The knowledge we build, we share.
Open-source frameworks, detection engineering tools, red team roadmaps, and practitioner guides — built by SCYTHE and given freely to the security community.
11+
Free resources & guides
2
Open-source frameworks on GitHub
140+
Open-source Sigma detection rules
100%
Free — no paywall, no strings
Open-Source Frameworks
Built by SCYTHE. Owned by the community.
Two production-ready open-source projects for purple team programs and detection engineering pipelines — free, GitHub-hosted, and actively maintained.
Purple Team Exercise Framework v4
SCYTHE's open framework for building a formal purple team program. PTEFv4 adds a Maturity Model, Detection Engineering lifecycle, graded 0–5 outcome scoring, AI/ML coverage mapped to MITRE ATLAS, and 10 printable one-pagers. Free. No C2 required.
Sigma Regression Testing Pipeline
140 open-source Sigma rules for Windows, Linux, and M365/Azure — with automated CI/CD validation, pySigma Splunk conversion, and Atomic Red Team regression testing built in. Every rule in production has passed a real technique execution test. MITRE ATT&CK mapped. Free.
Get the Pipeline — Free GitHub →
eBooks & Reports
Deep dives for security leaders and practitioners.
Practical guides on adversarial emulation, threat exposure management, CTI operationalization, red team maturity, and adversarial behavior detection.
-1.png)
Adversarial Emulation & Validation Guide
How CTEM and AEV transform enterprise security from reactive to proactive — with practical guidance on operationalizing continuous validation.
Cyber Threat Intelligence eBook
CTI has become a cornerstone of modern cybersecurity. As threats grow more frequent, organizations must proactively anticipate and operationalize intelligence.
Offensive Cybersecurity Maturity
For security leaders navigating a complex landscape — a comprehensive framework for building a forward-looking offensive security strategy that scales with your program.
Red Team Operations Roadmap
A comprehensive roadmap for organizations at any stage of Red Team maturity — from building the program to scaling operations and measuring real adversary readiness.
Transforming Cyber Defense through Adversarial Behavior Detection
The threat landscape continuously evolves across IT, OT/ICS, and regulatory environments. This report examines how adversarial behavior detection transforms cyber defense programs.
Cyber Fitness Guide 2024
Your organization's annual cybersecurity physical — a structured security posture assessment that surfaces strengths, vulnerabilities, and actionable improvement priorities.
Guides & Reference
Practical frameworks for every stage of your program.
From building a purple team program to structuring incident response — practical reference material for security leaders and practitioners.
.jpg)
CISOs Guide to Purple Teaming
The SCYTHE PTEF provides a structured path for organizations to build a purple team program from scratch — scoped, measured, and tied to executive reporting.
Annual Cyber Fitness eGuide
The original annual cyber fitness guide — designed to help security teams baseline cyber risk, identify coverage gaps, and establish a repeatable security posture review cycle.
Attack, Detect, and Respond
SCYTHE's framework for validating people, processes, and technologies across the full detection and response lifecycle — from the initial attack through containment and recovery.