Black Lotus Labs (Lumen) (opens in a new tab)
Why: Lumen threat research arm; China-nexus IoT/proxy quartermaster enablement model — high value for edge/IoT defenders.
Actionable intelligence to understand adversaries, campaigns and techniques. Curated, verified and designed for practitioners.
32 current resources
Highest starting-point strength resources in this category.
Why: Lumen threat research arm; China-nexus IoT/proxy quartermaster enablement model — high value for edge/IoT defenders.
Why: High-yield detection engineering research including agentic post-compromise tradecraft.
Why: Annual CrowdStrike threat landscape report — adversary trends, malware families, and industry risk themes for planners and responders.
Showing 32 resources
Why: Lumen threat research arm; China-nexus IoT/proxy quartermaster enablement model — high value for edge/IoT defenders.
Why: High-yield detection engineering research including agentic post-compromise tradecraft.
Why: Annual CrowdStrike threat landscape report — adversary trends, malware families, and industry risk themes for planners and responders.
Why: Olly Whitehouse (NCSC CTO) Substack — senior UK cyber perspective and pointers to useful practitioner resources.
Why: Google Project Zero researches and discloses high-impact zero-day vulnerabilities with detailed technical write-ups that inform defence and vulnerability management.
Why: Mandiant’s annual M-Trends report — real-world breach findings and frontline response lessons.
Why: Standing hub for identity/edge tradecraft (device-code phishing, TerminalFix, Unicode phishing).
Why: PortSwigger Research publishes practical web-security research papers, tools and techniques used by penetration testers and application defenders.
Why: Red Canary Threat Detection Report — annual study of detections, ATT&CK techniques, and SOC lessons.
Why: Red Canary threat intelligence resources — detection guidance, reports, and practitioner write-ups.
Why: Trusted-infrastructure and evidence-layer tradecraft (e.g. Fire Ant / TACACS).
Why: Verizon DBIR — the industry-standard annual data-breach study used for risk conversations and planning.
Why: Curated GitHub index of annual security and threat reports — a fast way to find this year’s major publications.
Why: Curated open list of threat-intelligence feeds, frameworks and research sources — a practical starting index for building a TI stack.
Why: CERT-EU threat intelligence publications — EU institutional threat reporting and situational awareness.
Why: Standing CPR hub for nation-state and crimeware research (e.g. Lazarus / 0-day campaigns).
Why: Annual DFIR year-in-review — practical incident response lessons and case themes from the DFIR Report team.
Why: ENISA foresight on cybersecurity threats out to 2030 — useful for long-range risk and strategy conversations.
Why: FortiGuard Threat Signal Report — weekly Fortinet roundup of notable threats and exploit activity.
Why: IBM X-Force Threat Intelligence Index — annual view of attack trends, industries hit, and attacker techniques.
Why: Unit 42 research hub — threat reports, actor profiles, and vulnerability write-ups from Palo Alto Networks.
Why: Edge persistence research plus Global Threat Landscape series.
Why: Standing Insikt research hub (Russia initial access, DPRK IT-worker pipelines, etc.).
Why: Kaspersky’s long-running research hub for malware analysis, APT reporting and threat insights used by defenders worldwide.
Why: Sophos annual threat report — ransomware, malware, and attacker behaviour trends for defenders.
Why: Trellix Advanced Research Center threat reports — regular analysis of malware, campaigns, and emerging threats.
Why: BAE Systems threat intelligence newsletter — regular insights from their TI team.
Why: e2e-assure Recon Review — LinkedIn newsletter covering reconnaissance themes and open-source intel.
Why: HP Wolf Security Threat Insights — annual report on malware delivery, browser threats, and endpoint risk themes.
Why: NETSCOUT annual threat intelligence report — DDoS, botnet, and network-attack trends from global telemetry.
Why: NSHC ThreatRecon Team on Medium — regular threat research posts and campaign write-ups.
Why: Community-minded internet security organisation offering threat intelligence, reputation data and research for defenders.