The Analyst's
Reference Hub

Practitioner-built reference material for security analysts, pentesters, SOC teams, and students. Organized across three disciplines - Offensive, Defensive, and Practitioner Reference. No paywalls. No signups. Updated regularly.

// Growing library  ยท  free forever  ยท  press / to search
โŒ•
๐Ÿ”ด Offensive
Red Team & Attack Techniques
4 resources
โ†—
[01] WEB SECURITY

Web App Pentest

OWASP Top 10, SQL injection, XSS, IDOR, SSRF, XXE, broken authentication, manual testing methodology, and professional toolset.

OWASP SQLi XSS IDOR SSRF Burp Suite
Coming Soon
[02] API SECURITY

API Security Testing

REST, GraphQL, and gRPC testing. OWASP API Top 10, authentication bypass, BOLA, mass assignment vulnerabilities.

Coming Soon
[03] BUG BOUNTY

Bug Bounty Methodology

Recon methodology, scope analysis, report writing, and tips for effective hunting on HackerOne and Bugcrowd.

Coming Soon
[04] RECON

OSINT Toolkit

Shodan, TheHarvester, Recon-ng, Amass, SpiderFoot, Maltego, and open source intelligence methodology.

๐Ÿ”ต Defensive
Blue Team & Security Operations
8 resources
โ†—
[05] LOG ANALYSIS

Log Analysis Guide

The lifeblood of security operations. Windows, Linux, web server, firewall, Zeek, authentication, and cloud log reference with detection patterns.

Windows Events Sysmon Zeek CloudTrail Nginx KQL
Coming Soon
[06] SOC OPERATIONS

SOC Playbook & Roles

Tier 1/2/3 roles and responsibilities, alert triage process, escalation workflows, shift handoff, and SOC metrics.

Coming Soon
[07] DFIR

Incident Response

IR phases, NIST and PICERL frameworks, containment strategies, and playbooks for ransomware, phishing, and BEC.

Coming Soon
[08] THREAT HUNTING

Threat Hunting

Open source threat hunting with ELK/Kibana KQL, Security Onion, Wireshark/PCAP, Sigma rules, and MITRE ATT&CK.

Coming Soon
[09] INTELLIGENCE

Cyber Threat Intelligence

CTI lifecycle, MISP, OpenCTI, ATT&CK Navigator, threat feeds, IOC management, and threat actor profiling.

Coming Soon
[10] MITRE

MITRE ATT&CK

Framework overview, tactic and technique reference, ATT&CK Navigator usage, and mapping detections to TTPs.

Coming Soon
[11] DETECTION

Detection Engineering

Detection lifecycle, Sigma rule writing, YARA rules, detection-as-code, alert tuning, and open source tooling.

โ†—
[12] EMAIL SECURITY

Phishing & Email Investigation

Email header analysis, SPF/DKIM/DMARC, phishing indicators, URL and attachment analysis, BEC red flags, and investigation workflow.

Email Headers SPF/DKIM DMARC BEC Phishing IOCs Sandboxing
๐Ÿ“š Reference
Practitioner Reference
8 resources
โ†—
[13] LINUX

Linux Commands

Essential Linux commands for security practitioners. File system, networking, processes, forensics, privilege escalation, and pentest essentials.

Bash Networking Forensics PrivEsc Pentest File System
โ†—
[14] PYTHON

Python for Cybersecurity

Log parsing, network scripting, OSINT automation, threat intel API integration, file analysis, cryptography, and reusable script templates.

Scripting Automation Scapy VirusTotal API Shodan IOC Extraction
Coming Soon
[15] WINDOWS

Windows Event IDs

Critical Security Event IDs, Sysmon events, PowerShell logging, authentication events, and detection use cases.

Coming Soon
[15] DFIR

Digital Forensics

Open source forensics tools, evidence acquisition, memory forensics, disk analysis, and forensic artifact locations.

Coming Soon
[16] NETWORK

Wireshark & PCAP

Capture and display filters, protocol analysis, malicious traffic patterns, and PCAP investigation workflow.

Coming Soon
[17] FRAMEWORK

Cyber Kill Chain

Lockheed Martin Kill Chain phases mapped to attacker TTPs, MITRE ATT&CK alignment, and defensive countermeasures.

Coming Soon
[18] VULNERABILITIES

CVEs & KEVs

CVE format, CVSS scoring, CISA Known Exploited Vulnerabilities catalog, and vulnerability prioritization methodology.

โ†—
[19] FULL SPECTRUM

Cyber Exercises

Tabletop exercises, purple team methodology, CTF platforms, practice lab environments, IR simulations, and CISA frameworks.

Tabletop Purple Team CTF HackTheBox TryHackMe CISA

Built by Practitioners, For Practitioners

These resources are maintained by the CMTA Cyber team and updated regularly. All content is written for real-world use. Coming Soon pages are actively being built. Suggest a topic or report an error by reaching out directly.

Suggest a Topic // New pages added regularly