This page contains links to couple of interesting training resources, tools and other material useful for Incident Response, Penetration Testing, Malware Analysis and other security-related areas. Although I’ve placed it here mainly for myself and students of my security courses, if you find it useful, it is also accessible through the easily remembered URL csirt.xyz. Bellow, you may find materials for the following areas: Security Monitoring and Incident Response Threat Hunting Penetration Testing and Red Teaming Purple Teaming Malware Analysis Application Security Miscellaneous Security Monitoring and Incident Response Standards and Best Practices ENISA Good Practice Guide for Incident Management NIST Computer Security Incident Handling Guide (SP 800-61r2) SIM3: Security Incident Management Maturity Model SOC-CMM Handbook for Computer Security Incident Response Teams (CSIRTs) Reference Security Incident Taxonomy (RSIT) (current version) FIRST CSIRT/PSIRT Services Framework MaGMa Use Case Framework Traffic Light Protocol (TLP) Incident Response Hierarchy of Needs Training Resources CSIRT Training Resources from ENISA Tutorials for Network Miner and Other Netresec Tools PCAP Files for Training - Netresec PCAP Files for Training - Malware Traffic Analysis PCAP Files for Training - Active Countermeasures FIRST Courses TRANSITS Materials Encyclopedia of evasion techniques Collections of Resources List of resources for SOC/CSIRT SANS Information Security Resources List of Security APIs from Alexander Jäger List of tools for PDF Analysis Tool Analysis Result Sheet TriOp - Tool for quickly gathering statistical information from Shodan.
I’ve added a new page to the site with links to miscelaneous tools and materials useful for Incident Response, Malware Analysis, Penetration Testing, etc. It may be accessed here or through the easily remembered URL http://csirt.xyz.