christiant.io / reference
Cybersecurity Resources
A maintained collection of practical cybersecurity frameworks, training, threat intelligence, detection engineering, DFIR, and career resources.
Cybersecurity Resources
A practical set of resources I would point defenders, engineers, students, and security leaders toward today. This page intentionally avoids hard-coded pricing, resource counts, and other details that become stale quickly.
Last reviewed: September 25, 2026.
Start Here: Frameworks and Live Reference Data
- NIST Cybersecurity Framework 2.0 - Risk-management framework with implementation guidance, profiles, mappings, and quick-start resources.
- MITRE ATT&CK - Adversary behavior knowledge base for threat intelligence, detection engineering, hunting, and control validation.
- CISA Known Exploited Vulnerabilities Catalog - High-value input for vulnerability prioritization because entries represent vulnerabilities known to be exploited in the wild.
- FIRST EPSS - Probability-oriented vulnerability prioritization signal that complements CVSS and KEV.
- CIS Controls - Prioritized defensive safeguards and implementation groups.
- OWASP - Application-security projects including the Top 10, ASVS, testing guidance, cheat sheets, and API security material.
Hands-on Learning
Free or broadly accessible
- PortSwigger Web Security Academy - Excellent web-security learning material paired with interactive labs.
- CyLab Security Academy / picoCTF - Carnegie Mellon learning and CTF ecosystem for foundational through advanced practice.
- OverTheWire - Command-line, Linux, web, and exploitation wargames.
- Microsoft Learn Security - Microsoft security, identity, Azure, and Defender learning paths.
- AWS Skill Builder - AWS security and cloud learning paths.
- Google Cloud Skills Boost - Google Cloud security and infrastructure labs.
Structured lab platforms
- TryHackMe - Guided learning paths and hands-on labs.
- Hack The Box Academy - Structured technical modules and practical exercises.
- CyberDefenders - Blue-team, DFIR, threat hunting, and SOC-oriented challenges.
Detection Engineering and Security Operations
- Sigma - Portable detection-rule format and community rule ecosystem.
- YARA - Pattern-matching language widely used for malware identification and file analysis.
- Suricata - Network IDS/IPS and network-security monitoring.
- Zeek - Network telemetry and protocol analysis.
- Security Onion - Integrated network security monitoring and investigation platform.
- osquery - SQL-style endpoint instrumentation.
- Velociraptor - Endpoint visibility, collection, DFIR, and threat hunting.
- Volatility 3 - Memory forensics framework.
- Timesketch - Collaborative forensic timeline analysis.
christiant.io references
- Splunk Cheatsheet
- Splunk Beginner Guide
- KQL Beginner Guide
- Falcon LogScale / FQL
- Sigma Rule Guide
- YARA Rule Guide
- Snort and Suricata Rule Guide
- Endpoint Forensics
Threat Intelligence and Vulnerability Research
Use a mix of government advisories, vendor research, and primary technical reporting rather than relying on a single feed.
Government and public-interest sources
- CISA Cybersecurity Advisories
- CISA KEV Catalog
- NIST National Vulnerability Database
- UK NCSC Guidance
- ENISA Publications
Research teams worth following
- Google Threat Intelligence / Mandiant
- Microsoft Threat Intelligence
- Palo Alto Networks Unit 42
- Cisco Talos
- CrowdStrike Counter Adversary Operations
- Elastic Security Labs
- SANS Internet Storm Center
Vulnerability Management
A useful prioritization workflow generally combines:
- Exposure - Is the affected product actually present and reachable?
- Known exploitation - Check CISA KEV and credible threat reporting.
- Exploit likelihood - Use signals such as EPSS.
- Technical severity - Use CVSS and vendor analysis as context, not the only decision point.
- Business impact - Identity, privilege, data, criticality, and blast radius.
- Compensating controls - EDR, segmentation, WAF, hardening, or feature disablement.
Useful sources:
- CISA KEV
- FIRST EPSS
- NVD
- CVE Program
- Vendor security advisory portals for the affected product
Software Supply Chain and Secure Development
- OpenSSF - Open-source software supply-chain security.
- SLSA - Supply-chain integrity framework for software artifacts and build systems.
- OWASP Software Component Verification Standard - Guidance for software supply-chain controls.
- GitHub Security Lab - Vulnerability research and secure-development material.
- Secure Package Management on christiant.io - Practical npm and Python hardening guidance.
Cloud, Containers, and Infrastructure
- Kubernetes Security Documentation
- CIS Benchmarks
- AWS Security Documentation
- Microsoft Security Documentation
- Google Cloud Security
- Podman vs Docker: Security Angle
- Container Device Interface
- Local LLM Stack Guide
AI and Agent Security
AI tooling changes quickly, so prefer current documentation and observed behavior over static model assumptions.
- Agent Sandboxing
- Agentic SOC
- LLM Security Guide
- Token Guard
- Model Family Explorer
- Coding Agent Explorer
- Zero Data Retention Endpoints
The two benchmark explorers intentionally use Artificial Analysis source measurements directly for intelligence/performance, cost per task, and token utilization. They do not apply local GPT price modifiers.
Career and Workforce
- NIST NICE Framework - Common language for cybersecurity work roles, tasks, knowledge, and skills.
- CyberSeek - U.S. cybersecurity career pathways and workforce data.
- SANS / GIAC - Deep technical training and certifications.
- ISC2 - Security certifications and professional development.
- CompTIA Cybersecurity - Foundational and intermediate certification paths.
- OffSec - Hands-on offensive-security training and certifications.
For interview preparation on this site:
- General Cyber Interview
- SOC Interview
- Security Engineer Interview
- Threat Hunter Interview
- LLM / GenAI Developer Interview
Research and Conference Material
- USENIX Security
- IEEE Symposium on Security and Privacy
- ACM CCS
- NDSS Symposium
- Black Hat
- DEF CON
- CTFtime
Arizona and Phoenix Community
For local conferences, meetups, professional groups, and community events, see the maintained Phoenix Cybersecurity Events & Community page.
If a resource on this page becomes stale or materially changes, the goal is to replace or remove it rather than preserve outdated pricing, membership counts, or marketing claims.