Skip to content

Tools

Security tools 55 tools

Submit tool
Category
Health

55 tools

SIPCAPTURE Homer Healthy open source

Troubleshooting and monitoring VoIP calls.

infisical Healthy open source

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Prowler Healthy open source

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

pentest-ai Healthy open source

Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.

msaad00/agent-bom Healthy open source

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

authentik Healthy open source

The authentication glue you need.

Checkov Healthy open source

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

cap Healthy open source

The privacy-first, self-hosted CAPTCHA for the modern web.

octelium Healthy open source

A next-gen FOSS self-hosted unified zero trust secure access platform that can operate as a remote access VPN, a ZTNA platform, API/AI/MCP gateway, a PaaS, an ngrok-alternative and a homelab infrastructure.

Zircolite Healthy open source

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

OpenZiti Healthy open source

Fully-featured, zero trust, full mesh overlay network. Includes a 2FA support out of the box, clients for all major desktop/mobile OS'es.

Pompelmi Healthy open source

Open-source file upload security for Node.js. Scan files before storage to detect malware, MIME spoofing, and risky archives.

MyIP Healthy open source

All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.

One Time Secret Healthy open source

Share sensitive information securely with self-destructing links that are only viewable once.

Mybucks.online Healthy open source

Secure, browser-based, password-only self-custodial cryptocurrency wallet.

beelzebub Healthy open source

Honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks.

teleport Healthy open source

The easiest, and most secure way to access and protect all of your infrastructure.

trufflehog Healthy open source

Find, verify, and analyze leaked credentials

PasswordPusher Healthy open source

Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

warpgate Healthy open source

Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software

AI-Infra-Guard by Tencent Zhuque Lab Healthy open source

A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

voidauth Healthy open source

Single Sign-On for Your Self-Hosted Universe

gebalamariusz/cloud-audit Healthy open source

Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.

kanidm Healthy open source

Kanidm: A simple, secure, and fast identity management platform

VAST Healthy open source

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

sysreptor Healthy open source

A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.

Ghidra Healthy open source

Ghidra is a software reverse engineering (SRE) framework

GlobaLeaks Healthy open source

Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

aliasvault Healthy open source

Privacy-first password manager with built-in email aliasing. Fully encrypted and self-hostable.

pocket-id Healthy open source 1 tracking

A simple and easy-to-use OIDC provider that allows users to authenticate with their passkeys to your services.

Cardea Healthy open source

SSH bastion server with access control, session recording, and optional TPM-backed key protection. `EUPL-1.2` `Go/Docker`

Splunk Security Content Healthy open source

Splunk Security Content

cyntrisec/cyntrisec-cli Healthy open source

Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.

Radare2 Healthy open source

UNIX-like reverse engineering framework and command-line toolset

VaulTLS Healthy open source

Selfhostable web app to make managing mTLS certificates a breeze

Stratus Red Team | DataDog Healthy open source

cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

is-website-vulnerable Healthy open source

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries

Kamailio Healthy open source

Modular SIP server (registrar/proxy/router/etc).

Zeek Healthy open source

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Arkime Healthy open source

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

passbolt_api Healthy open source

Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!

mitmproxy Healthy open source

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

openbao Healthy open source

OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

shellfirm Healthy open source

Safety guardrails for ai coding agents and human terminal commands

keycloak Healthy open source

Open Source Identity and Access Management For Modern Applications and Services

PrivateCaptcha Healthy open source

Independent, privacy-first, self-hostable PoW CAPTCHA service made in EU

authgear-server Healthy open source

Open source Auth0/Clerk/Firebase alternative. Passkeys, SSO, MFA, passwordless, biometric login. Self-hosted or cloud. Enterprise-ready for SaaS & mobile apps

Sigma Healthy open source

Main Sigma Rule Repository

LDAP Account Manager (LAM) Healthy open source

Web frontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory.

wazuh Healthy open source

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Beta — feedback welcome: [email protected]