Live ransomware tracking, threat news, vendor research, vulnerability advisories, and the tradecraft references I use day to day. Migrated from start.me, maintained here.
Real-time ransomware tracking, exploited CVE catalog, live threat maps. Stealer-log / dark-web monitoring lives in OSINT & Intel.
Lookup public IPv4 and IPv6 reputation data from IPQS.
Merged feed across 31 security-dedicated outlets, time-sorted. Includes original start.me sources plus first-to-break outlets (Risky Bulletin, Zetter Zero Day, 404 Media, Cybersecurity Dive, StateScoop / FedScoop, CISA News, NCSC UK, Tao Security). General-tech outlets excluded.
Merged feed across 53 vendor research blogs that publish RSS, plus a directory of major vendors that have stopped publishing RSS so you can still navigate to them.
Merged feed across 10 offensive / tradecraft blogs.
CVEs, KEV updates, vendor advisories, proof-of-concept exploits.
Currently active threat campaigns. Each card links to canonical writeup, group profile, or live tracker. LOL catalogs included since campaign TTPs operate through them.
Comprehensive offensive + defensive tooling, all categories in one tab. Includes Josh's own Fibratus Fleet fork in the EDR panel.
Detection-as-code, hunting frameworks, atomic emulation, Sigma/YARA. The Featured panel highlights the chokepoints framework and DetectionStream — both are mental models / platforms worth orbiting around.
Threat-intel portals, OSINT, reputation, paste sites, dark web, plus the Flare-tier paid landscape vs. free options.
Annual threat reports, deep technical references, frameworks, standards, and learning platforms (incl. Threat Hunting Labs, DetectionStream).