The most comprehensive directory of cybersecurity tools for security assessment, penetration testing, and risk discovery.
Explore our curated collection of 137+ essential cybersecurity tools, ranging from network security and penetration testing to malware analysis and vulnerability assessment.
Whether you're a security professional, penetration tester, or IT administrator, find the right tools to enhance your security operations, conduct thorough assessments, and protect your digital assets.
Open source cloud native security observability platform
Open source web server scanner that performs comprehensive tests against web servers for multiple items
Framework for performing layer 2 attacks, focused on network protocol analysis
Powerful network analysis framework that transforms network traffic into high-level events and entities
Platform for searching, monitoring, and analyzing machine-generated big data via a web-style interface
Open-source penetration testing framework designed for social engineering.
A comprehensive vulnerability scanner for containers, filesystems, and git repositories, offering fast and accurate scanning with DevOps-friendly integration.
Developer security platform for open source and container security
Multi-modal content analysis platform utilizing machine learning for detecting AI-generated or manipulated media, featuring forensic analysis tools and automated reporting.
Collection of cybersecurity tools for red team operations.
Modern phishing tool with advanced functionality.
Platform for monitoring threat actor channels and data breaches.
A modern API security scanner supporting GraphQL and REST API testing, authentication testing, rate limiting analysis, and API fuzzing capabilities.
Open source antivirus engine for detecting trojans, viruses, malware & other malicious threats
Open source phishing framework for penetration testers and security researchers.
Fast and flexible network logon cracker which supports numerous protocols
An offensive Google framework focused on OSINT gathering and vulnerability research around Google services and products. Latest v2.0.1 release includes major improvements.
Advanced image metadata analysis tool providing metadata extraction, digital signature verification, image source identification, and manipulation detection features.
Collaborative platform for InfoSec teams to handle reporting and vulnerability management
Fast subdomains enumeration tool for penetration testers
A comprehensive mobile security testing framework offering static and dynamic analysis, API security testing, and malware analysis.
Feature-full, modular, high-performance Ruby framework aimed towards web application security scanning
Tool for identifying and analyzing potentially AI-generated or manipulated images.
Penetration testing framework that makes hacking simple
Tool for detecting and analyzing potential deepfake videos using advanced AI algorithms.
Professional email finder and verifier tool. Find anyone's email address and verify them in bulk. Features include email finder, domain search, and email verification.
Open source intelligence (OSINT) automation tool that integrates with multiple data sources
Advanced service identification and port scanning tool
World's fastest and most advanced password recovery tool
Wireless and ethernet security auditing and attack software.
Active Directory security tool that uses graph theory to reveal hidden relationships and attack paths
Wireless network and device detector, sniffer, wardriving tool, and WIDS framework
An automated API security testing platform offering continuous API scanning, zero-day vulnerability detection, and API documentation analysis.
Swiss army knife for TCP/IP connections and listening
Open source threat intelligence aggregation platform
Pattern matching swiss knife for malware researchers and threat hunters
Sophisticated audio forensics tool for voice pattern analysis, audio manipulation detection, spectral analysis, and audio source identification.
Advanced AI-generated content detection platform with trial access.
Advanced command-line tool designed to brute force directories and files in webservers
Multi-modal AI detection platform for identifying synthetic images and audio.
Tool for finding Geolocation of devices using social engineering.
Vulnerability scanner for comprehensive security assessments
An OSINT tool to search for accounts by username in 581 sites. Features include asynchronous execution, highly customizable, and CSV/TXT export.
Collection of PowerShell modules used during penetration tests and red team engagements
A comprehensive digital image forensics tool offering error level analysis, noise analysis, clone detection, and metadata analysis capabilities for detecting manipulated images and verifying image authenticity.
AI image detection tool specifically designed for identifying AI-generated images.
Tool for testing and promoting user awareness by simulating real-world phishing attacks.
An IoT security assessment tool for default credential testing, device discovery, and vulnerability scanning.
Container and cloud security platform with runtime protection
Full-featured web reconnaissance framework written in Python
Advanced deepfake video detection platform that helps identify AI-generated video content.
Intelligence Framework for analyzing threats in multiple ways from a single API.
Security tool designed to find common security issues in Python code
Enterprise vulnerability management and assessment platform
An advanced mobile security scanner for Android vulnerability scanning, runtime analysis, and SDK security testing.
Network protocol analyzer for network troubleshooting and analysis
Open source Host-based Intrusion Detection System (HIDS) that performs log analysis, integrity checking, rootkit detection, and more
Man-in-the-middle attack framework used for phishing credentials and session cookies.
AI speech detection tool to identify synthetic and AI-generated audio content.
Open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws
An Infrastructure as Code security scanner that scans Terraform, CloudFormation, and Kubernetes manifests with 1000+ built-in policies and custom policy framework support.
A PowerShell-based Windows security tool for event log analysis, threat hunting automation, and IOC detection.
Comprehensive AI-generated content detection platform for video, audio, and images.
Open source network threat detection engine capable of real-time intrusion detection, inline intrusion prevention and network security monitoring
Open source intrusion prevention system capable of real-time traffic analysis and packet logging
Web Application Firewall (WAF) fingerprinting tool to identify and detect web application firewall products
Cloud-based IT, security and compliance solutions
Open Cyber Threat Intelligence Platform that allows organizations to manage their cyber threat intelligence knowledge and observables.
Advanced deepfake detection platform featuring video analysis, face manipulation detection, movement analysis, and confidence scoring capabilities.
Advanced AI text detection tool offering writing style analysis, perplexity scoring, and bulk content scanning capabilities for identifying AI-generated content.
WordPress vulnerability scanner used to identify security issues in WordPress installations
Integrated platform for web application security testing
Network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.
A Software Composition Analysis platform for software bill of materials (SBOM), component vulnerability analysis, and license compliance.
Open-source phishing toolkit designed for businesses and penetration testers.
Network tool able to send custom TCP/IP packets and display target replies
Post-exploitation framework that enables you to run PowerShell agents without powershell.exe
Professional audio authentication software featuring waveform analysis, digital signature verification, tampering detection, and comprehensive metadata analysis.
Automated adversary emulation system that performs post-compromise adversarial behavior
Security auditing tool for Linux/Unix-based systems that performs detailed security scans and compliance checks
A cloud-native runtime security tool providing real-time container security monitoring, Kubernetes threat detection, and custom rule engine for behavior detection.
A DevSecOps platform for security orchestration, vulnerability management, metrics reporting, and CI/CD integration.
A generic SIEM rules platform with multi-platform support and community-driven rules for easy conversion between formats.
Enterprise platform for detecting deepfakes and synthetic media across video content.
Comprehensive content verification platform offering cross-modal analysis, AI detection algorithms, blockchain verification, and detailed audit trails.
Specialized tool for detecting AI-generated and synthetic voice content.
Browser Exploitation Framework for penetration testing
Comprehensive digital content verification platform providing content provenance tracking, digital signatures, metadata verification, and chain of custody tracking.
AI image detection and analysis platform for identifying synthetic content.
Discover where your personal data is stored and how to reclaim it
Calculate potential costs associated with data breaches
Assess and improve your organization's data privacy practices
Define and scope your security assessment requirements