Tools
Security tools 173 tools
173 tools
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Troubleshooting and monitoring VoIP calls.
Password manager dedicated for managing passwords in a collaborative way. One symmetric key is used to encrypt all shared/team passwords and stored server side in a file and the database. works on any server Apache, MySQL and PHP.
Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.
Single Sign-On for Your Self-Hosted Universe
Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.
The authentication glue you need.
Web AI firewall utility which protects upstream resources from scraper bots.
The privacy-first, self-hosted CAPTCHA for the modern web.
Find, verify, and analyze leaked credentials
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.
Share sensitive information securely with self-destructing links that are only viewable once.
Secure sharing of secrets, passwords and files.
Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.
Rapid spam filtering system.
ZITADEL - Identity infrastructure, simplified for you.
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.
All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.
One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser
An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Single Sign-On Identity & Access Management via OpenID Connect, OAuth 2.0 and PAM
Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.
A simple and easy-to-use OIDC provider that allows users to authenticate with their passkeys to your services.
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
Generates lightweight, embedded honeypot triggers called canary tokens for detecting unauthorized access.
Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software
Open-source and next-generation Web Application Firewall (WAF)
Secure, browser-based, password-only self-custodial cryptocurrency wallet.
♂ Collect a dossier on a person by username from 3000+ sites
finds publicly known security vulnerabilities in a website's frontend JavaScript libraries
A tool for reverse engineering Android apk files
macOS (& ios) Artifact Parsing Tool
Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs
Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
ClamAV - Documentation is here: https://docs.clamav.net
Pomerium is an identity and context-aware access proxy.
Pattern recognition for hosts, services, and content
A Web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes
Splunk Security Content
AVML - Acquire Volatile Memory for Linux
A vulnerability scanner for container images and filesystems
The easiest, and most secure way to access and protect all of your infrastructure.
tirreno is an open-source security framework. Event tracking, threat detection, and risk scoring for any application.