Top #sec Tools & Software
Explore 392 hand-picked tools and software tagged with sec โ ranked by popularity and community signals.
anubis
githubWeighs the soul of incoming HTTP requests to stop AI crawlers
cutter
githubFree and Open Source Reverse Engineering Platform powered by rizin
DOMPurify
githubDOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
lynis
githubLynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
wazuh
githubWazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
zaproxy
githubThe ZAP by Checkmarx Core project
cryptomator
githubCryptomator for Windows, macOS, and Linux: Secure client-side encryption for your cloud storage, ensuring privacy and control over your data.
wifiphisher
githubThe Rogue Access Point Framework
hacker101
githubSource code for Hacker101.com - a free online web and mobile security class.
awesome-security
githubA collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
dirsearch
githubWeb path scanner
gophish
githubOpen-Source Phishing Toolkit
fscan
githubไธๆฌพๅ ็ฝ็ปผๅๆซๆๅทฅๅ ท๏ผๆนไพฟไธ้ฎ่ชๅจๅใๅ จๆนไฝๆผๆซๆซๆใ(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)
opensnitch
githubOpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.
tink
githubTink is a multi-language, cross-platform, open source library that provides cryptographic APIs that are secure, easy to use correctly, and hard(er) to misuse.
secguide
github้ขๅๅผๅไบบๅๆขณ็็ไปฃ็ ๅฎๅ จๆๅ
awesome-web-security
github๐ถ A curated list of Web Security materials and resources.
crowdsec
githubCrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.
routersploit
githubExploitation Framework for Embedded Devices
juice-shop
githubOWASP Juice Shop: Probably the most modern and sophisticated insecure web application
DVWA
githubDamn Vulnerable Web Application (DVWA)
keeweb
githubFree cross-platform password manager compatible with KeePass
user.js
githubFirefox privacy, security and anti-tracking: a comprehensive user.js template for configuration and hardening
mvt
githubMVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.