Practitioner-built reference material for security analysts, pentesters, SOC teams, and students. Organized across three disciplines - Offensive, Defensive, and Practitioner Reference. No paywalls. No signups. Updated regularly.
OWASP Top 10, SQL injection, XSS, IDOR, SSRF, XXE, broken authentication, manual testing methodology, and professional toolset.
REST, GraphQL, and gRPC testing. OWASP API Top 10, authentication bypass, BOLA, mass assignment vulnerabilities.
Recon methodology, scope analysis, report writing, and tips for effective hunting on HackerOne and Bugcrowd.
Shodan, TheHarvester, Recon-ng, Amass, SpiderFoot, Maltego, and open source intelligence methodology.
The lifeblood of security operations. Windows, Linux, web server, firewall, Zeek, authentication, and cloud log reference with detection patterns.
Tier 1/2/3 roles and responsibilities, alert triage process, escalation workflows, shift handoff, and SOC metrics.
IR phases, NIST and PICERL frameworks, containment strategies, and playbooks for ransomware, phishing, and BEC.
Open source threat hunting with ELK/Kibana KQL, Security Onion, Wireshark/PCAP, Sigma rules, and MITRE ATT&CK.
CTI lifecycle, MISP, OpenCTI, ATT&CK Navigator, threat feeds, IOC management, and threat actor profiling.
Framework overview, tactic and technique reference, ATT&CK Navigator usage, and mapping detections to TTPs.
Detection lifecycle, Sigma rule writing, YARA rules, detection-as-code, alert tuning, and open source tooling.
Email header analysis, SPF/DKIM/DMARC, phishing indicators, URL and attachment analysis, BEC red flags, and investigation workflow.
Essential Linux commands for security practitioners. File system, networking, processes, forensics, privilege escalation, and pentest essentials.
Log parsing, network scripting, OSINT automation, threat intel API integration, file analysis, cryptography, and reusable script templates.
Critical Security Event IDs, Sysmon events, PowerShell logging, authentication events, and detection use cases.
Open source forensics tools, evidence acquisition, memory forensics, disk analysis, and forensic artifact locations.
Capture and display filters, protocol analysis, malicious traffic patterns, and PCAP investigation workflow.
Lockheed Martin Kill Chain phases mapped to attacker TTPs, MITRE ATT&CK alignment, and defensive countermeasures.
CVE format, CVSS scoring, CISA Known Exploited Vulnerabilities catalog, and vulnerability prioritization methodology.
Tabletop exercises, purple team methodology, CTF platforms, practice lab environments, IR simulations, and CISA frameworks.
These resources are maintained by the CMTA Cyber team and updated regularly. All content is written for real-world use. Coming Soon pages are actively being built. Suggest a topic or report an error by reaching out directly.