# CyberSources' first table is a directory of commercial people-search services, and its anchors use three conventions

> A curated list with no code, whose navigation mixes deobfuscators with documentaries, whose one link appears twice in the same table with two different descriptions, and whose sponsor sells infostealer intelligence behind a commented-out line.

**bst04/CyberSources** — A curated list of cybersecurity tools and resources.

- Repository: https://github.com/bst04/CyberSources
- Website: https://www.cybersources.site
- Stars: 2,434 · Forks: 266
- Language: Unknown
- License: MIT
- Published: 2026-09-28 · Updated: 2026-09-28 · Language: en
- Canonical page: https://hysenlabs.com/projects/bst04-cybersources

## The first table is a directory of commercial people-search services

Open the list and the first thing you get is thirteen rows, and read carefully they are not thirteen security tools.

Several are facial recognition services for reverse image searches. Two are face-comparison sites that compare facial images to find matches. One is a service described on the page as being for locating and investigating individuals. Another is described as finding people using names, images or other details. One is an AI-driven reverse image platform, and one is a general-purpose visual search engine.

So the opening category of a security resource list is, in its majority, a set of commercial products whose business is indexing people and matching faces. That is a coherent thing for a curated list to contain; those tools are genuinely used in investigations. It is also worth knowing that you are being pointed at subscription vendors rather than at techniques, because the business model shapes what the tool returns and what it records.

The list does not mark which entries are free, which have a paid tier, or which are commercial at all. The descriptions are four or five words each, written in the passive voice, and the pricing model of a facial recognition search service is exactly the kind of thing a five-word description cannot convey.

## One readme, one directory, and a language the platform cannot classify

The whole repository is three entries at the root: the automation directory, the licence, the readme. And one more directory, whose name matches the project.

There is no code, no build configuration, no test suite, no package manifest and no release. The platform's own language field for the repository reads as unknown, which is the correct outcome for a list of links and is worth naming because it tells you what kind of thing this is before you read a word of it.

The companion directory is presumably the website that the readme links to as the project homepage. Which means the artefacts are two: a markdown file that people clone, and a site they visit. Neither is versioned. There are no GitHub releases, so there is no tag to point a colleague at and nothing to diff between the copy you read last month and the copy in front of you now.

For a list whose entire value is that entries keep working, that is the real structural weakness. A tool that disappears is a broken link, and a link that quietly stops being maintained is worse than a link that visibly rots. Nothing in the repository structure lets a reader tell which of the two has happened.

The licence is MIT, which covers the curation. It says nothing about the hundreds of third-party products listed inside it, which is the correct division and also the reason the list can be maintained without asking anyone's permission.

## The navigation uses three anchor conventions and one link is missing a bracket

The table of contents is long, twelve top-level groups, and it is generated by something that has clearly fought with the headings it is generating from.

Three different fragment styles appear in the same list. Some entries carry a numbered prefix, four digits then two hyphens, which is what happens when the heading itself is numbered. Others carry a hyphen with no number at all, which is what happens when the heading is not. And a third group carries a percent escape for a variation selector, which means some of those headings begin with an emoji and the generator encoded it into the fragment.

Inside the social-networks group the numbering runs to four digits for the tenth entry, so the numbering scheme there is positional across the whole group rather than per-subgroup, which is why one anchor reads like a four-digit index into a list of nine.

There is also a spelling error in a heading, in the binary exploitation category, which means every link pointing at it inherits the typo.

None of this breaks the page, and all of it is the signature of a hand-maintained list rather than a generated one. A list this size would be much better served by generating the navigation from the headings, which would fix all four problems at once and make the table of contents stop being something a contributor has to touch when they add an entry.

## One link appears twice in one table with two different descriptions

The first table has thirteen rows, and two of them point at the same address.

The row near the top is described in three words as a large collection of security tools. The row near the bottom is described differently, as an extensive repository of security tools and techniques. Same address, different sentence.

Neither description is wrong, which is exactly what makes it interesting. Two people curated this list, or one person curated it twice, and each pass wrote a fresh description for a link they had already chosen. Nobody removed the first one, because removing it would have meant deciding which description was right.

That is the characteristic failure mode of a hand-maintained list, and it is benign here. It is worth naming because the same process produced the inconsistent anchors and the malformed link in the first row, where a repository link is missing its closing bracket. Those three artefacts are all the same phenomenon: the list is edited by appending, and the appends are not reconciled against each other.

None of it is dangerous. All of it is a reason to treat the list as a starting point rather than as a reference, and a reason for the project to add a link checker, which is a one-line configuration in most static site generators.

## The sponsor's line of business is infostealer intelligence, and the sentence describing it is commented out

The header contains a sponsorship block above the content, and it is the first thing after the welcome paragraph.

The sponsor is a commercial intelligence vendor, and the block links to its free tools page. Directly beneath the visible link there is an HTML comment, invisible when the page renders, whose text explains what the sponsor's tools do: use them to learn how infostealer infections are impacting your business.

So the person funding this list makes its money from tracking commodity credential-stealing malware infections, and the sentence explaining that was written and then commented out, presumably to keep the header short.

That is a defensible choice and a slightly awkward one. The sponsor is not a security vendor of the usual kind; it is a company whose product is visibility into breaches caused by information-stealing malware, sold to enterprises that need to know whether their credentials are in a criminal market. That is a real and useful product, and it is also a business whose incentives point towards alarming language about your organisation.

For a reader, the practical point is that a sponsored entry is a marketing placement. The block sits above the content rather than beside a tool, so it is easy to read as a general endorsement of the list rather than as one paid link, which is presumably not what was intended.

## Twelve groups that mix attack tools with documentaries and LinkedIn creators

Look at the shape of the navigation and the axis it uses becomes clear, and it is not a single one.

Some groups are attack surfaces: username search, email search, phone number search, photo search, and a social-network group that runs to ten platforms. Some are protocols and hardware: RFID, WiFi, Bluetooth, closed-circuit television. Some are defensive: password managers, VPNs, privacy tooling, and a group whose entry is about deleting your traces. Some are offensive techniques: post exploitation, deobfuscators, decompilers, disassemblers and debuggers, network and web, cracking.

And then the rest. There is a group of learning resources with sub-entries for courses, certifications, tutorials, practice sites, capture-the-flag training, open-source repositories, a learning path and project-based work. And a group of social and media: events, community, podcasts, documentaries, books and papers, television shows, video channels and LinkedIn creators.

All of that is useful. But it means the navigation is a flat hierarchy where a deobfuscator, a learning path and a documentary are one click apart, and there is no signal anywhere about which entries the curator considers good. Every entry has a link and a short description. None has a recommendation, a difficulty, a date, a licence, or a note about whether it still works.

## Conclusion

Treat this as a directory rather than as a course. Its value is breadth, the fact that someone has grouped hundreds of links by task, and a website for searching them. Its limits are equally plain. There is no opinion anywhere in the categories, no version information, no dates on entries, and a first table made almost entirely of paid people-search products. If you want a structured curriculum with prerequisites, the learning section lists some, but the list itself will not tell you where to start.

## FAQ

### What is CyberSources?

An MIT-licensed curated list of cybersecurity tools and resources, organised into twelve groups from OSINT and pentesting through cryptography, forensics, anonymity, artificial intelligence tools, hardware, learning resources and media. The repository holds a readme and a companion site directory, with no code and no releases.

### How large is the CyberSources list?

The navigation covers twelve top-level groups with between four and eighteen sub-entries each, from four-digit section numbers down, plus a repository group for star history, collaboration and credits. The visible first table alone has thirteen rows of tools.

### Does CyberSources say which tools are best?

No. Every entry is a link with a short description, and there is no ranking, difficulty marker, date, licence note, or recommendation anywhere in the visible list. The stated goal is to be a central hub for the field rather than a comparison.

### What sponsors CyberSources?

A commercial intelligence vendor whose free tools page is linked in a sponsorship block above the content. A commented-out line in the source describes them as tools for learning how infostealer infections are impacting your business.

### Where do I find the CyberSources website?

At the project's own domain, linked from the header image and recorded as the repository homepage. The header also carries a community link to a chat server with a self-reported membership count and a separate link to a subreddit.

## Sources

- [bst04/CyberSources on GitHub](https://github.com/bst04/CyberSources)
- [Issues](https://github.com/bst04/CyberSources/issues)
- [License: MIT](https://github.com/bst04/CyberSources/blob/main/LICENSE)
- [Project website](https://www.cybersources.site)
- [README](https://github.com/bst04/CyberSources/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bst04-cybersources
