Skip to main content
Knowledge & Community Care

Community Resources

A hand-curated directory of 36 premier open-source tools, living standards, and community initiatives maintained by the Cyber Scotland Connect community.

💚 Community Wellbeing & Support

Mental Health in Infosec

Working in cybersecurity involves high-pressure environments, on-call rotations, and intense incident response cycles. Mental health challenges do not discriminate, and our community believes support should always be accessible, judgement-free, and stigma-free.

SAMH

Scottish Association for Mental Health. Operating across Scottish communities to provide direct support, suicide prevention, and mental health services.

Visit samh.org.uk ↗

Breathing Space & Nightline

Free, confidential listening and mental health support across Scotland. Breathing Space (0800 83 85 87) operates across Scottish communities, alongside local student services like Edinburgh Nightline.

Community Discord

Connect with fellow Scottish infosec practitioners in the Cyber Scotland Connect Discord for informal peer discussions, knowledge sharing, and community support.

Join Community Discord ↗

Scottish & UK Ecosystem

National coordination, public sector incident response, and professional career frameworks across Scotland and the UK.

Public Body / AdvisoryLocal / UK

Scottish Cyber Coordination Centre (SC3)

The Scottish Government focal point for national cyber resilience, coordinating incident response and sharing actionable threat intelligence across Scotland's public sector and critical infrastructure.

Scottish & UK EcosystemVisit Resource
Community ProjectLocal / UK

Cyber and Fraud Centre - Scotland

An independent Scottish charity empowering businesses and third-sector groups with free incident response triage, ethical hacking student clinics, and cyber exercise workshops.

Scottish & UK EcosystemVisit Resource
Public Body / AdvisoryLocal / UK

NCSC UK Guidance & Active Cyber Defence

The UK's technical authority on cyber security, providing world-class threat intelligence, Cyber Essentials certification frameworks, and free protective tools like PDNS and Web Check.

Scottish & UK EcosystemVisit Resource
Living StandardLocal / UK

UK Cyber Security Council

The self-regulatory standard-setting body for the UK cyber sector, governing chartered status, professional pathways, and skill standards across industry and academia.

Scottish & UK EcosystemVisit Resource
Community ProjectLocal / UK

Cyber Scotland Portal

A collaborative partnership uniting 15+ Scottish public sector and industry organisations to deliver timely threat alerts, advice, and professional community initiatives across Scotland.

Scottish & UK EcosystemVisit Resource
Community ProjectLocal / UK

ScotlandIS Cyber

The dedicated cluster leadership organisation representing and advancing Scotland's cybersecurity industry, skills development, and collaborative innovation.

Scottish & UK EcosystemVisit Resource

Defensive & Detection Engineering

Open threat models, generic detection signatures, and continuous detection engineering standards.

Living Standard

MITRE ATT&CK®

A globally-accessible, open knowledgebase of adversary tactics and techniques based on real-world observations, providing a universal common language for defenders.

Defensive & Detection EngineeringVisit Resource
Open Source Tool

SigmaHQ Generic Detection Signatures

The open-source signature format that lets defenders describe detection rules in vendor-neutral YAML and convert them dynamically for Elastic, Splunk, Sentinel, and QRadar.

Defensive & Detection EngineeringVisit Resource
Living Standard

The Cyber Defense Matrix

Sounil Yu's open-source mental model organizing security capabilities across asset types (Devices, Apps, Networks, Data, Users) and NIST CSF lifecycle phases to pinpoint coverage gaps.

Defensive & Detection EngineeringVisit Resource
Open Source Tool

Atomic Red Team

A library of simple, automated, and ATT&CK-mapped tests that allow security teams to easily test their detections against specific adversary techniques in minutes.

Defensive & Detection EngineeringVisit Resource
Community Project

Detection Engineering & Telemetry Guides

Open-source reference frameworks, continuous detection lifecycle guides, and telemetry architecture standards for modern SOC defenders.

Defensive & Detection EngineeringVisit Resource
Living Standard

MITRE D3FEND™

A knowledge graph of cybersecurity countermeasure techniques and defensive design patterns, designed to complement and counter the offensive ATT&CK framework.

Defensive & Detection EngineeringVisit Resource

Offensive & AppSec

Living standards, penetration testing methodologies, and community vulnerability research resources.

Living Standard

OWASP Top 10 & ASVS

The premier open-source awareness and verification documents for web application security, representing broad consensus on the most critical security risks facing software.

Offensive & AppSecVisit Resource
Living Standard

OWASP Web Security Testing Guide (WSTG)

The master open-source testing guide covering black-box and grey-box web application testing methodologies for penetration testers and software security teams.

Offensive & AppSecVisit Resource
Interactive Lab

PortSwigger Web Security Academy

Completely free, high-fidelity interactive training labs covering modern web vulnerabilities from SQL injection and SSRF to HTTP request smuggling and OAuth flaws.

Offensive & AppSecVisit Resource
Community Project

PayloadsAllTheThings

A massive, community-maintained repository of offensive bypass payloads, cheat sheets, and practical exploitation vectors across web, API, and cloud domains.

Offensive & AppSecVisit Resource
Community Project

HackTricks & HackTricks Cloud

An open-source encyclopedia by Carlos Polop detailing privilege escalation, network penetration testing techniques, Active Directory attacks, and multi-cloud security tradecraft.

Offensive & AppSecVisit Resource
Community Project

GTFOBins

A curated open-source repository of Unix binaries that can be leveraged to bypass local security restrictions in misconfigured environments.

Offensive & AppSecVisit Resource

DFIR & Incident Response

Real-world adversary campaign analyses, memory and filesystem forensic tooling, and open CTI platforms.

Community Project

The DFIR Report

Exemplary open post-incident analysis deconstructing real-world adversary campaigns from weaponized initial delivery through to ransomware execution, with full IOCs and MITRE mappings.

DFIR & Incident ResponseVisit Resource
Living Standard

SANS DFIR Cheat Sheets & Posters

Freely accessible, community-standard reference posters documenting Windows artifact analysis, memory forensics cheat sheets, and evidence triage command lines.

DFIR & Incident ResponseVisit Resource
Open Source Tool

Eric Zimmerman's Forensic Tools

The industry-standard open-source forensic parsing utilities for Windows artifacts, including MFTECmd, KAPE, Registry Explorer, and ShellBags Explorer.

DFIR & Incident ResponseVisit Resource
Open Source Tool

OpenCTI (Cyber Threat Intelligence Platform)

An open-source platform enabling organizations to manage, structure, and visualize cyber threat intelligence knowledge and STIX2 observables collaboratively.

DFIR & Incident ResponseVisit Resource
Community Project

Awesome Incident Response

A curated list of open-source incident response tools, playbooks, disk analysis scripts, memory collection utilities, and forensic readiness guides.

DFIR & Incident ResponseVisit Resource
Open Source Tool

Velociraptor

An advanced open-source digital forensics, incident response, and endpoint visibility platform using VQL to query and collect live artifacts at scale.

DFIR & Incident ResponseVisit Resource

Cloud, DevSecOps & Supply Chain

Vendor-agnostic control frameworks, container hardening guides, and software bill-of-materials (SBOM) platforms.

Living Standard

CSA Cloud Controls Matrix (CCM)

The Cloud Security Alliance cybersecurity control framework, providing clear systematic guidance and mapping to ISO 27001, NIST, and PCI DSS across cloud layers.

Cloud, DevSecOps & Supply ChainVisit Resource
Open Source Tool

OpenSSF Scorecard

An automated security tool from the Open Source Security Foundation that assesses open-source repositories against supply chain and code security best practices.

Cloud, DevSecOps & Supply ChainVisit Resource
Living Standard

CIS Benchmarks

Consensus-developed, vendor-agnostic security configuration guidelines providing authoritative baselines for hardening operating systems, cloud environments, and databases.

Cloud, DevSecOps & Supply ChainVisit Resource
Living Standard

Kubernetes Security & Hardening Documentation

Official open-source Kubernetes guidance covering cluster architecture, pod security standards, network segmentation, and hardening best practices.

Cloud, DevSecOps & Supply ChainVisit Resource
Open Source Tool

OWASP Dependency-Track & CycloneDX

An intelligent open-source Component Analysis platform that leverages Software Bill of Materials (SBOM) standards to track software supply chain vulnerabilities in real time.

Cloud, DevSecOps & Supply ChainVisit Resource
Living Standard

SLSA (Supply-chain Levels for Software Artifacts)

An open-source security framework providing automated, verifiable levels of integrity protection from source commit to production artifact.

Cloud, DevSecOps & Supply ChainVisit Resource

Interactive Labs & Tooling

Hands-on wargames, cryptanalysis challenges, protocol dissection, and open-source data manipulation utilities.

Open Source ToolLocal / UK

CyberChef (The Cyber Swiss Army Knife)

An intuitive open-source web application created by GCHQ for carrying out diverse cyber operations, data parsing, decoding, hashing, and decompressing without leaking data.

Interactive Labs & ToolingVisit Resource
Interactive Lab

OverTheWire Wargames: Bandit

The classic hands-on command-line wargame aimed at beginners, teaching Linux command-line navigation, file permissions, pipes, and essential security mechanics.

Interactive Labs & ToolingVisit Resource
Interactive Lab

Cryptopals Crypto Challenges

A legendary collection of practical programming exercises that guide you through breaking real-world flawed cryptographic implementations step by step.

Interactive Labs & ToolingVisit Resource
Open Source Tool

Wireshark & Sample Captures Repository

The standard open-source network protocol analyzer, paired with a rich public repository of packet captures for learning protocol analysis, malware dissection, and troubleshooting.

Interactive Labs & ToolingVisit Resource
Community Project

Awesome Cybersecurity Repository Lists

A curated open-source index of cybersecurity tools, software, academic papers, books, and courses maintained collaboratively by the global infosec community.

Interactive Labs & ToolingVisit Resource
Interactive Lab

picoCTF (Carnegie Mellon University)

A free, community-standard educational cybersecurity program and gamified CTF platform designed to teach practical reverse engineering, forensics, and web exploitation.

Interactive Labs & ToolingVisit Resource

Know an exceptional open resource?

Our reading room is maintained directly by the community. We prioritise open-source tools, living standards, and non-commercial projects. Simply create a markdown file in our repository to submit a pull request.