Tools
Security tools 101 tools
101 tools
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Troubleshooting and monitoring VoIP calls.
Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Password manager dedicated for managing passwords in a collaborative way. One symmetric key is used to encrypt all shared/team passwords and stored server side in a file and the database. works on any server Apache, MySQL and PHP.
Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.
Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.
Single Sign-On for Your Self-Hosted Universe
The authentication glue you need.
The privacy-first, self-hosted CAPTCHA for the modern web.
Rapid spam filtering system.
Secure sharing of secrets, passwords and files.
Find, verify, and analyze leaked credentials
Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.
Share sensitive information securely with self-destructing links that are only viewable once.
Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser
ZITADEL - Identity infrastructure, simplified for you.
All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.
OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.
Single Sign-On Identity & Access Management via OpenID Connect, OAuth 2.0 and PAM
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.
Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.
A simple and easy-to-use OIDC provider that allows users to authenticate with their passkeys to your services.
Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software
Secure, browser-based, password-only self-custodial cryptocurrency wallet.
finds publicly known security vulnerabilities in a website's frontend JavaScript libraries
A tool for reverse engineering Android apk files
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
Open-source and next-generation Web Application Firewall (WAF)
♂ Collect a dossier on a person by username from 3000+ sites
AVML - Acquire Volatile Memory for Linux
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
The easiest, and most secure way to access and protect all of your infrastructure.
ClamAV - Documentation is here: https://docs.clamav.net
Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.
Pomerium is an identity and context-aware access proxy.
Pattern recognition for hosts, services, and content
A vulnerability scanner for container images and filesystems
Splunk Security Content
cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
IntelOwl: manage your Threat Intelligence at scale
A comprehensive manual for mobile app security testing and reverse engineering.
UNIX-like reverse engineering framework and command-line toolset.
Malicious traffic detection system
Open Source Identity and Access Management For Modern Applications and Services
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more