Open-source project
bst04/CyberSources avatar
bst04/CyberSources

CyberSources: a curated index of security tooling, not a toolkit

A curated list of cybersecurity tools and resources.

2,434 stars266 forksUnknownMIT

At a glance

What is it?
CyberSources is a MIT-licensed Markdown list of cybersecurity tools, learning material and community links, published at cybersources.site. It is an index you read, not software you install, and its value depends on how much you trust an unversioned README to stay current.
Who is it for?
Adopt CyberSources as a browsing aid when you need a starting point across OSINT, pentesting, forensics and learning material, and treat each entry as a lead to verify rather than a vetted recommendation. Skip it if you need pinned versions, changelogs or a machine-readable feed, because the repository ships a README and a cybersources/ directory and nothing resembling a package.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 12 days ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem CyberSources solves: too many tabs, no index

Security work starts with a search problem. A newcomer looking for an email lookup tool, a hex editor, a decompiler or a CTF practice site has no shortage of options and no easy way to compare them. CyberSources answers that with a single Markdown table of contents that spans OSINT, pentesting, cryptography, forensics and malware analysis, anonymity tools, AI tooling, hardware and operating systems, learning resources, and community media such as podcasts, documentaries and YouTube channels. Each category is a table of tool names, links and one-line descriptions. The README states the project is a central hub for tools, resources and educational materials aimed at professionals, enthusiasts and learners.

The audience is therefore broad in a way that cuts both ways. A student working through certifications gets a reading list. A working analyst gets a reminder of categories they have not touched, such as RFID or CCTV tooling. What nobody gets is curation with criteria attached: the README does not state how tools are selected, when entries are reviewed, or what happens when a linked project goes dormant. That is the honest shape of the project. It is a directory, and directories are judged by freshness and coverage rather than by cleverness.

How the repository is organised and what ships with it

The top level of bst04/CyberSources holds .github/, LICENSE, README.md and a cybersources/ directory. The README carries the banner image and the Discord and Reddit badges, a sponsor block for Hudson Rock's free tools, and then the content itself: numbered sections from 1.1 OSINT through to the repository's own Stars History, Collaborate and Credits sections, with anchor links back to the table of contents at the top of each block.

That structure tells you what kind of artefact this is. There is no build step, no dependency manifest, no schema and no generated output described in the README. The content is the product, and the cybersources/ directory holds the assets the README points at, such as the banner image. The README also documents its own contribution surface through the Collaborate section, and it exposes a Stars History section, but it does not describe an editorial process, a review cadence or a way to flag a dead link other than opening an issue or a pull request.

The practical consequence is that diffing the README is the only reliable way to see what changed. There are no releases recorded for the repository, so there is no changelog to read.

Using CyberSources without installing anything

There is nothing to install. The README does not document a package, a CLI, a server or a configuration file, so any tutorial that shows you a build command would be inventing one. The project is consumed in a browser, either on GitHub or on its homepage at https://www.cybersources.site.

The README's own example of getting the repository locally is a clone:

bash
git clone https://github.com/bst04/CyberSources.git

After that, README.md is the file you read. You can also open the repository on GitHub and use the table of contents anchors at the top of the README to jump to a numbered section such as 1.1 OSINT or 4.4 Malware Analysis. From there, follow the outbound links in the tables. If you want to propose an addition, the README's Collaborate section is the entry point, and the repository also links its Discord community at http://discord.gg/cybersources for discussion.

Where a curated list falls short

Link rot is the structural weakness. Every row in CyberSources is an outbound URL to someone else's project, and the README carries no last-checked date per entry, no version pin and no status column. A tool that was archived two years ago looks identical in the table to one pushed last week. Nothing in the repository automates link checking as far as the README describes, so the only signal that an entry has gone stale is a reader noticing.

The descriptions are also one line each and sometimes duplicated. The OSINT section lists OSINT Framework twice, at osintframework.com and again at the same domain without the trailing path, with two different descriptions. That is a small thing, but it is the kind of thing a maintained index would catch, and it tells you the tables are edited by hand across many contributors.

Finally, the project is not a substitute for a lab. It points at cracking, post-exploitation and malware analysis tooling without stating scope, legality or safe-handling guidance for any of it. If you need a controlled environment with documented setup, this repository will not give you one. It gives you names.

CyberSources compared with the OSINT Framework and awesome lists

The closest thing to a peer inside CyberSources' own pages is the OSINT Framework, which the README lists as a huge collection of OSINT tools. The difference is shape. OSINT Framework presents a branching tree that you navigate by investigation type, so the path itself carries meaning: you start from a category such as username or email and drill down. CyberSources presents flat numbered tables with a description column. Flat tables are faster to scan and easier to diff in Git, but they lose the decision structure, which is why the README still links out to the tree rather than trying to reproduce it.

Generic awesome lists take a third approach: they are usually scoped to one domain and lean on contribution guidelines and CI checks to keep entries tidy. CyberSources is broader in scope than most single-domain lists, covering everything from RFID to TV shows, and correspondingly shallower per topic. If you want depth on one subject, a domain-specific list will beat it. If you want one bookmark that reminds you which categories exist, breadth is the point.

Maintenance, licence and the cost of keeping up

The repository is not archived, and the last push was on 2026-09-21, which is recent enough that the tables are likely close to current. That date is the only maintenance signal available here: no releases were recorded, so there is no version history to reason about and no upgrade path to plan. Upgrading means pulling the latest README and re-reading the diff, which is cheap in effort and zero in infrastructure.

The licence is MIT, which places few restrictions on reuse, modification and redistribution, provided the copyright notice and permission notice are preserved. Because the repository is mostly a collection of links and short descriptions rather than code, the licence covers the list itself and not the tools it points at. Each linked project carries its own licence, and some of the categories in the README, such as cracking and post-exploitation tooling, include projects whose terms differ substantially from MIT. Check the linked repository before you reuse or redistribute anything from it. None of this is legal advice; read the LICENSE file in the repository and the licence of each tool you actually adopt.

Editorial conclusion

Adopt CyberSources as a browsing aid when you need a starting point across OSINT, pentesting, forensics and learning material, and treat each entry as a lead to verify rather than a vetted recommendation. Skip it if you need pinned versions, changelogs or a machine-readable feed, because the repository ships a README and a cybersources/ directory and nothing resembling a package. Before relying on any single entry, open the linked tool's own repository and check when it was last pushed, since CyberSources itself records no per-tool status, no version and no maintenance date.

Frequently asked questions

Is CyberSources the same thing as Cybersource, the payment gateway?

No. bst04/CyberSources is a curated list of cybersecurity tools and resources hosted on GitHub with a homepage at cybersources.site. Cybersource, the payment platform, is an unrelated product with its own website and support channels.

Do I need to install anything to use CyberSources?

No. The README documents no package, CLI or server, so the project is consumed by reading README.md on GitHub or browsing cybersources.site. You can clone the repository if you want the tables locally, but nothing needs to be built or configured.

What kinds of tools does CyberSources cover?

Its table of contents spans OSINT, pentesting, cryptography, forensics and malware analysis, anonymity and security tools, AI tools, cryptocurrency and SIEM, operating systems and hardware, plus learning material, certifications, CTFs and community media such as podcasts and YouTube channels.

How do I contribute a tool to CyberSources?

The README includes a Collaborate section as the contribution entry point, and the project also runs a Discord community linked from the README. The README does not describe a review checklist or acceptance criteria, so expect the maintainers' judgement to decide.

Official sources

  1. bst04/CyberSources on GitHub
  2. Issues
  3. License: MIT
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/bst04-cybersources.svg)](https://hysenlabs.com/projects/bst04-cybersources)