Home / Libraries
Resources & Libraries
A curated index spanning cybersecurity training and certifications, privacy tooling, low-tech preparedness gear, and live threat intelligence — from beginner to advanced.
Section 01
Libraries & Useful Resources
Standards bodies, certification paths, training platforms and the podcasts that keep this field moving.
- ORGNIST — Federal standards body behind the Cybersecurity Framework (CSF) and countless baseline controls.
- ORGOWASP — Open community defining the Top 10 web app risks and dozens of free security testing tools.
- ORGPacket Storm Security — Long-running archive of exploits, advisories, tools and security news.
- DBCVE — The canonical identifier registry behind every "CVE-2026-xxxxx" vulnerability name.
- DBNVD — National Vulnerability Database — The US government's searchable, scored database of known vulnerabilities.
- DBGitHub Security Advisories — Vulnerability disclosures tied directly to the open-source packages and repos that use them.
- OSINTOpen Source Intelligence (OSINT) Framework — A categorized map of free OSINT tools and techniques — the standard starting point for this discipline.
- CERT(ISC)² — Cybersecurity Certifications — Home of CISSP, SSCP and other widely recognized certification paths.
- CERTCompTIA Security+ — Entry-level industry cert, plus A+, Network+ and other CompTIA tracks.
- TRAINProfessor Messer — Free Security+ (and other CompTIA) video training — site and YouTube channel.
- CERTEC-Council — Certified Ethical Hacker — The organization behind the CEH credential and related ethical-hacking certifications.
- ORGKaspersky — Global security vendor and research team; also runs the live cyberthreat map linked from our Research Desk.
- DBExploit Database (Exploit-DB) — Archive of public exploits and proof-of-concept code, maintained by Offensive Security.
- ORGCitizen Lab — University of Toronto research group investigating spyware, surveillance and digital rights abuses.
- ORGAmnesty International — Security Lab — Forensic investigations into state-sponsored spyware (e.g. Pegasus) and digital human-rights threats.
- GOVFBI Internet Crime Complaint Center (IC3) — File a report if you've been targeted by online fraud, scams or cybercrime.
- DOCSPalo Alto Networks Documentation — Official technical documentation for Palo Alto's firewall and security platforms.
- TRAINTryHackMe — Guided, beginner-friendly hands-on labs for learning offensive and defensive security.
- TRAINHack The Box — More advanced hands-on penetration-testing labs and CTF-style challenges.
- YTDave Bombal — Networking, ethical hacking and career-focused interviews and tutorials.
- CASTDarknet Diaries — True stories from the dark side of the internet — hacks, breaches and the people behind them.
- CASTRisky Business — Weekly security news roundup with sharp, practitioner-level analysis.
- CASTSecurity Now — Long-running deep dive into security news, hosted by Steve Gibson.
- CASTSmashing Security — Lighter, conversational take on the week's breaches and scams.
- CASTThe CyberWire Daily — Concise daily briefing on cybersecurity news and threat activity.
Blue Legends
The foundations this whole field still stands on.
- 1998Packet Storm Security — Still one of the longest-running exploit and advisory archives on the internet.
- 1999CVE — Gave the industry a shared, unambiguous way to name a vulnerability.
- 1988CERT advisories — The original coordinated-disclosure and incident-response body, born out of the Morris Worm.
- 1980Usenet — The distributed discussion network that predates the modern web by a decade, still archived and browsable today.
- 1988IRC — Real-time chat protocol that shaped hacker and open-source culture alike; still alive today via networks like Libera.Chat.
Section 02
More Techie & Cyber Tools
Privacy software, hardened hardware and hygiene practices, grouped the way a security team would organize them.
Encrypted communication
- MAILProton Mail — End-to-end encrypted email based in Switzerland, no logs by default.
- MAILTuta & Mailbox.org — Two other well-regarded encrypted email providers, both based in the EU.
- MSGSignal — The reference standard for end-to-end encrypted messaging and calls.
- ENCPGP / GPG Encryption — Public-key encryption and signing for email and files (GnuPG is the free implementation).
Anonymity, routing & VPNs
- NETTor — Onion-routed anonymized browsing and the backbone of the Tails OS below.
- NETI2P Project — A separate anonymizing network layer, optimized for peer-to-peer traffic rather than exit browsing.
- VPNProton VPN — No-logs VPN from the Proton privacy suite.
- VPNMullvad VPN — Anonymous-by-design VPN — accounts use random numbers, not email addresses.
- GUIDEPrivacy Guides — Independent, continuously updated recommendations across every privacy tool category.
VPN ranking
- T1Mullvad VPN — Anonymous-by-design, no-email accounts, consistently audited — the top tier for VPNs.
Browsers, Extension Tools, and Search
- APPBrave Browser — Chromium-based browser with tracker/ad blocking built in by default.
- APPMullvad Browser — Firefox-based browser built with the Tor Project, hardened against fingerprinting without needing the Tor network.
- APPDuckDuckGo — Search engine that doesn't build a profile of you or your queries.
- APPBlokada — System-wide ad and tracker blocking at the DNS/VPN level on mobile.
- EXTPrivacy Badger — EFF's browser extension that learns to block trackers based on behavior, not a fixed list.
- EXTuBlock Origin — Efficient, open-source content blocker for ads, trackers and malware domains.
- EXTGhostery — Tracker blocking plus a visible breakdown of exactly who's trying to track you on each page.
- EXTCookie AutoDelete — Automatically wipes cookies for a site once you close its tabs.
- EXTMozilla Facebook Container — Isolates Facebook into its own container so it can't track you across the rest of the web.
Browser Privacy ranking
- T1Tor Browser, Mullvad Browser — Built specifically to resist tracking and fingerprinting — the top tier for browser privacy.
- T2Brave, LibreWolf, Firefox (Hardened) — Strong privacy defaults out of the box, or Firefox hardened via a config like arkenfox.
- T3Vivaldi, DuckDuckGo — Reasonable middle ground — more configurable or privacy-forward than mainstream defaults.
- T4Safari, Chrome, Edge, Opera — Mainstream defaults — fine day to day, but not built with privacy as the priority.
AI Tools
- AILumo — Proton's privacy-focused AI assistant — no chat logs used to train models.
- AIOllama + open models — Run open-weight models locally on your own hardware — nothing leaves your machine.
- AILM Studio — Desktop app for downloading and running local open models with a GUI.
- AIOpen WebUI — Self-hosted chat interface that sits on top of Ollama or other local model backends.
- AIOpenAI — Maker of the GPT model family and ChatGPT.
- AIAnthropic — Maker of the Claude model family — used in the development of this site.
- AIMistral AI — French AI lab behind the open-weight Mistral model family.
- AIQwen — Alibaba's open-weight model family, widely used for local/self-hosted setups.
Search Rankings
- T1Kagi & SearXNG — Paid, ad-free, tracking-free search (Kagi) and a self-hostable open-source metasearch engine (SearXNG) — the top tier for search privacy.
- T2DuckDuckGo, Startpage, Brave Search — Solid, widely-used privacy-respecting alternatives to mainstream search.
- T3Mojeek, Ecosia — An independent index (Mojeek) and a search engine that funds tree-planting (Ecosia) — smaller, but real alternatives.
- T4Google, Bing — The mainstream default — capable, but built on tracking and profiling as the business model.
- VETSeasoned Veteran Tier — AOL, Dogpile, WebCrawler — Still online today, still doing the job — 90s survivors that never fully went away.
- R.I.P.Retired — AltaVista, AllTheWeb, SecurityFocus, the Bugtraq mailing list, Northern Lights, Ask Jeeves, HotBot, Cyberdyne Systems, Ellingson Mineral Company, Tyrell Corporation, Weyland-Yutani, Internet Explorer, Netscape Navigator, IBM WebExplorer, Mosaic NCSA — A mix of retired search engines and browsers from the early web.
Hardened devices & operating systems
- OSTails — Amnesic live OS that forces all traffic through Tor and leaves no trace on the host machine.
- OSGrapheneOS — Hardened, de-Googled Android OS built for Pixel hardware.
- HWOrange Pi — Low-cost single-board computer, useful for self-hosted or air-gapped projects.
- DEV"Ghost Phone" — Placeholder — link and listing coming once details are finalized.
- DEViPad or Chromebook with no SIM card — A Wi-Fi-only secondary device is one of the simplest ways to reduce your cellular attack surface.
Endpoint monitoring
- APPObjective-See — KnockKnock & OverSight — Free macOS tools that surface persistence mechanisms (KnockKnock) and mic/camera access (OverSight).
Authentication & credentials
- MFAMFA apps — Ente Auth, 2FAS, Proton Authenticator, Microsoft Authenticator, Google Authenticator — Use an app-based authenticator over SMS wherever a service supports it.
- APPBitwarden — Open-source password manager with a genuinely usable free tier.
Authenticator app ranking
- T1Exceptional — Ente Auth & Aegis — Open-source, encrypted local backups, no telemetry phoning home — the gold standard for this category.
- T2Tier 2 — 2FAS, Proton Authenticator, YubiKey Authenticator — Strong, actively maintained options with solid backup and sync stories.
- T3Tier 3 — FreeOTP, Authy — Functional and widely used, with fewer privacy guarantees than Tier 1 or 2.
- T4Tier 4 — Microsoft Authenticator, Salesforce Authenticator, Google Authenticator — Fine as a baseline, but tied tightly to one vendor's ecosystem.
Password manager ranking
- T1KeePassXC, Vaultwarden — Local-first (KeePassXC) or self-hosted (Vaultwarden) — full control over where your vault actually lives.
- T2Bitwarden, 1Password — Polished, cross-platform, well-audited managed services.
- T3Proton Pass, Strongbox — Solid privacy-forward options, newer or smaller than the Tier 2 mainstays.
- T4Apple Passwords, Google Password Manager — Convenient if you're already locked into that ecosystem, but not independently portable.
Hardware & network hygiene
- APPVirtual Machines (VirtualBox) — Isolate risky browsing, testing or unknown files in a disposable VM.
- HWHardware crypto wallets — Ledger, Trezor — Keep private keys offline instead of in a hot wallet or exchange account.
- HWHome security cameras on an air-gapped router — Put cameras on their own network segment, use WPA3 with a changed default password, keep firmware current, and retire the router once updates stop.
- HWUSB data blocker ("USB condom") — A charge-only adapter for USB-C or USB-A that physically blocks the data pins — plug into public or untrusted ports without exposing your device to data transfer.
A note on the entries above without a link. A few items in this section — the Ghost Phone placeholder, the iPad/Chromebook tip, and the home-camera and USB-blocker guidance — are general practices or products intentionally left unlinked rather than pointed at a specific vendor.
Section 03
Low-Tech & Select Survival Items
When the grid, the network, or your GPS isn't available. Grouped by what problem each item solves.
Signal & data protection
- GEARFaraday pouch — Blocks RF signals to a phone or key fob — prevents remote tracking, wireless attacks, and relay theft.
- GEARThermal cloak — Reduces thermal/IR signature — used in both survival and privacy-from-surveillance contexts.
Emergency bags
- GEARGo-bag — 72-hour kit, packed and ready if you need to leave immediately.
- GEARGet-home bag — Smaller kit kept in a vehicle or bag, focused on getting you home if normal transit isn't an option.
Power & water
- GEARPortable solar charger & solar power banks — Off-grid power for phones, radios and small electronics.
- GEARWater filter straw — Compact personal filtration for questionable water sources — LifeStraw is the well-known reference brand.
Protective equipment
- GEARIsraeli gas mask — Full-face protection, widely available surplus with replaceable filter canisters.
- GEARPD-100 & carbon-filtered KN-95 / N95 masks — Particulate and light-chemical filtration; check CDC NIOSH's approved respirator list before buying.
Navigation
- GEARClassic road atlas / paper map — Works when GPS is jammed, spoofed, or your phone has no signal or battery.
Buy from a retailer you trust. Most of this section is a product category rather than one specific brand — we've deliberately avoided pointing you at a single storefront.
Section 04
Cybersecurity News & Threat Intelligence
Live feeds, vulnerability databases and the blogs/shows that track it all — organized the way a SOC would bookmark it.
Government & public resources
- GOVCISA — Cybersecurity & Infrastructure Security Agency — the US government's front line for cyber defense.
- GOVUS-CERT Advisories — Advisory bulletins, now published directly under CISA.
- GOVNIST National Vulnerability Database (NVD) — The US government's searchable, scored database of known vulnerabilities.
- GOVFBI Cyber Division — Federal investigative arm for cybercrime, alongside IC3 in Section 01.
- GOVNSA Cybersecurity Guidance — Hardening guides and advisories published by the National Security Agency.
- GOVMITRE ATT&CK Framework — The industry-standard matrix of adversary tactics and techniques.
- GOVMITRE CVE Program — The authoritative naming/tracking system behind every "CVE-2026-xxxxx" identifier.
- GOVCISA Known Exploited Vulnerabilities (KEV) — The vulnerabilities confirmed to be under active exploitation right now — patch these first.
Vulnerability research
- VULNExploit Database (Exploit-DB) — Public exploits and PoC code, maintained by Offensive Security.
- VULNCVE Database — Search the canonical vulnerability identifier registry directly.
- VULNVulnCheck — Exploit intelligence and early vulnerability data, built for defenders.
- VULNSecurityFocus Archive — Legacy vulnerability database and mailing-list archive (BugTraq) — historical reference.
- VULNRapid7 Vulnerability Database — Searchable vulnerability and module database behind Metasploit.
- VULNTenable Research — Vulnerability disclosures and threat analysis from the Nessus team.
- VULNVulDB — Community-driven vulnerability database with exploitability scoring.
Threat intelligence
- INTELVirusTotal — Scan files and URLs against dozens of AV engines and threat-intel sources.
- INTELURLScan.io — Sandboxed scanning and visualization of what a URL actually does when visited.
- INTELAlienVault OTX — Open, crowd-sourced threat exchange from AT&T Cybersecurity.
- INTELGreyNoise — Separates targeted attack traffic from the internet's constant background scanning noise.
- INTELShodan — Search engine for internet-connected devices and exposed services.
- INTELCensys — Internet-wide asset and exposure scanning, similar in spirit to Shodan.
- INTELAbuseIPDB — Check and report IPs engaged in abusive or malicious activity.
- INTELHybrid Analysis — Free automated malware sandbox and analysis reports.
- INTELANY.RUN Sandbox — Interactive, real-time malware sandbox you can control while it detonates a sample.
- INTELJoe Sandbox — Deep behavioral malware analysis across multiple OS environments.
Data breach resources
- BREACHHave I Been Pwned? — Check if your email or phone number has surfaced in a known data breach.
- BREACHFirefox Monitor — Mozilla's breach-monitoring service, backed by the same HIBP data.
- BREACHDeHashed — Searchable breach-data index, commonly used in OSINT investigations.
- BREACHIntelligence X — Search engine and archive for leaked data, documents and darknet content.
Security blogs
- BLOGKrebs on Security — Investigative reporting on cybercrime from Brian Krebs.
- BLOGThe Hacker News — Fast-moving daily security news coverage.
- BLOGBleepingComputer — News plus hands-on malware removal and troubleshooting guides.
- BLOGDark Reading — Enterprise-focused security news and analysis.
- BLOGSANS Internet Storm Center — Daily diary of internet threat activity from SANS analysts.
- BLOGCisco Talos Intelligence — Threat research from Cisco's dedicated intel group.
- BLOGMicrosoft Security Blog — Microsoft's own threat research and product security updates.
- BLOGGoogle Project Zero — Deep technical write-ups of zero-day vulnerabilities from Google's elite research team.
- BLOGMandiant Blog — Incident-response and threat-actor tracking from Mandiant (Google Cloud).
- BLOGPalo Alto Unit 42 — Palo Alto's threat intelligence and incident-response research arm.
- BLOGCrowdStrike Blog — Adversary tracking and endpoint threat research from CrowdStrike.
Blue team resources
- BLUESigma Rules — Generic, shareable detection rules that translate across SIEM platforms.
- BLUEYARA Rules — Pattern-matching rules for identifying and classifying malware.
- BLUEVelociraptor — Query-driven endpoint visibility and DFIR collection at scale.
- BLUEChainsaw — Fast Windows event-log triage and Sigma-rule hunting from the command line.
- BLUESysmon — Detailed Windows process, network and file-change logging.
- BLUESysinternals Suite — The full Microsoft toolset Sysmon ships from — Process Explorer, Autoruns and more.
- BLUECyberChef — Browser-based "cyber swiss army knife" for encoding, decoding and data manipulation.
- BLUEWireshark — The world-standard packet capture and protocol analyzer.
- BLUEZeek — Passive network traffic analysis framework that turns packets into security logs.
- BLUESuricata — High-performance IDS/IPS and network security monitoring engine.
Podcasts & YouTube
- CASTDarknet Diaries — True stories from the dark side of the internet.
- CASTSecurity Now — Long-running weekly deep dive into security news.
- CASTRisky Business — Practitioner-level weekly security news roundup.
- CASTSmashing Security — Conversational take on the week's breaches and scams.
- YTProfessor Messer — Free CompTIA certification training videos.
- YTDave Bombal — Networking and ethical-hacking tutorials and interviews.
- YTJohn Hammond — Malware analysis and CTF walkthroughs.
- YTLiveOverflow — Deep, honest breakdowns of how exploits actually work.
- YTNetworkChuck — Approachable networking and security fundamentals.
- YTThe Cyber Mentor — Practical penetration-testing training from TCM Security.
- YTIppSec — Hack The Box machine walkthroughs, widely used for OSCP prep.