Resources
Curated references for both sides of the work — offensive tooling and the frameworks, detection material, and hardening guidance that answer it. No affiliate links, no sponsorships, only things I actually reach for.
Security Architecture
NIST Cybersecurity Framework ↗
The core framework for organizing security capabilities around Identify, Protect, Detect, Respond, and Recover.
SABSA Framework ↗
Enterprise security architecture framework used widely in large-scale deployments.
TOGAF Security Architecture ↗
Security architecture guidance within the TOGAF enterprise architecture framework.
Zero Trust
Network Security
CIS Controls ↗
Prioritized set of actions for cyber defense. Useful for understanding what controls matter most.
MITRE ATT&CK Framework ↗
Adversary tactics and techniques knowledge base. Essential for detection engineering and threat modeling.
NSA/CISA Network Security Best Practices ↗
Practical guidance on network segmentation, hardening, and monitoring from NSA and CISA.
Cloud Security
Detection Engineering
Standards and Frameworks
Career Development
These resources are curated based on practical usefulness. The list is not comprehensive — it reflects what I actually reference in my work. If you have suggestions, reach out.