Skip to content

Security

Free security — 103 tools · 103 tools

Creepy

Geolocation OSINT tool for gathering location information from social platforms

SecuritySelf-hosted

Google Dorking (GHDB)

Google Hacking Database (GHDB) of search queries used to uncover exposed information and vulnerabilities

Security

Holehe

Check if an email address is registered on websites and services without sending any emails

SecuritySelf-hosted

Maigret

Collect a dossier on a person by username from thousands of sites

SecuritySelf-hosted

Intel Techniques Tools

Curated suite of free online OSINT tools and searches used by investigators

Security

OSINT Framework

Web-based framework listing dozens of free OSINT tools by category

SecuritySelf-hosted

Osintgram

OSINT tool for Instagram that gathers user information such as followers, media and hashtags via CLI

SecuritySelf-hosted

Phone Infoga

Advanced phone number information gathering and tracking across public databases

SecuritySelf-hosted

Sherlock

Find usernames across social networks with a single search

SecuritySelf-hosted

Sherlock

Find usernames across 400+ social networks and platforms with a single query

SecuritySelf-hosted

Spider Foot

Automate OSINT collection across 200+ modules: scan a target and correlate IPs, domains, emails, and social footprints

SecuritySelf-hosted

Sublist3r

Enumerates subdomains of websites using OSINT sources and search engines

SecuritySelf-hosted

the Harvester

Gather emails, subdomains, hosts, and employee names from public sources for reconnaissance

SecuritySelf-hosted

Virus Total

Scan files, URLs, and domains against 70+ antivirus engines and threat intelligence feeds. Detect malware and phishing at scale

Security

Whats My Name

Unified usernames enumeration across 300+ websites

SecuritySelf-hosted

Who XY

Domain owner, registrar, and WHOIS history lookup tool

Security

Aircrack-ng

Complete suite of tools for assessing Wi-Fi network security: monitoring, attacking, testing, and cracking

SecuritySelf-hosted

Apktool

Tool for reverse engineering third-party Android apps by decoding resources back to nearly original form

SecuritySelf-hosted

Assetfinder

Passive subdomain discovery tool that finds related domains and subdomains without directly touching the target

SecuritySelf-hosted

Autopsy

Forensic analysis of hard drives and media. Recover deleted files, analyze artifacts, and generate reports

SecuritySelf-hosted

Autoruns

Sysinternals tool that shows every program configured to run at startup, logon or boot on Windows

SecuritySelf-hosted

Be EF

Browser Exploitation Framework that focuses on the web browser to assess security posture via client-side attacks

SecuritySelf-hosted

Binwalk

Firmware analysis tool that scans binary images to detect and extract embedded files and data

SecuritySelf-hosted

Blood Hound

Discover hidden and often unintended relationships in Active Directory using graph theory

SecuritySelf-hosted

bulk_extractor

Extracts valuable artifacts like emails, URLs and credit card numbers from disk images and directories

SecuritySelf-hosted

Chkrootkit

Locally checks for signs of rootkits on Unix-like systems

SecuritySelf-hosted

Cloud Fox

Automates situational awareness and reconnaissance for cloud penetration testing on AWS, Azure and GCP

SecuritySelf-hosted

Commix

Automated tool to detect and exploit command injection vulnerabilities in web applications

SecuritySelf-hosted

Crack Map Exec

Swiss army knife for pentesting Windows and Active Directory environments with credential spraying

SecuritySelf-hosted

Crack Station

Online hash cracking service with a large precomputed wordlist database for recovering plaintext passwords

Security

Cutter

Free and open-source reverse engineering platform powered by Radare2

SecuritySelf-hosted

Dirsearch

Advanced web path brute-forcer to discover hidden directories and files

SecuritySelf-hosted

Elastic Security

Free and open SIEM with detection rules, endpoint security, and threat hunting

SecuritySelf-hosted

Empire

PowerShell and Python post-exploitation framework with modules for lateral movement and persistence

SecuritySelf-hosted

Ettercap

Comprehensive suite for man-in-the-middle attacks, network sniffing and traffic interception

SecuritySelf-hosted

Evil-Win RM

Ultimate WinRM shell for hacking and pentesting Windows hosts using the native WinRM protocol

SecuritySelf-hosted

Eye Witness

Webscreenshot tool for reconnaissance that captures screenshots of multiple websites for analysis

SecuritySelf-hosted

Feroxbuster

Fast, simple, recursive content discovery tool written in Rust

SecuritySelf-hosted

FFUF

Fast web fuzzer that discovers directories, files, virtual hosts, and parameters on web servers

SecuritySelf-hosted

FLARE VM

Windows-based virtual machine distribution for malware analysis maintained by Mandiant

SecuritySelf-hosted

Foremost

Console program to recover deleted files by carving disk images based on file headers and footers

SecuritySelf-hosted

Frida

Dynamic instrumentation toolkit for developers and reverse engineers on Android, iOS, and desktop

SecuritySelf-hosted

gau

Get All URLs - fetches known URLs for a domain from public web archives like the Wayback Machine

SecuritySelf-hosted

Ghidra

NSA's software reverse engineering framework with disassembly and decompilation

SecuritySelf-hosted

Gitleaks

Scan git repos for secrets, passwords, and API keys that were accidentally committed

SecuritySelf-hosted

Go Phish

Phishing simulation toolkit for security awareness training. Track who clicks and reports

SecuritySelf-hosted

Go Witness

Web screenshot utility that uses Chrome headless to capture screenshots of websites at scale for recon

SecuritySelf-hosted

Graylog

Open-source log management for collecting, indexing, and analyzing machine data in real time

SecuritySelf-hosted

Hashcat

World's fastest password recovery tool. Recover lost passwords from hash files using CPU and GPU

SecuritySelf-hosted

hashes org

Public online hash database and cracking service for password hashes and hash lists

Security

httpx

Multipurpose HTTP toolkit for fast probing and scanning of HTTP services to reveal status codes, technologies and endpoints

SecuritySelf-hosted

jadx

Dex to Java decompiler that produces readable Java source code from Android APKs

SecuritySelf-hosted

John the Ripper

Fast password cracking tool for recovering weak passwords from hashes

SecuritySelf-hosted

Katana

Crawler designed for security testing that discovers endpoints and sensitive data on websites

SecuritySelf-hosted

Lynis

Audit Unix/Linux systems for security hardening gaps. Generates hardening recommendations

SecuritySelf-hosted

Masscan

Extremely fast port scanner that can scan the entire internet in minutes by sending packets in parallel

SecuritySelf-hosted

Metasploit Framework

Penetration testing framework with thousands of modules for exploitation, payloads, and post-exploitation

SecuritySelf-hosted

Mimikatz

Windows security tool that extracts plaintext passwords, hashes, PINs and Kerberos tickets from memory

SecuritySelf-hosted

MISP Threat Intelligence

Open source threat intelligence platform for storing, correlating, and sharing indicators of compromise

SecuritySelf-hosted

mitmproxy

Interactive HTTPS proxy for inspecting, modifying and replaying traffic between clients and servers

SecuritySelf-hosted

Mob SF

Mobile Security Framework - automated all-in-one mobile app penetration testing and malware analysis

SecuritySelf-hosted

Mod Security

Open source web application firewall with a rules engine for blocking attacks

SecuritySelf-hosted

Net Exec

Network exploitation and post-exploitation tool (successor to CrackMapExec) for pentesting Active Directory networks

SecuritySelf-hosted

Nikto

Scan web servers for outdated software, dangerous files, and misconfigurations

SecuritySelf-hosted

Nmap

Discover hosts and services on a network. Port scanning, OS detection, version detection, and scripting engine

SecuritySelf-hosted

Nuclei

Fast, template-based vulnerability scanner that sends requests to targets and matches results against templates

SecuritySelf-hosted

Open CTI

Open-source platform to store, organize, and analyze threat intelligence and cyber observables

SecuritySelf-hosted

Open VAS / Greenbone

Full vulnerability scanning and management suite. Scan networks for known CVEs and misconfigurations

SecuritySelf-hosted

Pacu

AWS exploitation framework for offensive security testing and red teaming of AWS accounts

SecuritySelf-hosted

Password Strength Meter

Score any password instantly with an in-browser strength meter that shows entropy, weak patterns, and concrete tips to make it stronger

SecurityRuns in your browserSelf-hosted

Payloads All The Things

Payloads All The Things - a large collection of payloads and bypasses for web application security testing

SecuritySelf-hosted

System Informer

System Informer (formerly Process Hacker) - a full-featured task manager and system monitor for Windows

SecuritySelf-hosted

Prowler

CIS benchmarks and security checks for AWS, Azure and GCP cloud environments

SecuritySelf-hosted

Radare2

Unix-like reverse engineering framework and command-line toolset for binary analysis

SecuritySelf-hosted

REMnux

REMnux Linux distribution for malware analysis and reverse engineering of malicious software

SecuritySelf-hosted

Responder

LLMNR, NBT-NS and MDNS poisoner used to grab credentials on local networks during penetration tests

SecuritySelf-hosted

Rootkit Hunter

Scan systems for rootkits, backdoors, and local exploits

SecuritySelf-hosted

Rust Scan

Fast port scanner written in Rust that finds open ports in seconds and pipes them into other tools

SecuritySelf-hosted

S3Scanner

Finds AWS S3 buckets and checks their permissions to identify publicly exposed buckets

SecuritySelf-hosted

Scout Suite

Open-source multi-cloud security auditing tool for AWS, Azure, GCP and other cloud providers

SecuritySelf-hosted

Search Sploit

Command-line search tool for the Exploit-DB archive to find exploits, shellcodes and papers

SecuritySelf-hosted

Sec Lists

Collection of security-related wordlists for fuzzing, brute force, and discovery

SecuritySelf-hosted

The Sleuth Kit

Command line toolkit for examining disk images and recovering evidence

SecuritySelf-hosted

Sliver

Implant-based command and control framework that generates and controls payloads for red team operations

SecuritySelf-hosted

SQLmap

Automatically detect and exploit SQL injection flaws. Supports many databases and injection techniques

SecuritySelf-hosted

Suricata

High performance network intrusion detection and prevention system with threat hunting

SecuritySelf-hosted

tcpdump

Command-line packet analyzer for capturing and inspecting network traffic on a live interface

SecuritySelf-hosted

The Hive

Scalable, open-source security incident response platform that integrates with MISP

SecuritySelf-hosted

Trivy

Comprehensive, fast scanner for vulnerabilities in container images, filesystems, and git repos

SecuritySelf-hosted

Velociraptor

Digital forensics and incident response platform for collecting data from endpoints at scale

SecuritySelf-hosted

Volatility

Analyze RAM dumps to find malicious processes, injected code, and hidden artifacts

SecuritySelf-hosted

Volatility 3

Memory forensics framework for extracting artifacts such as processes, connections and hashes from RAM dumps

SecuritySelf-hosted

W3AF

Web application attack and audit framework with 200+ plugins

SecuritySelf-hosted

WAFW00F

Web application firewall fingerprinting tool that detects which WAF protects a given website

SecuritySelf-hosted

Waybackurls

Fetch all known URLs for a domain from the Wayback Machine for recon and asset discovery

SecuritySelf-hosted

TShark

Command line version of Wireshark for scripting and automation of packet capture analysis

SecuritySelf-hosted

Wireshark

Capture and inspect network traffic in real time. The industry-standard protocol analyzer for troubleshooting and security

SecuritySelf-hosted

WPScan

Black-box WordPress vulnerability scanner that checks for known CVEs and weaknesses

SecuritySelf-hosted

x64dbg

Open-source Windows x64/x32 debugger for reverse engineering and malware analysis

SecuritySelf-hosted

XSStrike

Advanced cross-site scripting detection suite with fuzzing and analysis to find XSS vulnerabilities

SecuritySelf-hosted

YARA

Identify and classify malware by creating rules that match on binary patterns

SecuritySelf-hosted

OWASP ZAP

Automated security scanner for finding vulnerabilities in web applications. Proxy, fuzzer, and scanner in one

SecuritySelf-hosted

Zeek

Powerful network analysis framework focused on security monitoring and research

SecuritySelf-hosted