Skip to content

Tools

Developer tools directory 115 tools

Submit tool
Category
Health
#security

115 tools

msaad00/agent-bom Healthy open source

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

infisical Healthy open source

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Cosmos-Server Healthy open source

☁ The Most Secure and Easy Selfhosted Home Server. Take control of your data and privacy without sacrificing security and stability (Authentication, anti-DDOS, anti-bot)

OxiCloud Healthy open source

☁ Ultra-fast, secure & lightweight self-hosted cloud storage — your files, photos, calendars & contacts, all in one place. Built in Rust.

Prowler Healthy open source

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

VAST Healthy open source

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

PasswordPusher Healthy open source

Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

voidauth Healthy open source

Single Sign-On for Your Self-Hosted Universe

Fleet device management Healthy open source

Open device management

microsandbox Healthy open source

secure, local, cross-platform and programmable sandboxes for AI agents

Anubis Mixed open source

Web AI firewall utility which protects upstream resources from scraper bots.

authentik Healthy open source

The authentication glue you need.

flytohub/flyto-core Healthy open source

Deterministic execution engine for AI agents with 412 modules across 78 categories (browser, file, Docker, data, crypto, scheduling). Features execution trace, evidence snapshots, replay from any step, and supports both STDIO and Streamable HTTP transport.

UPinar/contrastapi Healthy open source

Security intelligence API with 31 MCP tools for CVE/EPSS/KEV lookup, domain recon (DNS/WHOIS/SSL/subdomains/CT logs), IOC/threat intel, OSINT (email/phone/username), and code security scanning (secrets, injection). Free 100 req/hr.

trufflehog Healthy open source

Find, verify, and analyze leaked credentials

GlobaLeaks Healthy open source

Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

goklab/guardvibe Healthy open source

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

Shuffle Healthy open source

Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.

MyIP Healthy open source

All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.

openbao Healthy open source

OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

NGINX Healthy open source

HTTP and reverse proxy server, mail proxy server, and generic TCP/UDP proxy server.

freema/openclaw-mcp Healthy open source

MCP server for OpenClaw AI assistant integration. Enables Claude to delegate tasks to OpenClaw agents with sync/async tools, OAuth 2.1 auth, and SSE transport for Claude.ai.

Sops Healthy open source

An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.

is-website-vulnerable Healthy open source

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries

Maigret Healthy open source

♂ Collect a dossier on a person by username from 3000+ sites

cerbos Healthy open source

Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.

bunkerweb Healthy open source

Open-source and next-generation Web Application Firewall (WAF)

bytebase Healthy open source

World's most advanced database DevSecOps solution for Developer, Security, DBA and Platform Engineering teams. The GitHub/GitLab for database DevSecOps.

Zeek Healthy open source

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

grype Healthy open source

A vulnerability scanner for container images and filesystems

Chainsaw Healthy open source

Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.

Splunk Security Content Healthy open source

Splunk Security Content

teleport Healthy open source

The easiest, and most secure way to access and protect all of your infrastructure.

openvpn Healthy open source

OpenVPN is an open source VPN daemon

defguard Healthy open source

Zero-Trust access management with true WireGuard® 2FA/MFA

matomo Healthy open source

Empowering People Ethically — Matomo is hiring! Join us → https://matomo.org/jobs Matomo is the leading open-source alternative to Google Analytics, giving you complete control and built-in privacy. Easily collect, visualise, and analyse data from websites & apps. Star us on GitHub ⭐ – Pull Requests welcome!

Hayabusa Healthy open source

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

NetAlertX Healthy open source

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

SafeLine Mixed open source

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

Stratus Red Team | DataDog Healthy open source

cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Timesketch Healthy open source

Collaborative forensic timeline analysis

pentest-ai Healthy open source

Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.

gebalamariusz/cloud-audit Healthy open source

Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.

wazuh Healthy open source

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Arkime Healthy open source

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

PrivateBin Healthy open source

A minimalist, open source online pastebin where the server has zero knowledge of pasted data. Data is encrypted/decrypted in the browser using 256 bits AES.

Maltrail Healthy open source

Malicious traffic detection system

I4cTime/quantum_ring Healthy open source

Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.

Rizin Healthy open source

UNIX-like reverse engineering framework and command-line toolset.

Trivy Healthy open source

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Beta — feedback welcome: [email protected]