Tools
Security tools 83 tools
83 tools
AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.
Single Sign-On for Your Self-Hosted Universe
Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.
The authentication glue you need.
Web AI firewall utility which protects upstream resources from scraper bots.
Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
Find, verify, and analyze leaked credentials
All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.
OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.
An editor of encrypted files that supports YAML, JSON and BINARY formats and encrypts with AWS KMS and PGP.
finds publicly known security vulnerabilities in a website's frontend JavaScript libraries
Open-source and next-generation Web Application Firewall (WAF)
♂ Collect a dossier on a person by username from 3000+ sites
Cerbos is the open core, language-agnostic, scalable authorization solution that makes user permissions and authorization simple to implement and manage by writing context-aware access control policies for your application resources.
The easiest, and most secure way to access and protect all of your infrastructure.
Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.
Splunk Security Content
A vulnerability scanner for container images and filesystems
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
Main Sigma Rule Repository
Malicious traffic detection system
Collaborative forensic timeline analysis
Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.
Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.
Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.
Arkime is an open source, large scale, full packet capturing, indexing, and database system.
IntelOwl: manage your Threat Intelligence at scale
UNIX-like reverse engineering framework and command-line toolset.
Independent, privacy-first, self-hostable PoW CAPTCHA service made in EU
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock
KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.
Credential isolation proxy for AI agents. Injects secrets at the network boundary with domain restrictions, agent authentication, and audit logging. No SDK required — works as a transparent HTTP proxy or MCP server.
Honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks.
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
7 SQL tools (validate, format, parse, lint, security scan, metadata extraction, full analysis) over Streamable HTTP. Public remote server at mcp.gosqlx.dev - no install needed. 1.25M+ ops/sec, 6 SQL dialects.
High-speed log analysis and forensics tool with multi-format parsing, pattern matching, timeline reconstruction and anomaly detection for incident response.
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
Kanidm: A simple, secure, and fast identity management platform
A framework for secure and scalable network traffic analysis - https://netcap.io