This is mostly intended for people getting started in security. There are so many resources, communities, and paths you can take, and it’s easy to get overwhelmed. Everything below has helped me or someone I know, and I’d trust it to help you too.
Online Reading
Subreddits
Aggregators
RSS Feeds
While I previously maintained my own lists, awesome_threat_intel_blogs does a far better job, which is also available as a Google Sheet.
X Lists
The following are lists which are strictly curated to improve signal:noise ratio. It’s advised that you supplement these with a set of muted words that further filter out unwanted content.
Fundamentals
Newcomers to the industry, or those wanting to deepen their intelligence skills, may also find Curated Intel’s CTI Fundamentals repository useful. It offers an extensive list of blog posts, whitepapers and presentations to help guide and support your learning.
Managing It All
RSS.app can turn X lists into RSS feeds, which can then be pulled into the likes of Feedly or Inoreader alongside your other RSS feeds, Telegram channels, subreddits and Google News searches. For threat intel specific functions, consider Obstracts or Feedly.
Infrastructure
NZ Infosec Scene
Resources
- Awesome Forensics
- Awesome Game Security
- Awesome Incident Response
- Awesome OSINT
- Awesome Red Teaming
- Awesome Reverse Engineering
- Awesome Threat Intel Blogs
- Awesome Threat Intelligence
- Awesome Web Scraping
- Bellingcat Toolkit
- deepdarkCTI
- HackTricks
- Internal All The Things
- Payloads All The Things
- The C2 Matrix
- The Hacker Recipes
Communities
Books
Cyber Intelligence
- Intelligence-Driven Incident Response by Scott J. Roberts and Rebekah Brown
- Open Source Intelligence Techniques by Michael Bazzell
- Operationalizing Threat Intelligence by Kyle Wilhoit and Joseph Opacki
Cybercrime
- Ctrl + Alt + Chaos by Joe Tidy
- Rinsed: From Cartels to Crypto by Geoff White
- The Art of Cyberwarfare by Jon DiMaggio
Malware Analysis
- Malware Analyst’s Cookbook by Michael Ligh
- Practical Malware Analysis by Michael Sikorski
Reverse Engineering
- Game Hacking by Nick Cano
- Practical Binary Analysis by Dennis Andriesse
- Practical Reverse Engineering by Bruce Dang
- Reversing: Secrets of Reverse Engineering by Eldad Eilam
- The Art of Memory Forensics by Michael Ligh, Andrew Case, Jamie Levy and Aaron Walters
- Windows Internals (Part 1) by Mark Russinovich
- Windows Internals (Part 2) by Mark Russinovich
Exploit Development
- Hacking: The Art of Exploitation by John Erickson
Development
- C A Software Engineering Approach by Peter A. Darnell and Philip E. Margolis
- Learn Python the Hard Way by Zed Shaw
- Violent Python by TJ O’Connor
Detection Engineering
- The Practice of Network Security Monitoring: Understanding Incident Detection and Response by Richard Bejtlich
Red Teaming
- Red Team: How to Succeed By Thinking Like the Enemy by Micah Zenko
- Red Team Development and Operations: A practical guide by Joe Vest and James Tubberville
- Red Teams and Counterterrorism Training by Stephen Sloan
- The Red Team Handbook by The University of Foreign Military and Cultural Studies
Physical Security
- A Burglar’s Guide to the City by Geoff Manaugh
Social Engineering
- Social Engineering: The Art of Human Hacking by Christopher Hadnagy
- The Art of Deception: Controlling the Human Element of Security by Kevin Mitnick
Analytical Techniques
- A Rulebook for Arguments by Anthony Weston
- Psychology of Intelligence Analysis by Richards J. Heuer Jr.
Warfare Studies
- Deciphering Sun Tzu: How to Read The Art of War by Derek Yuen
- Dirty Wars: The World Is a Battlefield by Jeremy Scahill
- Silent Warfare: Understanding the World of Intelligence by Abram Shulsky and Gary Schmitt
- Terrorism and Counterintelligence: How Terrorist Groups Elude Detection by Blake Mobley
- Tolkachev, A Worthy Successor to Penkovsky by Barry Royden
Finance
- Business Adventures by John Brooks
- One Up On Wall Street by Peter Lynch
- The Art and Science of Technical Analysis by Adam Grimes
- Trading Wisdom: 50 lessons every trader should know by Cheds
Good Causes
Training
- Courses & Certifications by @offsectraining
- Exploit Writing by @corelanc0d3r
- GuidedHacking by @GuidedHacking
- MalDev Academy by @mr.d0x and @NUL0x4C
- Malwareless Adversarial Emulation by @ZephrSec
- Red Team Ops by @zeropointsecltd
- Reverse Engineering Workshops by @malwareunicorn
- TryHackMe by @tryhackme
- Zero2Automated: The Advanced Malware Analysis Course by @0verfl0w_ and @VK_Intel
Podcasts
- Bellingcat Podcast
- Darknet Diaries
- Red Team Podcast
- Recorded Future
- SpyCast
- The Privacy, Security, & OSINT Show
- The Underworld Podcast