Abuse.ch
Community-driven malware infrastructure tracking; free public feeds for malicious IPs, domains, and hashes. Strong on ransomware family tracking.
Cybersecurity Applications & Tools.
The vendor and platform vocabulary an analyst meets in the SOC. Each tool is defined by what it does: threat-intel feed, EDR, SIEM, SOAR, IAM, forensics, network security. The name on the slide maps back to a category an analyst can reason about.
Sources of curated indicators, campaign reports, and analyst-grade intelligence.
Community-driven malware infrastructure tracking; free public feeds for malicious IPs, domains, and hashes. Strong on ransomware family tracking.
Collaborative threat-intel exchange aggregating IOCs from a global community, with SIEM/automated integrations.
Collects, analyzes, and prioritizes threat data with enrichment and risk scoring; integrates with existing security stacks.
U.S. Cybersecurity and Infrastructure Security Agency advisories on vulnerabilities and active threats, with mitigation guidance.
Electricity sector ISAC; threat intel, IR support, and risk analysis tailored to grid operators.
Rapid high-priority notifications about imminent cyber threats targeting public and private partners.
Global financial-sector ISAC providing real-time alerts, incident coordination, and member collaboration.
Filters internet background-scan noise so SOCs focus on targeted attacks. IP context with malicious vs. benign classification.
Healthcare-sector ISAC; threat intelligence, incident response coordination, and best practices for clinical environments.
Commercial deep/dark-web monitoring with adversary infrastructure, TTP, and threat-actor behavior intelligence.
Global knowledge base of adversary tactics, techniques, and procedures. The shared vocabulary of modern SOCs.
Multi-State ISAC for U.S. state, local, tribal, and territorial governments; alerts, IR, and risk management resources.
UK National Cyber Security Centre; guidance, threat intelligence, and IR services across public and private sectors.
Successor to RiskIQ PassiveTotal (acquired by Microsoft, 2021). Aggregates passive DNS, WHOIS, SSL, and infrastructure data for attribution and threat hunting.
Community-validated database of phishing URLs; supplies security tools and browsers with up-to-date intelligence.
Threat-intelligence platform combining machine learning with human analysis across open, dark, and technical sources.
External Attack Surface Management, the renamed RiskIQ Illuminate (acquired by Microsoft, 2021). Discovers and monitors internet-facing assets, third-party services, and shadow IT.
Training, certification, and research; publishes critical threat research and runs the Internet Storm Center.
Free analysis of files and URLs across many AV engines; community sharing and reputation data.
Protocol and database of domain registration data; used to investigate suspicious domains and attribution.
Platforms that watch cloud workloads, identities, and posture across multi-account, multi-cloud environments.
Records and logs API activity within an AWS account, the audit trail for security and forensic work.
Monitoring and observability for AWS resources and applications; metrics, logs, alarms, automation hooks.
Microsoftβs cloud identity and access management; SSO, MFA, conditional access, and integration with SaaS apps.
Behavior analytics layered onto Microsoft Sentinel for detecting insider threats and anomalous activity.
Cloud-native security analytics platform from Google Cloud; high-speed search and threat detection at petabyte scale.
Cloudflareβs threat-research team and intelligence service; produces actionable indicators, campaign tracking, and disruption support against active adversaries.
DLP, cloud security, and insider-threat behavior analytics across endpoints, networks, and cloud applications.
Cloud-native SIEM/SOAR; AI-driven analytics across on-prem, cloud, and hybrid with rich connector library.
Agentless cloud security; full-stack visibility, vulnerability management, and risk prioritization across cloud workloads.
Cloud-native security platform from Palo Alto Networks; workload protection, IaC scanning, compliance, runtime defense.
Cloud-native security focused on container runtime, Kubernetes monitoring, and cloud workload protection.
Agentless cloud risk visibility; correlates infra/config/workload data to map attack paths and prioritize risk.
Where the logs go to be aggregated, normalized, and queried. The SOCβs primary lens.
Long-standing SIEM with strong correlation engine for compliance reporting and forensic analysis.
Data routing and processing for observability pipelines; filter, enrich, and reduce log data before forwarding.
Unified security on the Elastic Stack; endpoint protection, prebuilt detections, and customizable monitoring.
Next-gen SIEM with built-in UEBA; user-behavior timelines and automated investigation workflows.
Open-source data collector that unifies log collection and processing across distributed systems via plugins.
Enterprise SIEM with real-time correlation, ML-assisted prioritization, and broad ecosystem integration.
Server-side pipeline that ingests, transforms, and forwards data; central to the Elastic Stack.
Aggregation and correlation of security event data for centralized detection, compliance, and IR.
Premium SIEM on the Splunk platform; correlation searches, ML, prebuilt content for SOC workflows.
Windows service that produces rich endpoint telemetry, process creation, network connections, file events, for SIEM ingestion.
The agents that watch process trees, file activity, and on-host behavior.
EDR with behavior analysis, anti-exploit, root-cause analysis, and policy-based remediation.
Cloud-native EDR with a lightweight agent; combines behavioral analytics, threat intel, and ML.
EDR/XDR focused on endpoint visibility, malware detection, IR, and deep process-tree forensics.
Self-learning AI; builds behavioral baselines, detects anomalies, autonomously responds via Antigena.
DLP and endpoint security with context-aware policies for data usage across endpoints, networks, cloud.
Managed threat-hunting service on top of CrowdStrike Falcon; 24/7 human-led analysis to validate stealthy intrusions.
Deception-based identity-threat detection. Plants fake credentials and decoy paths to surface attacker lateral movement. Illusive Networks acquired by Proofpoint, 2022.
Attack-chain visualization, IOC search, sandboxing, and threat-intel integration with centralized management.
Lightweight EDR with strong remediation; ransomware rollback and post-infection recovery.
Antivirus, endpoint protection, EDR (Defender for Endpoint), and XDR ties to Sentinel and Entra ID.
Unified EPP/EDR with behavioral AI, autonomous response, rollback on Windows, and threat-hunting telemetry.
Next-gen AV plus EDR with deep learning and exploit prevention; strong investigation tools for SMB and enterprise.
Endpoint protection, email security, DLP, and EDR; global sensor network feeding detection and response.
Part of the broader Trellix XDR; detection, investigation, and response with behavioral analytics and forensic timelines.
XDR correlating telemetry across email, endpoint, server, and cloud workloads.
The kit that turns a disk image, a memory dump, or a phone into a defensible report.
Open-source forensics platform on The Sleuth Kit; timeline analysis, keyword search, file carving, media analysis.
DFIR tool focused on memory, disk, mobile, and cloud forensics; parses encrypted containers and RAM dumps.
Industry standard for mobile-device extraction and analysis; UFED covers a wide range of devices.
Long-standing digital-investigation suite; acquisition, indexing, analysis, and court-admissible reporting.
Forensics across computers, mobile, cloud, IoT; powerful artifact parsing and cross-source correlation.
Mobile forensics for law enforcement; XRY for extraction, XAMN for evidence visualization, XEC for lab management.
Mobile, cloud, drone, and IoT forensics with deep parsing of app data including secure messengers.
Lightweight, fast forensic suite with strong scripting and hex-level analysis for deep investigations.
Who you are, what you can touch, and how the SOC proves it.
Privileged access management; just-in-time access, password vaulting, session monitoring, endpoint privilege management.
Market leader in PAM; credential rotation, secret management, session monitoring, secure remote access.
MFA, device trust, and contextual access; widely used for remote access and SaaS protection.
Enterprise IAM with lifecycle management, governance, AI-driven access recommendations, and risk-based auth.
Identity platform with SSO, MFA, lifecycle management, and federation across thousands of apps.
IGA with lifecycle, RBAC, privileged access governance; unifies AD, Azure AD, and cloud platform identity.
Cloud-first identity for SSO, MFA, and customer IAM; strong hybrid and multi-cloud support.
Identity governance with least-privilege enforcement, access reviews, and ML-driven anomaly detection.
Where the wire is inspected. Flow data, deep packet inspection, NIDS, and scanners.
Cloud-delivered DNS-layer security; blocks malicious domains at resolution time, secures outbound web traffic.
IT asset discovery and inventory; CMDB foundations and continuous visibility into devices, software, and users.
Cisco-developed protocol for flow-based monitoring and anomaly detection; metadata about traffic sessions.
Vulnerability management with dynamic scans and exploitability-based prioritization; pairs with Metasploit.
Vulnerability scanner with authenticated/unauthenticated scans and compliance framework support.
Network intrusion detection: inspects traffic for signatures, protocol anomalies, and behavioral indicators.
Open-source NIDS with deep packet inspection and a large community rule set maintained by Cisco Talos.
Open-source NIDS/IPS with multi-threaded inspection, file extraction, TLS inspection, and JSON output.
File-integrity monitoring and change detection; enforces baselines and supports compliance.
Open-source packet analyzer; deep protocol decoding for investigation and forensics.
Behavior-focused network monitoring producing structured session logs for SIEM-friendly analytics.
Where playbooks live, alerts get enriched, and analysts get back their afternoons.
XDR with autonomous investigation and remediation playbooks aimed at small-to-mid SOCs.
Open-source forensic-artifact collector from ANSSI (the French national cyber agency). Runs on Windows endpoints to gather a broad, configurable set of artifacts for offline post-compromise analysis. Not a case-management platform.
SOAR with advanced playbooks, threat-intel enrichment, KPI tracking, and human-in-the-loop decisions. DFLabs acquired by Sumo Logic, 2021.
Comprehensive SOAR with case management, threat intel, playbook-driven automation, and hundreds of integrations.
ITSM and security workflow with ticketing, change management, CMDB integration, and security automation.
SOAR with case management, playbooks, and analyst dashboards; integrated with Google SecOps (Chronicle) telemetry. Siemplify acquired by Google, 2022; fully integrated into Google SecOps.
Security orchestration, automation, and response: define, automate, and orchestrate IR workflows at scale.
SOAR with Python-based playbooks, 300+ integrations, and deep Splunk analytics ties. Phantom acquired by Splunk in 2018 and renamed Splunk SOAR in 2021; Splunk itself acquired by Cisco, 2024.
Low-code SOAR for SOC analysts to build automation workflows without deep programming expertise.
Open-source IR platform with collaborative case management; integrates with Cortex for automated analysis.
No-code automation built for security teams; modular βstoriesβ for alert ingestion, enrichment, and response.
Sandboxes for malware, honeypots for attackers, and frameworks for stress-testing defenses.
Interactive malware sandbox with behavioral and network analysis for collaborative investigation.
Deception platform deploying low-interaction honeypots that produce high-fidelity alerts on attacker interaction.
Open-source automated malware analysis running suspect files in VMs and capturing behavior.
Deception platform with realistic traps and decoys to misdirect attackers and surface intrusion attempts.
Deception technology focused on detecting lateral movement via decoys and traps that mimic real assets.
Controlled attack simulations to validate detection and response based on real-world TTPs.
Offensive emulation and red-team tooling to stress-test defenses with realistic adversary behavior.
Breach-and-attack simulation continuously testing defenses across the kill chain.
Deception with decoys and lures mimicking real IT; alerts on engagement and provides attacker-TTP insight.
Threat-intel platform with playbooks for attack simulation, response automation, and intel-driven workflows.
Cloud sandbox combining behavior analysis with threat intelligence for advanced-malware investigation.
Deception and threat detection with decoys across endpoints, networks, and cloud. TrapX Security acquired by Commvault, 2022; rebranded as ThreatWise.
Security-controls validation through simulated real-world attacks; risk-based testing and gap identification.
Threat research and malware sandboxing powering Zscalerβs cloud security services.
Scanners, fuzzers, and surface-discovery tools that find the holes before adversaries do.
Automated web vulnerability scanner for SQLi, XSS, misconfig, and modern-web/SPA technologies.
Industry-leading web app security tooling: intercepting proxy, scanning, manual pentest tools, and extensions.
Internet-wide asset discovery via continuous scanning; SSL/TLS, services, and attack-surface monitoring.
Open-source web-server scanner for dangerous files, outdated components, and known issues.
Network discovery and security auditing with rich NSE scripting for service detection.
Free, open-source web app security testing with automated and manual capabilities.
Cloud-based vulnerability management, policy compliance, and web app scanning across enterprise estates.
Search engine for internet-connected devices; identifies exposed services, outdated software, ICS, IoT.
Vulnerability management platform; Nessus-based scanning with on-prem, cloud, and hybrid coverage.
Open-source web app scanner combining automated checks with a manual testing framework.
Open-source command-line web vulnerability scanner; crawls and injects payloads for common flaws.
What you actually need before ransomware shows up, backups, immutability, and recovery posture.
Backup with integrated anti-malware; blockchain-based notarization and broad workload coverage.
Unified data protection with replication, HA, and ransomware-resistant immutable storage.
Cloud-based backup and DR for SMBs; encrypted transmission, hybrid backup, ransomware features.
Cloud-native endpoint data protection focused on insider risk and self-service restore.
Unified data management; backup, archive, governance, and SaaS-app protection with AI analytics.
Cloud-native, agentless data protection for endpoints, data center, and cloud workloads.
Cloud-native data management; instant recovery, immutable backups, and ransomware detection.
Backup and recovery across virtual, physical, and cloud workloads with cloud-mobility options.
Enterprise-grade backup with broad workload coverage and centralized hybrid-cloud management.
The languages, frameworks, and editors that the rest of security operations runs on top of.
Open-source automation for config management, deployment, and orchestration via YAML playbooks.
Cross-platform desktop app framework using web technologies; powers Cursor, VS Code, Slack, and more.
Open-source CI/CD automation server; builds, tests, and deploys with a vast plugin ecosystem.
Event-driven JavaScript runtime on V8; backend services, APIs, automation scripts, and tooling.
Task automation and configuration shell built on .NET; cross-platform via PowerShell Core.
High-level language ubiquitous in security tooling, automation, data analysis, and ML.
Lightweight, extensible code editor from Microsoft; rich ecosystem of extensions for development and security.
Tools that keep the fleet patched, the baselines enforced, and the auditors quiet.
Web-based interface for Ansible automation; RBAC, scheduling, visual dashboards, workflow orchestration.
Endpoint management platform automating patching, compliance, and security configuration at scale.
Infrastructure-as-code platform enforcing security configurations via recipes and cookbooks.
Formerly System Center Configuration Manager (SCCM). Patching, software distribution, and compliance for Windows ecosystems; now part of the Microsoft Intune family alongside cloud-only endpoint management.
Free Microsoft tool for centrally approving and distributing Windows updates within an organization.
Automates installation and updates of popular third-party software across many endpoints.
Config management automating patching and continuous compliance through code-defined policies.
Cloud-based patching tied to vulnerability management; prioritizes patches by risk exposure.
Centralized patching for Windows and third-party apps; integrates with WSUS and Microsoft Configuration Manager (MECM/SCCM).
Patch management, software distribution, and configuration enforcement across enterprise endpoints.
Cameras, badge readers, intrusion detection, and the tools that bridge physical and cyber.
HD surveillance, video analytics, and access control with AI-powered anomaly detection.
Pioneer of network video surveillance; broad IP-camera portfolio with edge analytics.
Surveillance, intrusion detection, access, and fire across enterprise and critical-infrastructure deployments.
Converged networking-plus-security platform unifying surveillance, access, and IoT device management.
Unified Security Center for video surveillance, access control, and license plate recognition.
Integrated physical security: surveillance, access, intrusion detection, alarms across critical infrastructure.
Physical security with OpenBlue platform; security plus building automation, with cybersecurity built in.
OnGuard access control, video, and alarm management for enterprise environments.
Open-platform IP video management with broad camera support and rich analytics.
Surveillance cameras, recorders, and VideoXpert management; rugged builds for outdoor and industrial use.
End-to-end surveillance with the Valerus VMS platform; open architecture and flexible deployment.