Skip to content

Tools

Security tools 170 tools

Submit tool
Category
Health

170 tools

SIPCAPTURE Homer Healthy open source

Troubleshooting and monitoring VoIP calls.

infisical Healthy open source

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Prowler Healthy open source

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

pentest-ai Healthy open source

Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.

msaad00/agent-bom Healthy open source

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

authentik Healthy open source

The authentication glue you need.

Checkov Healthy open source

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

389 Directory Server At Risk open source

Enterprise-class Open Source LDAP server for Linux.

cap Healthy open source

The privacy-first, self-hosted CAPTCHA for the modern web.

octelium Healthy open source

A next-gen FOSS self-hosted unified zero trust secure access platform that can operate as a remote access VPN, a ZTNA platform, API/AI/MCP gateway, a PaaS, an ngrok-alternative and a homelab infrastructure.

MyIP Healthy open source

All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.

Zircolite Healthy open source

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Pompelmi Healthy open source

Open-source file upload security for Node.js. Scan files before storage to detect malware, MIME spoofing, and risky archives.

OpenZiti Healthy open source

Fully-featured, zero trust, full mesh overlay network. Includes a 2FA support out of the box, clients for all major desktop/mobile OS'es.

One Time Secret Healthy open source

Share sensitive information securely with self-destructing links that are only viewable once.

Mybucks.online Healthy open source

Secure, browser-based, password-only self-custodial cryptocurrency wallet.

warpgate Healthy open source

Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software

PasswordPusher Healthy open source

Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

trufflehog Healthy open source

Find, verify, and analyze leaked credentials

beelzebub Healthy open source

Honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks.

teleport Healthy open source

The easiest, and most secure way to access and protect all of your infrastructure.

gebalamariusz/cloud-audit Healthy open source

Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.

voidauth Healthy open source

Single Sign-On for Your Self-Hosted Universe

AI-Infra-Guard by Tencent Zhuque Lab Healthy open source

A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

UUSEC WAF Mixed open source

Industry-leading high-performance, AI and semantic technology web application firewall and API security gateway (fork of nginx).

ZeroTierOne At Risk open source

A Smart Ethernet Switch for Earth

FreeRADIUS Mixed open source

FreeRADIUS - A multi-protocol policy server.

logto Mixed open source

Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC and OAuth 2.1 with multi-tenancy, SSO, and RBAC.

sysreptor Healthy open source

A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.

VAST Healthy open source

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

kanidm Healthy open source

Kanidm: A simple, secure, and fast identity management platform

Secrover Mixed open source

Open-source security reports — no paywalls, just actionable insights.

Splunk Security Content Healthy open source

Splunk Security Content

Quark-Engine Mixed open source

An Obfuscation-Neglect Android Malware Scoring System.

Cardea Healthy open source

SSH bastion server with access control, session recording, and optional TPM-backed key protection. `EUPL-1.2` `Go/Docker`

pocket-id Healthy open source 1 tracking

A simple and easy-to-use OIDC provider that allows users to authenticate with their passkeys to your services.

aliasvault Healthy open source

Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.

Ghidra Healthy open source

Ghidra is a software reverse engineering (SRE) framework

Recog Mixed open source

Pattern recognition for hosts, services, and content

GlobaLeaks Healthy open source

Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

Transmission Mixed open source

Fast, easy, free Bittorrent client.

bunkerweb Mixed open source

Open-source and next-generation Web Application Firewall (WAF)

Tox At Risk open source

Distributed, secure messenger with audio and video chat capabilities.

VaulTLS Healthy open source

Selfhostable web app to make managing mTLS certificates a breeze

cyntrisec/cyntrisec-cli Healthy open source

Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.

Shuffle Mixed open source

Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.

Yopass Mixed open source

Secure sharing of secrets, passwords and files.

grype Mixed open source

A vulnerability scanner for container images and filesystems

Engity's Bifröst Mixed open source

Highly customizable SSH server with several ways to authorize a user and options where and how to execute a user's session.

Trivy At Risk open source

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Beta — feedback welcome: [email protected]