The most comprehensive directory of cybersecurity tools for security assessment, penetration testing, and risk discovery.
Explore our curated collection of 137+ essential cybersecurity tools, ranging from network security and penetration testing to malware analysis and vulnerability assessment.
Whether you're a security professional, penetration tester, or IT administrator, find the right tools to enhance your security operations, conduct thorough assessments, and protect your digital assets.
A modern API security scanner supporting GraphQL and REST API testing, authentication testing, rate limiting analysis, and API fuzzing capabilities.
World's fastest and most advanced password recovery tool
An OSINT tool to search for accounts by username in 581 sites. Features include asynchronous execution, highly customizable, and CSV/TXT export.
A comprehensive vulnerability scanner for containers, filesystems, and git repositories, offering fast and accurate scanning with DevOps-friendly integration.
A DevSecOps platform for security orchestration, vulnerability management, metrics reporting, and CI/CD integration.
Full-featured web reconnaissance framework written in Python
Open source cloud native security observability platform
Advanced AI text detection tool offering writing style analysis, perplexity scoring, and bulk content scanning capabilities for identifying AI-generated content.
Sophisticated audio forensics tool for voice pattern analysis, audio manipulation detection, spectral analysis, and audio source identification.
Tool for testing and promoting user awareness by simulating real-world phishing attacks.
Platform for monitoring threat actor channels and data breaches.
Collection of cybersecurity tools for red team operations.
Wireless and ethernet security auditing and attack software.
Advanced deepfake video detection platform that helps identify AI-generated video content.
Integrated platform for web application security testing
A generic SIEM rules platform with multi-platform support and community-driven rules for easy conversion between formats.
Cloud-based IT, security and compliance solutions
Open source threat intelligence aggregation platform
Wireless network and device detector, sniffer, wardriving tool, and WIDS framework
Enterprise vulnerability management and assessment platform
Feature-full, modular, high-performance Ruby framework aimed towards web application security scanning
Comprehensive content verification platform offering cross-modal analysis, AI detection algorithms, blockchain verification, and detailed audit trails.
Professional audio authentication software featuring waveform analysis, digital signature verification, tampering detection, and comprehensive metadata analysis.
A comprehensive mobile security testing framework offering static and dynamic analysis, API security testing, and malware analysis.
Fast and flexible network logon cracker which supports numerous protocols
AI image detection and analysis platform for identifying synthetic content.
Security auditing tool for Linux/Unix-based systems that performs detailed security scans and compliance checks
Penetration testing framework that makes hacking simple
Multi-modal content analysis platform utilizing machine learning for detecting AI-generated or manipulated media, featuring forensic analysis tools and automated reporting.
An Infrastructure as Code security scanner that scans Terraform, CloudFormation, and Kubernetes manifests with 1000+ built-in policies and custom policy framework support.
Active Directory security tool that uses graph theory to reveal hidden relationships and attack paths
AI image detection tool specifically designed for identifying AI-generated images.
Automated adversary emulation system that performs post-compromise adversarial behavior
Open source phishing framework for penetration testers and security researchers.
Intelligence Framework for analyzing threats in multiple ways from a single API.
Multi-modal AI detection platform for identifying synthetic images and audio.
Enterprise platform for detecting deepfakes and synthetic media across video content.
Swiss army knife for TCP/IP connections and listening
Tool for detecting and analyzing potential deepfake videos using advanced AI algorithms.
A cloud-native runtime security tool providing real-time container security monitoring, Kubernetes threat detection, and custom rule engine for behavior detection.
Open source Host-based Intrusion Detection System (HIDS) that performs log analysis, integrity checking, rootkit detection, and more
An advanced mobile security scanner for Android vulnerability scanning, runtime analysis, and SDK security testing.
AI speech detection tool to identify synthetic and AI-generated audio content.
Tool for identifying and analyzing potentially AI-generated or manipulated images.
Advanced command-line tool designed to brute force directories and files in webservers
An automated API security testing platform offering continuous API scanning, zero-day vulnerability detection, and API documentation analysis.
Comprehensive AI-generated content detection platform for video, audio, and images.
A Software Composition Analysis platform for software bill of materials (SBOM), component vulnerability analysis, and license compliance.
Collection of PowerShell modules used during penetration tests and red team engagements
Open source web server scanner that performs comprehensive tests against web servers for multiple items
Developer security platform for open source and container security
Vulnerability scanner for comprehensive security assessments
A PowerShell-based Windows security tool for event log analysis, threat hunting automation, and IOC detection.
Network tool able to send custom TCP/IP packets and display target replies
Open Cyber Threat Intelligence Platform that allows organizations to manage their cyber threat intelligence knowledge and observables.
Tool for finding Geolocation of devices using social engineering.
Collaborative platform for InfoSec teams to handle reporting and vulnerability management
An offensive Google framework focused on OSINT gathering and vulnerability research around Google services and products. Latest v2.0.1 release includes major improvements.
Advanced deepfake detection platform featuring video analysis, face manipulation detection, movement analysis, and confidence scoring capabilities.
Powerful network analysis framework that transforms network traffic into high-level events and entities
Post-exploitation framework that enables you to run PowerShell agents without powershell.exe
Network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.
Web Application Firewall (WAF) fingerprinting tool to identify and detect web application firewall products
An IoT security assessment tool for default credential testing, device discovery, and vulnerability scanning.
Specialized tool for detecting AI-generated and synthetic voice content.
Open-source phishing toolkit designed for businesses and penetration testers.
Advanced AI-generated content detection platform with trial access.
Network protocol analyzer for network troubleshooting and analysis
Pattern matching swiss knife for malware researchers and threat hunters
Open source network threat detection engine capable of real-time intrusion detection, inline intrusion prevention and network security monitoring
Comprehensive digital content verification platform providing content provenance tracking, digital signatures, metadata verification, and chain of custody tracking.
WordPress vulnerability scanner used to identify security issues in WordPress installations
Open-source penetration testing framework designed for social engineering.
Container and cloud security platform with runtime protection
Modern phishing tool with advanced functionality.
A comprehensive digital image forensics tool offering error level analysis, noise analysis, clone detection, and metadata analysis capabilities for detecting manipulated images and verifying image authenticity.
Man-in-the-middle attack framework used for phishing credentials and session cookies.
Open source intelligence (OSINT) automation tool that integrates with multiple data sources
Advanced image metadata analysis tool providing metadata extraction, digital signature verification, image source identification, and manipulation detection features.
Fast subdomains enumeration tool for penetration testers
Framework for performing layer 2 attacks, focused on network protocol analysis
Open source antivirus engine for detecting trojans, viruses, malware & other malicious threats
Open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws
Security tool designed to find common security issues in Python code
Security tool that mounts automated victim-customized phishing attacks against WiFi clients.
Browser Exploitation Framework for penetration testing
Platform for searching, monitoring, and analyzing machine-generated big data via a web-style interface
Professional email finder and verifier tool. Find anyone's email address and verify them in bulk. Features include email finder, domain search, and email verification.
Open source intrusion prevention system capable of real-time traffic analysis and packet logging
Discover where your personal data is stored and how to reclaim it
Calculate potential costs associated with data breaches
Assess and improve your organization's data privacy practices
Define and scope your security assessment requirements