunting&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Methodologies and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.threathunting.net/files/hunt-evil-practical-guide-threat-hunting.pdf&#34;&gt;Hunt Evil: Your Practical Guide to Threat Hunting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://medium.com/@sqrrldata/the-cyber-hunting-maturity-model-6d506faa8ad5&#34;&gt;Sqrrl Cyber Hunting Maturity Model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cyberedgegroup.com/wp-content/uploads/2021/02/Endgames-Guide-to-Threat-Hunting.pdf&#34;&gt;The Endgame Guide to Threat Hunting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.betaalvereniging.nl/wp-content/uploads/DEF-TaHiTI-Threat-Hunting-Methodology.pdf&#34;&gt;TaHiTI Threat Hunting Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://mitre.org/publications/technical-papers/ttp-based-hunting&#34;&gt;TTP-Based hunting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.splunk.com/en_us/blog/security/peak-threat-hunting-framework.html&#34;&gt;PEAK Threat Hunting Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.splunk.com/en_us/pdfs/gated/ebooks/threat-hunters-cookbook.pdf&#34;&gt;The Threat Hunter&amp;rsquo;s Cookbook&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://threathunterplaybook.com/&#34;&gt;Threat Hunter Project&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.threathunting.net/&#34;&gt;The ThreatHunting Project&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://securitydatasets.com/&#34;&gt;Security Datasets Project (Mordor)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/mthcht/awesome-lists&#34;&gt;Security lists for SOC/DFIR detections&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.activecountermeasures.com/hunt-training/&#34;&gt;Active Countermeasures Threat Hunt Training Course&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/reading-room/whitepapers/threats/generating-hypotheses-successful-threat-hunting-37172&#34;&gt;Generating Hypotheses for Successful Threat Hunting&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;threat_intelligence&#34;&gt;Threat Intelligence&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Methodologies and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.enisa.europa.eu/publications/enisa-cybersecurity-threat-landscape-methodology&#34;&gt;ENISA Threat Landscape Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://csrc.nist.gov/publications/detail/sp/800-150/final&#34;&gt;NIST Guide to Cyber Threat Information Sharing (SP 800-150)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.dni.gov/files/documents/ICD/ICD-203.pdf&#34;&gt;Intelligence Community Directive 203: Analytic Standards&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.x-isac.org/publication.html&#34;&gt;X-ISAC Guidelines to setting up an information sharing community&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/global/sigs/cti/curriculum/&#34;&gt;FIRST Cyber Threat Intelligence Curriculum&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://medium.com/katies-five-cents/a-cyber-threat-intelligence-self-study-plan-part-1-968b5a8daf9a&#34;&gt;A Cyber Threat Intelligence Self-Study Plan: Part 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://medium.com/katies-five-cents/a-cyber-threat-intelligence-self-study-plan-part-2-d04b7a529d36&#34;&gt;A Cyber Threat Intelligence Self-Study Plan: Part 2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://apt.threattracking.com/&#34;&gt;APT Groups and Operations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/reading-room/whitepapers/threatintelligence/quantifying-threat-actor-assessments-39585&#34;&gt;Quantifying Threat Actor Assessments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.ialeia.org/docs/Psychology_of_Intelligence_Analysis.pdf&#34;&gt;Psychology of Intelligence Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.crest-approved.org/cyber-threat-intelligence-maturity-assessment-tools/&#34;&gt;CREST Cyber Threat Intelligence Maturity Assessment Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.ransomware.live/&#34;&gt;Recent ransomware victims&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.ransomlook.io/recent&#34;&gt;Recent ransomware attacks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;threat_modeling&#34;&gt;Threat Modeling&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Methodologies and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.schneier.com/academic/archives/1999/12/attack_trees.html&#34;&gt;Attack Trees&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/DREAD_(risk_assessment_model)&#34;&gt;DREAD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.linddun.org/&#34;&gt;LINDDUN&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://resources.sei.cmu.edu/library/asset-view.cfm?assetID=309051&#34;&gt;OCTAVE &amp;amp; OCTAVE-Related Assets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://versprite.com/blog/what-is-pasta-threat-modeling/&#34;&gt;PASTA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.microsoft.com/security/blog/2007/09/11/stride-chart/&#34;&gt;STRIDE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/CARVER_matrix&#34;&gt;CARVER&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://trike.sourceforge.net/&#34;&gt;Trike&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://threatmodeler.com/threat-modeling-methodologies-vast/&#34;&gt;VAST&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://emb3d.mitre.org/&#34;&gt;MITRE EMB3D Threat Model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://csrc.nist.gov/csrc/media/publications/sp/800-154/draft/documents/sp800_154_draft.pdf&#34;&gt;NIST Guide to Data-Centric System Threat Modeling (SP 800-154)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/2022/TF-CSIRT-09-2022-Threat_modeling.pdf&#34;&gt;Threat modeling in Security Operations using MITRE ATT&amp;amp;CK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://web.archive.org/web/20220119191327/https://www.mitre.org/publications/systems-engineering-guide/enterprise-engineering/systems-engineering-for-mission-assurance/crown-jewels-analysis&#34;&gt;Crown Jewels Analysis&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://docs.microsoft.com/en-us/azure/security/develop/threat-modeling-tool&#34;&gt;Microsoft Threat Modeling Tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-threat-dragon/&#34;&gt;OWASP Threat Dragon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cairis.org/&#34;&gt;Computer Aided Integration of Requirements and Information Security (CAIRIS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://online.visual-paradigm.com/diagrams/features/threat-modeling-tool/&#34;&gt;Visual Paradigm Online Threat Modeling Toool&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://shellsharks.com/threat-modeling&#34;&gt;A Threat Modeling Field Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/TalEliyahu/Threat_Model_Examples&#34;&gt;Threat Model Examples&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.threatmodelingmanifesto.org/&#34;&gt;Threat Modeling Manifesto&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://insights.sei.cmu.edu/sei_blog/2018/12/threat-modeling-12-available-methods.html&#34;&gt;Threat Modeling: 12 Available Methods&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.mitre.org/sites/default/files/2021-11/prs-18-1174-ngci-cyber-threat-modeling.pdf&#34;&gt;Cyber Threat Modeling: Survey, Assessment, and Representative Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Threat-Driven-Approach.pdf&#34;&gt;A Threat-Driven Approach to Cyber Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html&#34;&gt;OWASP Threat Modeling Cheat Sheet&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;penetration_testing&#34;&gt;Penetration Testing and Red Teaming&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Methodologies and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/OWASP/wstg/releases/download/v4.2/wstg-v4.2.pdf&#34;&gt;OWASP Web Security Testing Guide (WSTG) v4.2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.isecom.org/OSSTMM.3.pdf&#34;&gt;Open Source Security Testing Methodology Manual (OSSTMM) v3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/osstmm.en.2.1.pdf&#34;&gt;Open Source Security Testing Methodology Manual (OSSTMM) v2.1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/issaf0.2.1.pdf&#34;&gt;Information Systems Security Assessment Framework (ISSAF) v0.2.1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.pentest-standard.org/index.php/Main_Page&#34;&gt;Penetration Testing Execution Standard (PTES)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/NIST.SP.800-115.pdf&#34;&gt;NIST Technical Guide to Information Security Testing and Assessment (SP 800-115)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/cvss/&#34;&gt;CVSS - Common Vulnerability Scoring System&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.fedramp.gov/assets/resources/documents/CSP_Penetration_Test_Guidance.pdf&#34;&gt;FedRAMP Penetration Test Guidance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.crest-approved.org/wp-content/uploads/2022/04/CREST-Penetration-Testing-Guide-1.pdf&#34;&gt;CREST - A guide for running an effective Penetration Testing programme&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.gfma.org/wp-content/uploads/0/83/197/231/fff190cf-305a-44a6-a429-39848f22a48b.pdf&#34;&gt;GFMA Framework for the Regulatory Use of Penetration Testing in the Financial Services Industry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html&#34;&gt;TIBER-EU Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://smartgrid.epri.com/doc/NESCORGuidetoPenetrationTestingforElectricUtilities-v3-Final.pdf&#34;&gt;NESCOR Guide to Penetration Testing for Electric Utilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cyberark.com/resources/threat-research-blog/thick-client-penetration-testing-methodology&#34;&gt;CyberArk Thick Client Penetration Testing Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.iso.org/standard/72889.html&#34;&gt;ISO/IEC 18045:2022 - Evaluation criteria for IT security — Methodology for IT security evaluation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.blackhat.com/presentations/bh-europe-05/BH_EU_05-Long.pdf&#34;&gt;Google Hacking for Penetration Testers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://portswigger.net/web-security&#34;&gt;PortSwigger WebSecurity Academy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://university.apisec.ai/&#34;&gt;API Security University&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/swisskyrepo/PayloadsAllTheThings&#34;&gt;PayloadsAllTheThings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/enaqx/awesome-pentest&#34;&gt;Awesome Penetration Testing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://posts.specterops.io/kerberosity-killed-the-domain-an-offensive-kerberos-overview-eb04b1402c61?gi=792386eee43b&#34;&gt;Kerberosity Killed the Domain: An Offensive Kerberos Overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://lolbas-project.github.io/&#34;&gt;LOLBAS - Living Off The Land Binaries, Scripts and Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://gtfobins.github.io/&#34;&gt;GTFOBins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://lolrmm.io/&#34;&gt;LOLRMM - Living Off The Land Remote Monitoring and Management&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://weibell.github.io/reverse-shell-generator/&#34;&gt;Reverse Shell Generator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://nmap.org/&#34;&gt;Nmap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/BC-SECURITY/Empire&#34;&gt;Empire&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/SpecterOps/BloodHound&#34;&gt;BloodHound&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/fortra/impacket&#34;&gt;Impacket&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://howto.thec2matrix.com/&#34;&gt;The C2 Matrix&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;purple_teaming&#34;&gt;Purple Teaming&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Methodologies and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/scythe-io/purple-team-exercise-framework&#34;&gt;Purple Team Exercise Framework (PTEF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.scythe.io/library/introducing-the-purple-team-maturity-model&#34;&gt;Purple Team Maturity Model&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/redcanaryco/atomic-red-team&#34;&gt;Atomic Red Team&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://caldera.mitre.org/&#34;&gt;MITRE Caldera&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.akamai.com/infectionmonkey&#34;&gt;Infection Monkey&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/SecurityRiskAdvisors/VECTR&#34;&gt;VECTR&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/alphasoc/flightsim&#34;&gt;Network Flight Simulator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/vectra-ai-research/MAAD-AF&#34;&gt;MAAD-AF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/ch33r10/EnterprisePurpleTeaming&#34;&gt;Enterprise Purple Teaming&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/center-for-threat-informed-defense/adversary_emulation_library&#34;&gt;CTID Adversary Emulation Library&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;malware_analysis&#34;&gt;Malware Analysis&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://malwareunicorn.org/#/workshops&#34;&gt;Malware Unicorn Workshops&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/hasherezade/malware_training_vol1&#34;&gt;Haseherezade Malware Training vol. 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://class.malware.re/&#34;&gt;Introduction to Malware Analysis and Reverse Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://untrustednetwork.net/files/russinovich-malware-hunting-with-the-sysinternals-tools.pdf&#34;&gt;Malware Hunting with the Sysinternals Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/jstrosch/learning-reverse-engineering&#34;&gt;Learning Reverse Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/NationalSecurityAgency/ghidra/tree/master/GhidraDocs/GhidraClass&#34;&gt;Ghidra Class&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/rshipp/awesome-malware-analysis&#34;&gt;Awesome Malware Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/fr0gger/awesome-ida-x64-olly-plugin/blob/master/README.md&#34;&gt;Awesome IDA, Ghidra, x64DBG, GDB &amp;amp; OllyDBG plugins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/0x4143/malware-gems/blob/master/README.md&#34;&gt;malware-gems&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.untrustednetwork.net/en/sandboxes/&#34;&gt;Overview of free online malware analysis sandboxes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/Obfuscator-Collections/&#34;&gt;Obfuscator Collections&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Sample sources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/ytisf/theZoo&#34;&gt;theZoo - A Live Malware Repository&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/jstrosch/malware-samples&#34;&gt;Malware Samples&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://zeltser.com/malware-sample-sources/&#34;&gt;Malware Sample Sources for Researchers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://bazaar.abuse.ch/&#34;&gt;MalwareBazaar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/vxunderground/MalwareSourceCode&#34;&gt;vx-underground Malware Source Code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.vx-underground.org/malware.html&#34;&gt;vx-underground Malware Collections&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/fireeye/flare-vm&#34;&gt;Flare VM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://remnux.org/&#34;&gt;REMnux: A Linux Toolkit for Malware Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://docs.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite&#34;&gt;Sysinternals Suite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://blog.didierstevens.com/didier-stevens-suite/&#34;&gt;Didier Stevens Suite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.winitor.com/download&#34;&gt;pestudio&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/cert-ee/cuckoo3&#34;&gt;Cuckoo3 Sandbox&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/kevoreilly/CAPEv2&#34;&gt;CAPE: Malware Configuration And Payload Extraction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/CERT-Polska/drakvuf-sandbox&#34;&gt;DRAKVUF Sandbox&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/NationalSecurityAgency/ghidra&#34;&gt;Ghidra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://malcat.fr/&#34;&gt;Malcat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://hash.cymru.com/&#34;&gt;Malware Hash Registry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/MobSF/Mobile-Security-Framework-MobSF&#34;&gt;Mobile Security Framework (MobSF)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.elastic.co/blog/ten-process-injection-techniques-technical-survey-common-and-trending-process&#34;&gt;Ten process injection techniques: A technical survey of common and trending process injection techniques&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.winitor.com/pdf/Malware-Analysis-Fundamentals-Files-Tools.pdf&#34;&gt;Malware Analysis Fundamentals - Files &amp;amp; Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://malpedia.caad.fkie.fraunhofer.de/&#34;&gt;Malpedia&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://unprotect.it/&#34;&gt;Unprotect Project&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;application_security&#34;&gt;Application Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Standards and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://ieeecs-media.computer.org/media/technical-activities/CYBSI/docs/Top-10-Flaws.pdf&#34;&gt;Avoiding the Top 10 Software Security Design Flaws&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.microsoft.com/en-us/securityengineering/sdl/practices&#34;&gt;Microsoft Security Development Lifecycle Practices&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://csrc.nist.gov/projects/ssdf&#34;&gt;NIST Secure Software Development Framework (SSDF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1r1.pdf&#34;&gt;NIST Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems (SP 800-160 Vol. 1)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2r1.pdf&#34;&gt;NIST Developing Cyber-Resilient Systems: A Systems Security Engineering Approach (SP 800-160 Vol. 2)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://csrc.nist.gov/pubs/sp/800/190/final&#34;&gt;NIST Application Container Security Guide (SP 800-190)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.iso.org/standard/44716.html&#34;&gt;ISO/IEC 21827:2008 - Systems Security Engineering — Capability Maturity Model (SSE-CMM)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-application-security-verification-standard/&#34;&gt;OWASP Application Security Verification Standard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owaspsamm.org/&#34;&gt;OWASP SAMM - Software Assurance Maturity Model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-developer-guide/&#34;&gt;OWASP Developer Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-mobile-security-testing-guide/&#34;&gt;OWASP Mobile Security Project&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-code-review-guide/&#34;&gt;OWASP Code Review Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/Top10/&#34;&gt;OWASP Top 10&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-top-10-ci-cd-security-risks/&#34;&gt;OWASP Top 10 CI/CD Security Risks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-api-security/&#34;&gt;OWASP API Security Top 10&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://owasp.org/www-project-devsecops-maturity-model/&#34;&gt;OWASP DSOMM - DevSecOps Maturity Model&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://resources.sei.cmu.edu/asset_files/TechnicalReport/2009_005_001_15110.pdf&#34;&gt;SEI Secure Design Patterns&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://wiki.sei.cmu.edu/confluence/display/seccode/Top+10+Secure+Coding+Practices&#34;&gt;SEI Top 10 Secure Coding Practices&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.practical-devsecops.com/devsecops-university/&#34;&gt;DevSecOps University&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/sottlmarek/DevSecOps&#34;&gt;Ultimate DevSecOps Library&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/analysis-tools-dev&#34;&gt;Analysis Tools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cisa.gov/sbom&#34;&gt;CISA Software Bill of Materials (SBOM)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cyclonedx.org/&#34;&gt;OWASP CycloneDX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://spdx.dev/specifications/#current-version&#34;&gt;Software Package Data Exchange (SPDX)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cwe.mitre.org/top25/&#34;&gt;CWE Top 25 Most Dangerous Software Weaknesses&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#threat_modeling&#34;&gt;Threat Modeling Resources&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;ot_security&#34;&gt;OT Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Standards and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf&#34;&gt;NIST Guide to Operational Technology (OT) Security (SP 800-82 Rev. 3)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.pera.net/&#34;&gt;Purdue Enterprise Reference Architecture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/white-papers/five-ics-cybersecurity-critical-controls/&#34;&gt;SANS Five ICS Cybersecurity Critical Controls&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.28.pdf&#34;&gt;NIST Cybersecurity White Paper - Security Segmentation in a Small Manufacturing Environment (CSWP 28)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://apps.dtic.mil/sti/citations/AD1056116&#34;&gt;Advanced Cyber Industrial Control System Tactics, Techniques, and Procedures (ACI TTP) for Department of Defense (DOD) Industrial Control Systems (ICS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.iiconsortium.org/wp-content/uploads/sites/2/2023/06/IISF-Version-2.pdf&#34;&gt;Industrial Internet of Things Security Framework (IISF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.mitre.org/news-insights/publication/crown-jewels-analysis-industrial-control-systems&#34;&gt;Crown Jewels Analysis (CJA) for Industrial Control Systems (ICS)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cisa.gov/ics-training-available-through-cisa&#34;&gt;ICS Training Available Through CISA&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Collections of Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.robertmlee.org/a-collection-of-resources-for-getting-started-in-icsscada-cybersecurity/&#34;&gt;A Collection of Resources for Getting Started in ICS/SCADA Cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/hslatman/awesome-industrial-control-system-security&#34;&gt;Awesome Industrial Control System Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.controlthings.io/platform&#34;&gt;ControlThings Platform&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/mitre/caldera-ot&#34;&gt;Caldera for OT Plugins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/nsacyber/GRASSMARLIN&#34;&gt;GRASSMARLIN&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Misc
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/cisagov/ICSNPP&#34;&gt;CISA Industrial Control Systems Network Protocol Parsers (ICSNPP) for Zeek&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://drive.google.com/file/d/1_22MtEjveuv-Apl2ghQrfR5TaSnSPJAG/view?usp=drive_web&#34;&gt;Scanning Higly Sensitive Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cisa.gov/sites/default/files/2023-01/Procurement_Language_Rev4_100809_S508C.pdf&#34;&gt;Cyber Security Procurement Language for Control Systems&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://literature.rockwellautomation.com/idc/groups/literature/documents/td/enet-td001_-en-p.pdf&#34;&gt;Converged Plantwide Ethernet (CPwE) Design and Implementation Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://gca.isa.org/hubfs/ISAGCA%20Quick%20Start%20Guide%20FINAL.pdf&#34;&gt;Quick Start Guide: An Overview of ISA/IEC 62443 Standards&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://f.hubspotusercontent10.net/hubfs/5382318/Applying%20ISO%20IEC%2027001%202%20and%20the%20ISA%20IEC%2062443%20Series%20White%20Paper.pdf&#34;&gt;Applying ISO/IEC 27001/2 and the ISA/IEC 62443 Series for Operational Technology Environments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.namur.net/fileadmin/media_www/Dokumente/AK-PRAXIS_4.18_NA163_Checkliste_EN_2017_12_15.xlsx&#34;&gt;NAMUR Checklist for Risk Assessment of Safety Industrial Systems (AK-PRAXIS 4.18: NA163 Checklist)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.ferc.gov/sites/default/files/2020-04/E-2_11.pdf&#34;&gt;FERC Order 706&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/mlp/ics-field-manual&#34;&gt;SANS ICS Cybersecurity Field Manual&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://isagca.org/hubfs/2023 ISA Website Redesigns/ISAGCA/PDFs/Industrial Cybersecurity Knowledge FINAL.pdf&#34;&gt;CURRICULAR GUIDANCE: Industrial Cybersecurity Knowledge&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h2 id=&#34;misc&#34;&gt;Miscellaneuos&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Standards and Best Practices
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://learn.cisecurity.org/control-download-v8-1&#34;&gt;CIS Critical Security Controls&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://learn.cisecurity.org/cis-ram-2-download&#34;&gt;CIS Risk Assessment Method (RAM)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.etsi.org/deliver/etsi_ts/103300_103399/10330501/05.01.01_60/ts_10330501v050101p.pdf&#34;&gt;ETSI TR 103 305-1: Critical Security Controls for Effective Cyber Defence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.nist.gov/cyberframework&#34;&gt;NIST Cybersecurity Framework (CSF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final&#34;&gt;NIST Guide for Conducting Risk Assessments (SP 800-30r1)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-137.pdf&#34;&gt;NIST Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations (SP 800-137)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-137A.pdf&#34;&gt;NIST Assessing Information Security Continuous Monitoring (ISCM) Programs:Developing an ISCM Program Assessment (SP 800-137A)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://csrc.nist.gov/pubs/ir/8212/final&#34;&gt;NIST ISCMA: An Information Security Continuous Monitoring Program Assessment (IR 8212)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final&#34;&gt;NIST Risk Management Framework for Information Systems and Organizations (SP 800-37r2)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.enisa.europa.eu/publications/european-cybersecurity-skills-framework-role-profiles&#34;&gt;European Cybersecurity Skills Framework Role Profiles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center/current-version&#34;&gt;NICE Framework Resource Center&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.ncsc.gov.uk/collection/cyber-assessment-framework&#34;&gt;NCSC Cyber Assessment Framework (CAF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.rfc-editor.org/rfc/rfc9116&#34;&gt;RFC 9116 - A File Format to Aid in Security Vulnerability Disclosure&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Training Resources
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://unit42.paloaltonetworks.com/wireshark-workshop-videos/&#34;&gt;Wireshark Tutorial&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://security.geant.org/training/&#34;&gt;Géant Security Training&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cybrary.it/&#34;&gt;Cybrary.it - Security Training Videos&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.isc2.org/1mcc&#34;&gt;Free ISC2 Certified in Cybersecurity Course and Certification&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Tools
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/cisagov/cset&#34;&gt;Cyber Security Evaluation Tool (CSET)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;ul&gt;
&lt;li&gt;Other
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://attack.mitre.org/&#34;&gt;MITRE ATT&amp;amp;CK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://d3fend.mitre.org/&#34;&gt;MITRE D3FEND&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://academic.oup.com/cybersecurity/article-pdf/6/1/tyaa009/33746006/tyaa009.pdf&#34;&gt;Categorizing human phishing difficulty: a PhishScale&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.hexacorn.com/blog/&#34;&gt;Hexacorn Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://posts.specterops.io/bloodhound-versus-ransomware-a-defenders-guide-28147dedb73b&#34;&gt;BloodHound versus Ransomware: A Defender’s Guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://rootdse.org/posts/active-directory-basics-1/&#34;&gt;Active Directory Fundamentals&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://ioda.inetintel.cc.gatech.edu/&#34;&gt;Internet Outage Detection and Analysis (IODA)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/n0x08/ShodanTools&#34;&gt;ShodanTools - Collection of scripts &amp;amp; fingerprinting tricks for Shodan.io&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.auditscripts.com/free-resources/collective-risk-project/&#34;&gt;AuditScripts Collective Risk Project&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.enisa.europa.eu/publications/interoperable-eu-risk-management-framework&#34;&gt;ENISA - Interoperable EU Risk Management Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4/&#34;&gt;Cloud Controls Matrix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/posters/key-metrics-cloud-enterprise-vmmm/&#34;&gt;SANS Vulnerability Management Maturity Model (VMMM)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.sans.org/blog/vmmm-self-assessment-tool/&#34;&gt;Vulnerability Management Maturity Model – Self-Assessment Tool (VMMM-SAT)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.first.org/epss/&#34;&gt;FIRST Exploit Prediction Scoring System (EPSS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://oasis-open.github.io/csaf-documentation/&#34;&gt;OASIS Common Security Advisory Framework (CSAF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2&#34;&gt;Cybersecurity Capability Maturity Model (C2M2)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://inl.gov/cie/&#34;&gt;Cyber-Informed Engineering (CIE)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-50r1.pdf&#34;&gt;NIST Building a Cybersecurity and Privacy Learning Program (SP 800-50r1)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/nmantani/archiver-MOTW-support-comparison&#34;&gt;Archiver MOTW Support Comparison&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>Tools</category>
            
          
        
        
          
            
              <category>CSIRT</category>
            
          
        
        
      </item>
      

    
  </channel>
</rss>