Tools
Security tools 58 tools
58 tools
FreeRADIUS - A multi-protocol policy server.
Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC and OAuth 2.1 with multi-tenancy, SSO, and RBAC.
Industry-leading high-performance, AI and semantic technology web application firewall and API security gateway (fork of nginx).
Open-source security reports — no paywalls, just actionable insights.
Pattern recognition for hosts, services, and content
An Obfuscation-Neglect Android Malware Scoring System.
Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.
Open-source and next-generation Web Application Firewall (WAF)
Secure sharing of secrets, passwords and files.
A vulnerability scanner for container images and filesystems
Malicious traffic detection system
Fast, easy, free Bittorrent client.
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
Highly customizable SSH server with several ways to authorize a user and options where and how to execute a user's session.
An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.
Complete, reliable, secure and zero-trust webapp based on zero-knowledge encryption to store your TOTP codes.
Simple, robust, BitTorrent tracker (client and server) implementation.
The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™
♂ Collect a dossier on a person by username from 3000+ sites
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
AVML - Acquire Volatile Memory for Linux
Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.
Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.
Pomerium is an identity and context-aware access proxy.
Generates lightweight, embedded honeypot triggers called canary tokens for detecting unauthorized access.
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
Single Sign-On Identity & Access Management via OpenID Connect, OAuth 2.0 and PAM
Lightweight SIP proxy, location server, and registrar for a reliable and scalable SIP infrastructure.
A helm plugin that help manage secrets with Git workflow and store them anywhere
A Web app to manage your Two-Factor Authentication (2FA) accounts and generate their security codes
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
Browser forensics tool for Google Chrome (and other Chromium-based browsers)
IntelOwl: manage your Threat Intelligence at scale
Anonymously share files, browse and publish _freesites_ (web sites accessible only through Hyphanet) and chat on forums.
A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
UNIX-like reverse engineering framework and command-line toolset.
Web-based Traffic and Security Network Traffic Monitoring
High-speed log analysis and forensics tool with multi-format parsing, pattern matching, timeline reconstruction and anomaly detection for incident response.
A framework for secure and scalable network traffic analysis - https://netcap.io
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
portchecker.io is a free online utility to check the port status of a given hostname or IP address.
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
A turnkey OAuth & authentication system, designed for both Cloudflare Workers and Node.js
ClamAV - Documentation is here: https://docs.clamav.net
One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser
Keep your sensitive information out of chat logs, emails, and more with encrypted secrets.