๐ Research Resource Directory โ Deep Technical Sources
Direktori sumber daya riset teknis mendalam untuk keamanan siber โ khusus Digital Forensic, Attack Defense, dan Incident Response. Bukan sekadar daftar link, tapi peta sumber daya dengan konteks penggunaannya. Dibuat dari riset Jina DeepResearch + kurasi manual. Untuk metodologi praktik, lihat ctf-competition-methodology-strategy. Untuk tools, lihat ctf-tool-arsenal-universal.
Daftar Isi
- Fondasi Riset Lanskap
- Digital Forensic โ Tools & Framework
- Digital Forensic โ Metodologi & Studi Kasus
- Attack Defense โ Exploitation & Defense
- Attack Defense โ Metodologi & Latihan
- Incident Response โ Tools & Platform
- Incident Response โ Framework & Studi Kasus
- Platform Latihan Multi-Kategori
Fondasi Riset Lanskap
| Sumber | URL | Kapan Dipakai |
|---|---|---|
| MITRE ATT&CK | https://attack.mitre.org/ | Mapping TTP attacker โ setiap kali analisis malware/APT |
| MITRE D3FEND | https://d3fend.mitre.org/ | Countermeasure mapping โ defense technique against specific attack |
| SANS Reading Room | https://www.sans.org/reading-room/ | Whitepaper teknis โ forensic imaging, memory analysis, IR playbook |
| Black Hat Archives | https://www.blackhat.com/archives.html | Slide & video presentasi โ 0day, teknik baru, research terdepan |
| DEF CON Archives | https://defcon.org/html/defcon-archive/defcon-archive.html | Sama โ lebih ke komunitas & tool release |
| Google Scholar | https://scholar.google.com/scholar?q=cyber+security | Jurnal akademik โ memory forensic techniques terbaru, ML untuk deteksi |
| OWASP Top 10 + WSTG | https://owasp.org/www-project-web-security-testing-guide/ | Web vulnerability reference โ test case per kerentanan |
| Exploit-DB | https://www.exploit-db.com/ | PoC exploit โ cari CVE spesifik, belajar teknik exploit |
| CVE Details | https://www.cvedetails.com/ | Database CVE โ severity, CWE, products affected |
Digital Forensic โ Tools & Framework
Memory Forensic
| Tool | URL | Fungsi |
|---|---|---|
| Volatility Foundation | https://www.volatilityfoundation.org/ | Framework utama โ profile detection, plugin ekstensi |
| Volatility 3 GitHub | https://github.com/volatilityfoundation/volatility3 | Source code + plugin komunitas |
Deep skill: inject detection (process hollowing, DLL injection), rootkit hidden process, credential extraction (NTLM hash dari lsass), network artifact reconstruction dari memory.
Disk Forensic
| Tool | URL | Fungsi |
|---|---|---|
| Autopsy / Sleuth Kit | https://www.autopsy.com/ | GUI + CLI โ MFT analysis, timeline, keyword search, carving |
| FTK Imager | https://www.exterro.com/ftk-imager/ | Forensic imaging โ bit-by-bit, preview, hashing |
| Magnet AXIOM | https://www.magnetforensics.com/products/magnet-axiom/ | All-in-one โ disk + mobile + cloud artifact analysis |
Network Forensic
| Tool | URL | Fungsi |
|---|---|---|
| Wireshark | https://www.wireshark.org/ | Display filter kompleks, stream reassembly, protocol deep-dive |
| Zeek (Bro IDS) | https://zeek.org/ | Log-based traffic analysis โ conn.log, dns.log, http.log, ssl.log |
Mobile Forensic
| Tool | URL | Fungsi |
|---|---|---|
| Cellebrite | https://www.cellebrite.com/ | Ekstraksi fisik/logis โ iOS/Android, bypass lock |
| Oxygen Forensic Detective | https://www.oxygen-forensic.com/ | Analisis data aplikasi, cloud backup, timeline visual |
Digital Forensic โ Metodologi & Studi Kasus
| Sumber | URL | Isi |
|---|---|---|
| NIST SP 800-86 | https://csrc.nist.gov/publications/detail/sp/800-86/final | Integrasi forensik ke IR โ standar pemerintah AS |
| DFIR Process (ident-preserv-collect-analyze-report) | โ | Chain of custody, write-blocker, hashing, imaging valid |
| CyberDefenders | https://cyberdefenders.org/ | Tantangan DFIR โ memory, disk, PCAP, malware analysis |
| TryHackMe DFIR Paths | https://tryhackme.com/ | Room IR + forensik โ skenario realistis, tools siap pakai |
| Magnet Forensics CTF | https://www.magnetforensics.com/blog/category/ctf/ | CTF forensic โ writeup kompetisi sebelumnya |
| Verizon DBIR | https://www.verizon.com/business/resources/reports/dbir/ | Data breach real โ statistik, root cause, lessons learned |
Attack Defense โ Exploitation & Defense
| Tool | URL | Fungsi |
|---|---|---|
| Metasploit Framework | https://www.metasploit.com/ | Exploit dev, payload crafting (reverse/bind), post-exploitation |
| Burp Suite | https://portswigger.net/burp/ | Web proxy โ intercept, repeater, intruder, sequencer |
| SQLMap | http://sqlmap.org/ | SQL injection automation โ boolean, time, error, out-of-band |
| Nmap + NSE | https://nmap.org/ | Network scanning + scripting engine โ vuln detection, backdoor scan, brute |
| Ghidra | https://ghidra-sre.org/ | Reverse engineering โ decompiler, disassembler, scriptable (Java/Python) |
| IDA Free | https://hex-rays.com/ida-free/ | Disassembler โ decompiler limited, tapi standar industri |
| AFL / LibFuzzer | https://lcamtuf.coredump.cx/afl/ โ https://llvm.org/docs/LibFuzzer.html | Fuzzing โ bug hunting otomatis, coverage-guided |
Attack Defense โ Metodologi & Latihan
| Sumber | URL | Isi |
|---|---|---|
| OSSTMM v3 | https://www.isecom.org/OSSTMM.3.pdf | Standar pengujian keamanan โ channel, class, vector |
| PTES | http://www.pentest-standard.org/index.php/Main_Page | Standar pentest โ pre-engagement โ reporting |
| Hack The Box | https://www.hackthebox.com/ | Box realistis โ active + retired, walkthrough komunitas |
| TryHackMe Red Team | https://tryhackme.com/ | Red team path โ exploit dev, web hacking, AD |
| VulnHub | https://www.vulnhub.com/ | VM vulnerable โ download + run local, full pentest |
| PortSwigger Academy | https://portswigger.net/web-security | Lab interaktif web vuln โ SQLi, XSS, SSRF, RCE |
| Project Zero Blog | https://googleprojectzero.blogspot.com/ | 0day deep-dive โ teknik finding, exploitation chain |
| CTFTime Writeups | https://ctftime.org/writeups/ | Solusi CTF global โ filter by category, year, event |
Incident Response โ Tools & Platform
| Tool | URL | Fungsi |
|---|---|---|
| ELK Stack | https://www.elastic.co/ | Log aggregation + search + dashboard โ indeks milyaran log |
| Splunk | https://www.splunk.com/ | SIEM enterprise โ SPL query language, correlation rules |
| Osquery | https://osquery.io/ | SQL-like endpoint query โ threat hunting across fleet |
| Sysmon | https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon | Windows logging advanced โ process, network, registry, file change |
| MISP | https://www.misp-project.org/ | Threat intelligence sharing โ IOC correlation, feed integration |
| SOAR (konseptual) | โ | Automation playbook โ block IP, isolate host, collect forensic data |
Incident Response โ Framework & Studi Kasus
| Sumber | URL | Isi |
|---|---|---|
| NIST SP 800-61 Rev 2 | https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final | Bible IR โ preparation โ detection/analysis โ containment โ eradication โ post-incident |
| Cyber Kill Chain | https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html | 7 tahap serangan โ recon โ weaponize โ deliver โ exploit โ install โ C2 โ exfil |
| CyberDefenders IR | https://cyberdefenders.org/ | Tantangan IR โ malware analysis, log analysis, threat hunting |
| DFIR Report | https://thedfirreport.com/ | Analisis insiden nyata โ artefak, timeline, TTP, IOC |
| SANS IR Resources | https://www.sans.org/incident-response/ | Whitepaper, webcast, playbook โ dari pelatihan SANS |
Platform Latihan Multi-Kategori
| Platform | URL | Fokus | Cocok Untuk |
|---|---|---|---|
| CyberDefenders | https://cyberdefenders.org/ | DFIR | Forensic + IR |
| Hack The Box | https://www.hackthebox.com/ | Offensive | Web, PWN, AD, Crypto |
| TryHackMe | https://tryhackme.com/ | Beginner-friendly | Semua kategori โ learning path |
| VulnHub | https://www.vulnhub.com/ | Offline VM | Pentest full scope |
| PortSwigger Academy | https://portswigger.net/web-security | Web khusus | Web vuln dari basic โ advanced |
| PicoCTF | https://picoctf.org/ | Beginner CTF | CTF pemula โ kategori lengkap |
| CTFTime | https://ctftime.org/ | Jadwal + writeup | Semua event + solusi |
| Blue Team Labs Online | https://blueteamlabs.online/ | Blue team | Forensic, IR, SOC simulation |
Cross-Link
- Atlas CTF Framework โ hierarchy-ctf-competition-framework
- Methodology & Strategy โ ctf-competition-methodology-strategy
- Tool Arsenal โ ctf-tool-arsenal-universal
- Network Forensics โ hierarchy-network-forensics
- Windows Forensics โ windows-forensics-artifact-analysis
- File Carving โ file-carving-data-recovery-advanced
- Attack-Defense Hardening โ attack-defense-hardening-playbook
- Master Index โ master-index
Research Resource Directory ยท Sumber Daya Universal โ Tidak Terikat Event ยท Jina DeepResearch + Kurasi Manual ยท Baca Dulu, Praktik Kemudian