The cybersecurity field guide
Understand the cybersecurity tool landscape.
Every category, vendor, and tool explained in plain English and cross-referenced by domain — no sales pitch, nothing to buy.
224 tools141 vendors35 categories134 glossary terms
Seven ways in
Pick your starting point.
Start here
Four tool types everyone should know first.
The rest of the landscape builds on these. Each card opens a beginner lesson — what the tool does, the attack it stops, and how it works under the hood.
EDR/XDREndpoint & Extended Detection and ResponseRecords process, file, and network activity on laptops and servers so security teams can detect, investigate, and contain attacks that bypass preventive controls.SIEMSecurity Information & Event ManagementThe security team's central log warehouse: collects events from everything in the environment, correlates them into alerts, and gives analysts one place to search when something looks wrong.IAM/SSOIdentity & Access Management / Single Sign-OnThe system employees log into once to reach every other work app, and the system IT uses to control who gets access to what — the front door for almost everything else in a company's software stack.NGFWNext-Generation FirewallControls traffic entering and leaving a network. In addition to addresses and ports, it identifies applications, inspects content, and blocks known attack patterns.
The 10 domains
One palette, every security domain.
Cobalt, teal, ink, and slate stay consistent across the map, category index, and every tool card. Labels do the identifying; color keeps the landscape coherent.