Home / Libraries
Resources & Libraries
A curated index spanning cybersecurity training and certifications, privacy tooling, low-tech preparedness gear, and live threat intelligence — from beginner to advanced.
Jump to
Libraries & Useful Resources
Standards bodies, certification paths, training platforms and the podcasts that keep this field moving.
- ORGNIST (opens in new tab) — Federal standards body behind the Cybersecurity Framework (CSF) and countless baseline controls.
- ORGOWASP (opens in new tab) — Open community defining the Top 10 web app risks and dozens of free security testing tools.
- ORGPacket Storm Security (opens in new tab) — Long-running archive of exploits, advisories, tools and security news.
- DBCVE (opens in new tab) — The canonical identifier registry behind every "CVE-2026-xxxxx" vulnerability name.
- DBNVD — National Vulnerability Database (opens in new tab) — The US government's searchable, scored database of known vulnerabilities.
- DBGitHub Security Advisories (opens in new tab) — Vulnerability disclosures tied directly to the open-source packages and repos that use them.
- OSINTOpen Source Intelligence (OSINT) Framework (opens in new tab) — A categorized map of free OSINT tools and techniques — the standard starting point for this discipline.
- CERT(ISC)² — Cybersecurity Certifications (opens in new tab) — Home of CISSP, SSCP and other widely recognized certification paths.
- CERTCompTIA Security+ (opens in new tab) — Entry-level industry cert, plus A+, Network+ and other CompTIA tracks.
- TRAINProfessor Messer (opens in new tab) — Free Security+ (and other CompTIA) video training — site and YouTube channel.
- CERTEC-Council — Certified Ethical Hacker (opens in new tab) — The organization behind the CEH credential and related ethical-hacking certifications.
- ORGKaspersky (opens in new tab) — Global security vendor and research team; also runs the live cyberthreat map linked from our Research Desk.
- DBExploit Database (Exploit-DB) (opens in new tab) — Archive of public exploits and proof-of-concept code, maintained by Offensive Security.
- ORGCitizen Lab (opens in new tab) — University of Toronto research group investigating spyware, surveillance and digital rights abuses.
- ORGAmnesty International — Security Lab (opens in new tab) — Forensic investigations into state-sponsored spyware (e.g. Pegasus) and digital human-rights threats.
- GOVFBI Internet Crime Complaint Center (IC3) (opens in new tab) — File a report if you've been targeted by online fraud, scams or cybercrime.
- DOCSPalo Alto Networks Documentation (opens in new tab) — Official technical documentation for Palo Alto's firewall and security platforms.
- TRAINTryHackMe (opens in new tab) — Guided, beginner-friendly hands-on labs for learning offensive and defensive security.
- TRAINHack The Box (opens in new tab) — More advanced hands-on penetration-testing labs and CTF-style challenges.
- YTDave Bombal (opens in new tab) — Networking, ethical hacking and career-focused interviews and tutorials.
- CASTDarknet Diaries (opens in new tab) — True stories from the dark side of the internet — hacks, breaches and the people behind them.
- CASTRisky Business (opens in new tab) — Weekly security news roundup with sharp, practitioner-level analysis.
- CASTSecurity Now (opens in new tab) — Long-running deep dive into security news, hosted by Steve Gibson.
- CASTSmashing Security (opens in new tab) — Lighter, conversational take on the week's breaches and scams.
- CASTThe CyberWire Daily (opens in new tab) — Concise daily briefing on cybersecurity news and threat activity.
Blue Legends
The foundations this whole field still stands on.
- 1998Packet Storm Security (opens in new tab) — Still one of the longest-running exploit and advisory archives on the internet.
- 1999CVE (opens in new tab) — Gave the industry a shared, unambiguous way to name a vulnerability.
- 1988CERT advisories (opens in new tab) — The original coordinated-disclosure and incident-response body, born out of the Morris Worm.
- 1980Usenet (opens in new tab) — The distributed discussion network that predates the modern web by a decade, still archived and browsable today.
- 1988IRC (opens in new tab) — Real-time chat protocol that shaped hacker and open-source culture alike; still alive today via networks like Libera.Chat.
More Techie & Cyber Tools
Privacy software, hardened hardware and hygiene practices, grouped the way a security team would organize them.
Encrypted communication
- MAILProton Mail (opens in new tab) — End-to-end encrypted email based in Switzerland, no logs by default.
- MAILTuta (opens in new tab) & Mailbox.org (opens in new tab) — Two other well-regarded encrypted email providers, both based in the EU.
- MSGSignal (opens in new tab) — The reference standard for end-to-end encrypted messaging and calls.
- ENCPGP / GPG Encryption (opens in new tab) — Public-key encryption and signing for email and files (GnuPG is the free implementation).
Anonymity, routing & VPNs
- NETTor (opens in new tab) — Onion-routed anonymized browsing and the backbone of the Tails OS below.
- NETI2P Project (opens in new tab) — A separate anonymizing network layer, optimized for peer-to-peer traffic rather than exit browsing.
- VPNProton VPN (opens in new tab) — No-logs VPN from the Proton privacy suite.
- VPNMullvad VPN (opens in new tab) — Anonymous-by-design VPN — accounts use random numbers, not email addresses.
- GUIDEPrivacy Guides (opens in new tab) — Independent, continuously updated recommendations across every privacy tool category.
VPN ranking
- T1Mullvad VPN (opens in new tab) — Anonymous-by-design, no-email accounts, consistently audited — the top tier for VPNs.
Browsers, Extension Tools, and Search
- APPBrave Browser (opens in new tab) — Chromium-based browser with tracker/ad blocking built in by default.
- APPMullvad Browser (opens in new tab) — Firefox-based browser built with the Tor Project, hardened against fingerprinting without needing the Tor network.
- APPDuckDuckGo (opens in new tab) — Search engine that doesn't build a profile of you or your queries.
- APPBlokada (opens in new tab) — System-wide ad and tracker blocking at the DNS/VPN level on mobile.
- EXTPrivacy Badger (opens in new tab) — EFF's browser extension that learns to block trackers based on behavior, not a fixed list.
- EXTuBlock Origin (opens in new tab) — Efficient, open-source content blocker for ads, trackers and malware domains.
- EXTGhostery (opens in new tab) — Tracker blocking plus a visible breakdown of exactly who's trying to track you on each page.
- EXTCookie AutoDelete (opens in new tab) — Automatically wipes cookies for a site once you close its tabs.
- EXTMozilla Facebook Container (opens in new tab) — Isolates Facebook into its own container so it can't track you across the rest of the web.
Browser Privacy ranking
- T1Tor Browser (opens in new tab), Mullvad Browser (opens in new tab) — Built specifically to resist tracking and fingerprinting — the top tier for browser privacy.
- T2Brave (opens in new tab), LibreWolf (opens in new tab), Firefox (Hardened) (opens in new tab) — Strong privacy defaults out of the box, or Firefox hardened via a config like arkenfox.
- T3Vivaldi (opens in new tab), DuckDuckGo (opens in new tab) — Reasonable middle ground — more configurable or privacy-forward than mainstream defaults.
- T4Safari (opens in new tab), Chrome (opens in new tab), Edge (opens in new tab), Opera (opens in new tab) — Mainstream defaults — fine day to day, but not built with privacy as the priority.
AI Tools
- AILumo (opens in new tab) — Proton's privacy-focused AI assistant — no chat logs used to train models.
- AIOllama + open models (opens in new tab) — Run open-weight models locally on your own hardware — nothing leaves your machine.
- AILM Studio (opens in new tab) — Desktop app for downloading and running local open models with a GUI.
- AIOpen WebUI (opens in new tab) — Self-hosted chat interface that sits on top of Ollama or other local model backends.
- AIOpenAI (opens in new tab) — Maker of the GPT model family and ChatGPT.
- AIAnthropic (opens in new tab) — Maker of the Claude model family — used in the development of this site.
- AIMistral AI (opens in new tab) — French AI lab behind the open-weight Mistral model family.
- AIQwen (opens in new tab) — Alibaba's open-weight model family, widely used for local/self-hosted setups.
Search Rankings
- T1Kagi (opens in new tab) & SearXNG (opens in new tab) — Paid, ad-free, tracking-free search (Kagi) and a self-hostable open-source metasearch engine (SearXNG) — the top tier for search privacy.
- T2DuckDuckGo (opens in new tab), Startpage (opens in new tab), Brave Search (opens in new tab) — Solid, widely-used privacy-respecting alternatives to mainstream search.
- T3Mojeek (opens in new tab), Ecosia (opens in new tab) — An independent index (Mojeek) and a search engine that funds tree-planting (Ecosia) — smaller, but real alternatives.
- T4Google (opens in new tab), Bing (opens in new tab) — The mainstream default — capable, but built on tracking and profiling as the business model.
- VETSeasoned Veteran Tier — AOL (opens in new tab), Dogpile (opens in new tab), WebCrawler (opens in new tab) — Still online today, still doing the job — 90s survivors that never fully went away.
- R.I.P.Retired — AltaVista, AllTheWeb, SecurityFocus, the Bugtraq mailing list, Northern Lights, Ask Jeeves, HotBot, Cyberdyne Systems, Ellingson Mineral Company, Tyrell Corporation, Weyland-Yutani, Internet Explorer, Netscape Navigator, IBM WebExplorer, Mosaic NCSA — A mix of retired search engines and browsers from the early web.
Hardened devices & operating systems
- OSTails (opens in new tab) — Amnesic live OS that forces all traffic through Tor and leaves no trace on the host machine.
- OSGrapheneOS (opens in new tab) — Hardened, de-Googled Android OS built for Pixel hardware.
- HWOrange Pi (opens in new tab) — Low-cost single-board computer, useful for self-hosted or air-gapped projects.
- DEV"Ghost Phone" — Placeholder — link and listing coming once details are finalized.
- DEViPad or Chromebook with no SIM card — A Wi-Fi-only secondary device is one of the simplest ways to reduce your cellular attack surface.
Endpoint monitoring
- APPObjective-See — KnockKnock & OverSight (opens in new tab) — Free macOS tools that surface persistence mechanisms (KnockKnock) and mic/camera access (OverSight).
Authentication & credentials
- MFAMFA apps — Ente Auth (opens in new tab), 2FAS (opens in new tab), Proton Authenticator (opens in new tab), Microsoft Authenticator (opens in new tab), Google Authenticator (opens in new tab) — Use an app-based authenticator over SMS wherever a service supports it.
- APPBitwarden (opens in new tab) — Open-source password manager with a genuinely usable free tier.
Authenticator app ranking
- T1Exceptional — Ente Auth (opens in new tab) & Aegis (opens in new tab) — Open-source, encrypted local backups, no telemetry phoning home — the gold standard for this category.
- T2Tier 2 — 2FAS (opens in new tab), Proton Authenticator (opens in new tab), YubiKey Authenticator (opens in new tab) — Strong, actively maintained options with solid backup and sync stories.
- T3Tier 3 — FreeOTP (opens in new tab), Authy (opens in new tab) — Functional and widely used, with fewer privacy guarantees than Tier 1 or 2.
- T4Tier 4 — Microsoft Authenticator (opens in new tab), Salesforce Authenticator (opens in new tab), Google Authenticator (opens in new tab) — Fine as a baseline, but tied tightly to one vendor's ecosystem.
Password manager ranking
- T1KeePassXC (opens in new tab), Vaultwarden (opens in new tab) — Local-first (KeePassXC) or self-hosted (Vaultwarden) — full control over where your vault actually lives.
- T2Bitwarden (opens in new tab), 1Password (opens in new tab) — Polished, cross-platform, well-audited managed services.
- T3Proton Pass (opens in new tab), Strongbox (opens in new tab) — Solid privacy-forward options, newer or smaller than the Tier 2 mainstays.
- T4Apple Passwords, Google Password Manager (opens in new tab) — Convenient if you're already locked into that ecosystem, but not independently portable.
Hardware & network hygiene
- APPVirtual Machines (VirtualBox) (opens in new tab) — Isolate risky browsing, testing or unknown files in a disposable VM.
- HWHardware crypto wallets — Ledger (opens in new tab), Trezor (opens in new tab) — Keep private keys offline instead of in a hot wallet or exchange account.
- HWHome security cameras on an air-gapped router — Put cameras on their own network segment, use WPA3 with a changed default password, keep firmware current, and retire the router once updates stop.
- HWUSB data blocker ("USB condom") — A charge-only adapter for USB-C or USB-A that physically blocks the data pins — plug into public or untrusted ports without exposing your device to data transfer.
Low-Tech & Select Survival Items
When the grid, the network, or your GPS isn't available. Grouped by what problem each item solves.
Signal & data protection
- GEARFaraday pouch — Blocks RF signals to a phone or key fob — prevents remote tracking, wireless attacks, and relay theft.
- GEARThermal cloak — Reduces thermal/IR signature — used in both survival and privacy-from-surveillance contexts.
Emergency bags
- GEARGo-bag — 72-hour kit, packed and ready if you need to leave immediately.
- GEARGet-home bag — Smaller kit kept in a vehicle or bag, focused on getting you home if normal transit isn't an option.
Power & water
- GEARPortable solar charger & solar power banks — Off-grid power for phones, radios and small electronics.
- GEARWater filter straw (opens in new tab) — Compact personal filtration for questionable water sources — LifeStraw is the well-known reference brand.
Protective equipment
- GEARIsraeli gas mask — Full-face protection, widely available surplus with replaceable filter canisters.
- GEARPD-100 & carbon-filtered KN-95 / N95 masks — Particulate and light-chemical filtration; check CDC NIOSH's approved respirator list (opens in new tab) before buying.
Navigation
- GEARClassic road atlas / paper map (opens in new tab) — Works when GPS is jammed, spoofed, or your phone has no signal or battery.
Cybersecurity News & Threat Intelligence
Live feeds, vulnerability databases and the blogs/shows that track it all — organized the way a SOC would bookmark it.
Government & public resources
- GOVCISA (opens in new tab) — Cybersecurity & Infrastructure Security Agency — the US government's front line for cyber defense.
- GOVUS-CERT Advisories (opens in new tab) — Advisory bulletins, now published directly under CISA.
- GOVNIST National Vulnerability Database (NVD) (opens in new tab) — The US government's searchable, scored database of known vulnerabilities.
- GOVFBI Cyber Division (opens in new tab) — Federal investigative arm for cybercrime, alongside IC3 in Section 01.
- GOVNSA Cybersecurity Guidance (opens in new tab) — Hardening guides and advisories published by the National Security Agency.
- GOVMITRE ATT&CK Framework (opens in new tab) — The industry-standard matrix of adversary tactics and techniques.
- GOVMITRE CVE Program (opens in new tab) — The authoritative naming/tracking system behind every "CVE-2026-xxxxx" identifier.
- GOVCISA Known Exploited Vulnerabilities (KEV) (opens in new tab) — The vulnerabilities confirmed to be under active exploitation right now — patch these first.
Vulnerability research
- VULNExploit Database (Exploit-DB) (opens in new tab) — Public exploits and PoC code, maintained by Offensive Security.
- VULNCVE Database (opens in new tab) — Search the canonical vulnerability identifier registry directly.
- VULNVulnCheck (opens in new tab) — Exploit intelligence and early vulnerability data, built for defenders.
- VULNSecurityFocus Archive (opens in new tab) — Legacy vulnerability database and mailing-list archive (BugTraq) — historical reference.
- VULNRapid7 Vulnerability Database (opens in new tab) — Searchable vulnerability and module database behind Metasploit.
- VULNTenable Research (opens in new tab) — Vulnerability disclosures and threat analysis from the Nessus team.
- VULNVulDB (opens in new tab) — Community-driven vulnerability database with exploitability scoring.
Threat intelligence
- INTELVirusTotal (opens in new tab) — Scan files and URLs against dozens of AV engines and threat-intel sources.
- INTELURLScan.io (opens in new tab) — Sandboxed scanning and visualization of what a URL actually does when visited.
- INTELAlienVault OTX (opens in new tab) — Open, crowd-sourced threat exchange from AT&T Cybersecurity.
- INTELGreyNoise (opens in new tab) — Separates targeted attack traffic from the internet's constant background scanning noise.
- INTELShodan (opens in new tab) — Search engine for internet-connected devices and exposed services.
- INTELCensys (opens in new tab) — Internet-wide asset and exposure scanning, similar in spirit to Shodan.
- INTELAbuseIPDB (opens in new tab) — Check and report IPs engaged in abusive or malicious activity.
- INTELHybrid Analysis (opens in new tab) — Free automated malware sandbox and analysis reports.
- INTELANY.RUN Sandbox (opens in new tab) — Interactive, real-time malware sandbox you can control while it detonates a sample.
- INTELJoe Sandbox (opens in new tab) — Deep behavioral malware analysis across multiple OS environments.
Data breach resources
- BREACHHave I Been Pwned? (opens in new tab) — Check if your email or phone number has surfaced in a known data breach.
- BREACHFirefox Monitor (opens in new tab) — Mozilla's breach-monitoring service, backed by the same HIBP data.
- BREACHDeHashed (opens in new tab) — Searchable breach-data index, commonly used in OSINT investigations.
- BREACHIntelligence X (opens in new tab) — Search engine and archive for leaked data, documents and darknet content.
Security blogs
- BLOGKrebs on Security (opens in new tab) — Investigative reporting on cybercrime from Brian Krebs.
- BLOGThe Hacker News (opens in new tab) — Fast-moving daily security news coverage.
- BLOGBleepingComputer (opens in new tab) — News plus hands-on malware removal and troubleshooting guides.
- BLOGDark Reading (opens in new tab) — Enterprise-focused security news and analysis.
- BLOGSANS Internet Storm Center (opens in new tab) — Daily diary of internet threat activity from SANS analysts.
- BLOGCisco Talos Intelligence (opens in new tab) — Threat research from Cisco's dedicated intel group.
- BLOGMicrosoft Security Blog (opens in new tab) — Microsoft's own threat research and product security updates.
- BLOGGoogle Project Zero (opens in new tab) — Deep technical write-ups of zero-day vulnerabilities from Google's elite research team.
- BLOGMandiant Blog (opens in new tab) — Incident-response and threat-actor tracking from Mandiant (Google Cloud).
- BLOGPalo Alto Unit 42 (opens in new tab) — Palo Alto's threat intelligence and incident-response research arm.
- BLOGCrowdStrike Blog (opens in new tab) — Adversary tracking and endpoint threat research from CrowdStrike.
Blue team resources
- BLUESigma Rules (opens in new tab) — Generic, shareable detection rules that translate across SIEM platforms.
- BLUEYARA Rules (opens in new tab) — Pattern-matching rules for identifying and classifying malware.
- BLUEVelociraptor (opens in new tab) — Query-driven endpoint visibility and DFIR collection at scale.
- BLUEChainsaw (opens in new tab) — Fast Windows event-log triage and Sigma-rule hunting from the command line.
- BLUESysmon (opens in new tab) — Detailed Windows process, network and file-change logging.
- BLUESysinternals Suite (opens in new tab) — The full Microsoft toolset Sysmon ships from — Process Explorer, Autoruns and more.
- BLUECyberChef (opens in new tab) — Browser-based "cyber swiss army knife" for encoding, decoding and data manipulation.
- BLUEWireshark (opens in new tab) — The world-standard packet capture and protocol analyzer.
- BLUEZeek (opens in new tab) — Passive network traffic analysis framework that turns packets into security logs.
- BLUESuricata (opens in new tab) — High-performance IDS/IPS and network security monitoring engine.
Podcasts & YouTube
- CASTDarknet Diaries (opens in new tab) — True stories from the dark side of the internet.
- CASTSecurity Now (opens in new tab) — Long-running weekly deep dive into security news.
- CASTRisky Business (opens in new tab) — Practitioner-level weekly security news roundup.
- CASTSmashing Security (opens in new tab) — Conversational take on the week's breaches and scams.
- YTProfessor Messer (opens in new tab) — Free CompTIA certification training videos.
- YTDave Bombal (opens in new tab) — Networking and ethical-hacking tutorials and interviews.
- YTJohn Hammond (opens in new tab) — Malware analysis and CTF walkthroughs.
- YTLiveOverflow (opens in new tab) — Deep, honest breakdowns of how exploits actually work.
- YTNetworkChuck (opens in new tab) — Approachable networking and security fundamentals.
- YTThe Cyber Mentor (opens in new tab) — Practical penetration-testing training from TCM Security.
- YTIppSec (opens in new tab) — Hack The Box machine walkthroughs, widely used for OSCP prep.