Resources for Defenders and Operators

Resource Category Description
Try Hack Me Learning TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
Hack the Box Learning Hack The Box has helped hundreds of professional teams reinforce their cyber readiness with workforce development plans and hands-on exercises.
SANS Training and Research SANS is dedicated to delivering and validating hands-on cybersecurity skills through world-class training courses and industry-recognized certifications.
MITRE Research and Development MITRE is a non-profit organization focused on research, development, and innovation in various fields, including cybersecurity.
MITRE Cyber Infrastructure Protection Innovation Center Lab We develop technologies, practices, and approaches to protect critical infrastructure from malicious cyber or non-kinetic attack or disruption.
Threat Yeti Threat Intelligence Research tool provided by alphaMountain.ai for cybersecurity investigations, domain reputation and content classification.
The PLC Professor Training We assist companies in developing their training programs. There are thousands of these manuals in circulation.
Malware Traffic Analysis DFIR This blog focuses on network traffic related to malware infections, mostly from Windows-based malware.
SANS SIFT Incident Response The SIFT Workstation is a collection of free and open-source incident response and forensic tools designed to perform detailed digital forensic examinations.
Remnux DFIR A Linux Toolkit for Malware Analysis
SANS Infosec White Papers Research A collection of free white papers and blog posts developed by industry leaders and the trainers at SANS.
S4 ICS On Ramp Series Training The OnRamp training is a unique, free, and fast-paced program that focuses on the latest developments in Industrial Control Systems (ICS) and IIOT security.
CISA ICS Training Training CISA offers free industrial control systems (ICS) cybersecurity training to protect against cyberattacks on critical infrastructure.
Shodan DFIR Shodan is the world's first search engine for Internet-connected devices. Discover how Internet intelligence can help you make better decisions.
Not Simon Threat Intelligence A daily firehose of threat intelligence hosted on Mastodon. A great resource for timely information, cyber security news, threats, etc.
Takepoint Research Research Takepoint's research is conducted to help companies across the globe stay informed of the rapidly evolving cybersecurity landscape and make more insightful decisions.
Dragos Services OT environments face unique challenges that require OT-native solutions. That's where Dragos Platform comes in.

Have a site or resource that you would like to share submit it here. We will evaluate the resource and add it to the list.