Infosec_Reference is a free, open source threat detection & response project written in CSS and released under MIT. It has 5,998 GitHub stars, 1,230 forks and 4 open issues, and was last pushed 11 months ago. On this registry it ranks #17 of 42 tracked projects in Threat Detection & Response, with 5 head-to-head comparisons available.

What is Infosec_Reference?

Infosec_Reference is an MIT-licensed, freely available information security reference maintained as a Git repository and published as a hosted HTML page, intended for anyone from beginners to experienced practitioners who want a curated jumping-off point for techniques, tools, and tactics across offense, defense, and privacy.

What it is

Infosec_Reference is a documentation project that gathers links and pointers to information security knowledge rather than offering installable software. Its README describes the goal as acting as a free resource for anyone interested in learning more about Information Security, presenting a list of techniques, tools and tactics to learn from or reference, and functioning like a "Yellow Pages" in the sense that someone knows something exists but cannot recall what it was called. The project is explicitly not a set of personal notes; it is maintained as a way of having pointers to information that might help build someone's skillset or increase understanding of attacks, methods, and defenses. A hosted HTML version is available at https://rmusser.net/docs, while the source lives in a Git repository on GitHub and at the non-Microsoft mirror https://rmusser.net/git/admin-2/Infosec_Reference.

The concrete problem it solves is the scattered, perishable nature of infosec learning material. Rather than replacing a scanner, a SIEM, or an exploitation framework, it replaces the ad-hoc bookmark folder, the half-remembered tool name, and the personal notes file that goes stale. It lives in the information security ecosystem as a reference and recall aid, offering a jumping-off point for various niches or a way to look up material by topic. The README also notes that the project is not meant to condone illegal or malicious activities, framing the collection as educational.

Key capabilities

  • An index that links to dedicated Pre-ATT&CK and ATT&CK material, including an ATT&CK Stuff folder for adversary tactic and technique references.
  • A focused page for Attacking & Securing Active Directory, stored as Active_Directory.md.
  • Anonymity, OpSec and Privacy resources collected in AnonOpSecPrivacy.md.
  • A Basic Security Information section, marked with a beginner label in the index, for people starting in information security.
  • Coverage of BIOS/UEFI/Firmware attack material as a distinct index entry.
  • Topics spanning blueteam, forensics, penetration-testing, hacking, linux, and osx, giving the reference reach across offense, defense, and multiple operating systems.
  • A hosted HTML version at https://rmusser.net/docs, with the latest content updates visible through the repository's git history and contributions of relevant links accepted via Git.

Who uses it and how

  • Beginners use the Basic Security Information section as a structured entry point into information security.
  • Penetration testers and red teamers reference the ATT&CK and Active Directory pages when planning work or trying to recall a technique's name.
  • Blue team, forensics, and threat detection practitioners use the blueteam and forensics topics as a defense-side reference.
  • Privacy and OpSec practitioners consult the Anonymity/OpSec/Privacy page for pointers on operational security.
  • Contributors use GitHub or the non-Microsoft Git mirror to submit relevant links, and the project carries the hacktoberfest and hacktoberfest2021 topics, indicating participation in that contribution event.

Getting started

There is no package, Docker image, or compose file to install; the README directs readers to the hosted HTML version at https://rmusser.net/docs, while the source is available as a Git repository on GitHub and at the non-Microsoft mirror https://rmusser.net/git/admin-2/Infosec_Reference. Contributions of relevant links that are not already covered are accepted.

How it compares

No paid products or comparable tools are named in the provided facts, so this project stands alone in this registry. It occupies the space of a curated link directory and learning aid rather than a scanning, monitoring, or exploitation tool, and its nearest analogue would be a maintained reading list.

When to use it — and when not to

Use it when you need a free, maintained reading list of infosec techniques and tools and do not mind browsing a documentation repository; because it is not a deployable application, there is no database, storage, or SMTP service to operate. It is a poor choice if you need an installable scanner, SIEM, or automated detection platform, and the repository's primary language is CSS while its README includes extended political commentary on US surveillance law, which may not suit readers who want a strictly neutral technical reference. The MIT licence covers the repository itself, but the third-party material it links to carries its own terms.

project readme (upstream, from github) — read inline

InfoSec Reference

Any communicaitons occuring within the United States should be viewed as compromised and no privacy guaranteed unless E2EE was used and verified(Not new).

(New: The US gov now has legal authority to compel recording or monitoring by any citizen within the United States, regardless of their proximity or interaction with the supposed crime being monitored. Among the other issues made possible/enabled through passage of the legislation) I have kept this project non-political, but this is absolutely terrible.

Full support by Biden and his administration as well shows that this is not some partisan issue(Those who claim so, don't be a useful idiot).

I understand that people seem to think I'm a clown, so hopefully this entertainment will help keep this in mind when relevant. There is no other clearer sign of the corruption and ownership of state surveillance apparatus for the haves vs have-nots than this bill.

From https://xkcd.com/1053/

“The first question is by no means whether we are content with ourselves, but whether we are content with anything at all. If we affirm one single moment, we thus affirm not only ourselves but all existence. For nothing is self-sufficient, neither in us ourselves nor in things, and if our soul has trembled with happiness and sounded like a harp string just once, all eternity was needed to produce this one event – and in this single moment of affirmation all eternity was called good, redeemed, justified, and affirmed.”

  • Some Nihilist

Goal:

  • The goal of this project is to act as a free resource for anyone interested in learning more about Information Security.
    • A list of techinques, tools and tactics to learn from or reference.
    • Rich resource of infosec knowledge for anyone to browse through as a jumping off point for various niches OR as a reference/recall method for stuff.
    • Something like a "Yellow Pages" in the sense of you know something exists, but what was it called.... * 'If you give a man a fish, he is hungry again in an hour. If you teach him to catch a fish, you do him a good turn.'
    • To be clear, these aren't personal notes. I keep this repo maintained as a way of having pointers to information that I feel might help build someone's skillset or increase their understanding of attacks/methods/defenses.
  • This project is not meant to condone illegal or malicious activities.
  • For a HTML version of this reference, check out: https://rmusser.net/docs(I'm not a webdev. Can you tell?).
  • For latest content updates, check the git history.
  • Want to contribute a link?
    • Anything relevant that isn't already in or covered would be/is appreciated.
  • If this resource has helped you in any way(and didn't increase your frustration), please consider making a donation to Doctors Without Borders or Amnesty International.

Index - Table of Contents

  • A Quote:

    • "As the Americans learned so painfully in Earth's final century, free flow of information is the only safeguard against tyranny. The once-chained people whose leaders at last lose their grip on information flow will soon burst with freedom and vitality, but the free nation gradually constricting its grip on public discourse has begun its rapid slide into despotism. Beware of he who would deny you access to information, for in his heart he dreams himself your master."
    • Commissioner Pravin Lal, Peacekeeping Forces (Alpha Centauri, 1999)
  • Another Quote:

    • "Nowhere does Bokonon warn against a person’s trying to discover the limits of his karass and the nature of the work God Almighty has had it do. Bokonon simply observes that such investigations are bound to be incomplete. In the autobiographical section of The Books of Bokanon he writes a parable on the folly of pretending to discover, to understand: I once knew an Episcopalian lady in Newport, Rhode Island, who asked me to design and build a doghouse for her Great Dane. The lady claimed to understand God and His Ways of Working perfectly. She could not understand why anyone should be puzzled about what had been or about what was going to be. And yet, when I showed her a blueprint of the doghouse I proposed to build, she said to me, “I’m sorry, but I never could read one of those things.” “Give it to your husband or your minister to pass on to God,” I said, “and, when God finds a minute, I’m sure he’ll explain this doghouse of mine in a way that even you can understand.” She fired me. I shall never forget her. She believed that God liked people in sailboats much better than He liked people in motorboats. She could not bear to look at a worm. When she saw a worm, she screamed. She was a fool, and so am I, and so is anyone who thinks he sees what God is Doing, [writes Bokonon].
    • Cat's Cradle(The Books of Bokonon), Kurt Vonnegut
  • Thucydides, The Peloponnesian War - Athenian envoys:

    • For ourselves, we shall not trouble you with specious pretences—either of how we have a right to our empire because we overthrew the Mede, or are now attacking you because of wrong that you have done us—and make a long speech which would not be believed; and in return we hope that you, instead of thinking to influence us by saying that you did not join the Lacedaemonians, although their colonists, or that you have done us no wrong, will aim at what is feasible, holding in view the real sentiments of us both; since you know as well as we do that right, as the world goes, is only in question between equals in power, while the strong do what they can and the weak suffer what they must.

Frequently asked questions

Is Infosec_Reference free to use?

Infosec_Reference is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does Infosec_Reference do?

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

What is Infosec_Reference written in?

Infosec_Reference is primarily written in CSS. Its source is publicly available at https://github.com/rmusser01/Infosec_Reference, and it has 5,998 GitHub stars.