CySA+ reference

Cybersecurity Analyst Tools Matrix

Every tool placed on the kill chain and the IR lifecycle

A MITRE ATT&CK-style reference matrix of essential cybersecurity tools for security analysts. Each tool is tagged with its category, Cyber Kill Chain stage, license and OS.

77 tools 9 categories 11 kill-chain & IR stages

Why this matrix exists

Studying for the CompTIA CySA+ (CS0-003) means juggling dozens of tools across very different domains — network scanners, SIEMs, EDRs, forensics suites, vulnerability platforms. Most study guides list them in flat tables that don't show when each one is used in a real engagement.

This page is the reference I wish I had on day one. It maps every tool to two complementary frameworks: the Cyber Kill Chain (how an attacker progresses) and the NIST SP 800-61r2 Incident Response Lifecycle (how a defender responds). Pivoting by stage answers practical questions like "what do I reach for during containment?" or "which scanners belong in the preparation phase?"

It is a living reference rather than a snapshot: as I work through the exam domains and the lab builds, tools get added, descriptions get sharper, and the kill-chain mapping gets corrected wherever practice disagrees with the textbook. The aim is a page that stays useful long after the exam.

Showing 77/77
Reset