A curated collection of fantastic software, libraries, documents, books, and resources dedicated to security. From network and endpoint protection to threat intelligence and web security β a comprehensive list to enhance your security knowledge and practices.
- Metasploit Framework β tool for developing and executing exploit code against a remote target machine.
- Nmap β free and open source utility for network discovery and security auditing.
- Nuclei β fast, customizable vulnerability scanner based on simple YAML-based templates.
- OpenVAS β framework of services and tools offering comprehensive vulnerability scanning and management.
- pig β Linux packet crafting tool.
- Pompem β open source tool to automate the search for exploits in major databases.
- scapy β Python-based interactive packet manipulation program and library.
- Fibratus β tool for exploration and tracing of the Windows kernel activity.
- httpry β specialized packet sniffer for displaying and logging HTTP traffic.
- justniffer β network protocol analyzer that captures traffic and produces customized logs.
- ngrep β pcap-aware tool applying grep-like features to the network layer.
- ntopng β network traffic probe showing usage similar to the Unix
topcommand. - passivedns β tool to collect DNS records passively for incident handling and NSM.
- sagan β multi-threaded, real-time log analysis engine with a Snort-like rule set.
- AIEngine β next generation interactive Python/Ruby/Java/Lua packet inspection engine with NIDS functionality.
- Denyhosts β thwart SSH dictionary-based and brute force attacks.
- Fail2Ban β scans log files and takes action on IPs that show malicious behavior.
- Falco β cloud-native runtime security tool for detecting unexpected behavior in Linux systems.
- Lynis β open source security auditing tool for Linux/Unix.
- OSSEC β comprehensive open source HIDS performing log analysis, file integrity, rootkit detection and alerting.
- Security Onion β Linux distro for intrusion detection, network security monitoring, and log management.
- Snort β free and open source network intrusion prevention and detection system.
- SSHGuard β software protecting services in addition to SSH, written in C.
- sshwatch β IPS for SSH written in Python, gathers attacker information during attacks.
- Stealth β file integrity checker that leaves virtually no sediment on the monitored host.
- Suricata β high performance Network IDS, IPS and Network Security Monitoring engine.
- Wazuh β open source security platform unifying SIEM, XDR, and cloud security capabilities.
- Zeek β powerful network analysis framework (formerly Bro).
- Amun β Python-based low-interaction honeypot.
- awesome-honeypots β the canonical awesome honeypot list.
- Bifrozt β NAT device that works as a transparent SSHv2 proxy between an attacker and your honeypot.
- Conpot β ICS/SCADA low-interactive server-side honeypot.
- Cuckoo Sandbox β open source software for automating analysis of suspicious files.
- Dionaea β nepenthes successor honeypot embedding Python as scripting language.
- Glastopf β honeypot emulating thousands of vulnerabilities to gather web attack data.
- HoneyDrive β premier honeypot Linux distro with over 10 pre-installed honeypot packages.
- HoneyPy β low to medium interaction honeypot, easy to deploy and extend.
- HonSSH β high-interaction honeypot sitting between an attacker and a honeypot over SSH.
- Kippo β medium interaction SSH honeypot for logging brute force attacks.
- Kojoney β low level interaction honeypot emulating an SSH server.
- Dshell β network forensic analysis framework enabling rapid development of dissection plugins.
- Moloch β open source large scale IPv4 packet capturing, indexing and database system.
- OpenFPC β lightweight full-packet network traffic recorder and buffering system.
- stenographer β packet capture solution that spools all packets to disk for fast subset access.
- tcpflow β captures TCP connection data and stores it for protocol analysis and debugging.
- Xplico β open source Network Forensic Analysis Tool extracting applications data from captures.
- netsniff-ng β free Linux networking toolkit using zero-copy mechanisms for high performance.
- Wireshark β free and open-source packet analyzer with graphical front-end and filtering options.
- FIR β Fast Incident Response, a cybersecurity incident management platform.
- OSSIM β AT&T Cybersecurity SIEM with event collection, normalization, and correlation.
- Prelude β universal SIEM collecting, normalizing, aggregating and correlating security events.
- OpenVPN β open source VPN using a custom security protocol utilizing SSL/TLS for key exchange.
- WireGuard β extremely simple yet fast and modern VPN utilizing state-of-the-art cryptography.
- DPDK β set of libraries and drivers for fast packet processing.
- netmap β framework for high speed packet I/O available for FreeBSD, Linux and Windows.
- PACKET_MMAP/TPACKET/AF_PACKET β Linux kernel mechanism for high-performance packet capture and transmission.
- PF_RING β network socket dramatically improving packet capture speed.
- PF_RING ZC (Zero Copy) β flexible packet processing framework achieving line rate at any packet size.
- PFQ β functional networking framework for efficient packet capture and in-kernel processing.
- fwknop β protects ports via Single Packet Authorization.
- OPNsense β open source, easy-to-use FreeBSD-based firewall and routing platform.
- pfSense β firewall and Router FreeBSD distribution.
- SpamAssassin β powerful and popular email spam filter employing a variety of detection techniques.
docker pull kalilinux/kali-rollingβ official Kali Linuxdocker pull ghcr.io/zaproxy/zaproxy:stableβ official OWASP ZAPdocker pull wpscanteam/wpscanβ official WPScandocker pull metasploitframework/metasploit-frameworkβ Metasploitdocker pull citizenstig/dvwaβ Damn Vulnerable Web Applicationdocker pull hmlio/vaas-cve-2014-6271β Vulnerability as a service: Shellshockdocker pull hmlio/vaas-cve-2014-0160β Vulnerability as a service: Heartbleeddocker pull opendns/security-ninjasβ Security Ninjasdocker pull ismisepaul/securityshepherdβ OWASP Security Shepherd
- ClamAV β open source antivirus engine for detecting trojans, viruses, malware and other threats.
- Linux Malware Detect β malware scanner for Linux designed around threats in shared hosted environments.
- DocBleach β open-source CDR software sanitizing Office, PDF and RTF documents.
- Rudder β web-driven, role-based solution for IT Infrastructure Automation and Compliance.
- google-authenticator β implementations of one-time passcode generators and a PAM module.
- android-security-awesome β collection of Android security related resources.
- OWASP Mobile Security Testing Guide β comprehensive manual for mobile app security testing and reverse engineering.
- OSX Security Awesome β collection of OSX and iOS security resources.
- grr β GRR Rapid Response is an incident response framework focused on remote live forensics.
- ir-rescue β Windows Batch and Unix Bash scripts to collect host forensic data during incident response.
- mig β platform to perform investigative surgery on remote endpoints in parallel.
- Velociraptor β tool for collecting host-based state information using Velociraptor Query Language.
- Volatility β Python-based memory extraction and analysis framework.
- abuse.ch β tracks Command&Control servers and provides domain and IP blocklists.
- AlienVault Open Threat Exchange β collaborative threat intelligence network.
- AutoShun β Snort plugin correlating attacks across sensors, honeypots and mail filters worldwide.
- CIFv2 β cyber threat intelligence management system combining malicious threat information from many sources.
- CriticalStack β free aggregated threat intel for the Zeek network security monitoring platform.
- DNS-BH β listing of domains known to propagate malware and spyware.
- Emerging Threats - Open Source β open source community providing Suricata and Snort rules, firewall rules and IDS rulesets.
- FireEye OpenIOCs β FireEye publicly shared Indicators of Compromise.
- IntelMQ β solution for CERTs for collecting and processing security feeds using a message queue protocol.
- Internet Storm Center β free analysis and warning service for Internet threats.
- MISP β open source threat intelligence and sharing platform.
- OpenVAS NVT Feed β public feed of Network Vulnerability Tests containing 35,000+ NVTs.
- PhishTank β collaborative clearing house for phishing data with open API.
- Project Honey Pot β distributed system for identifying spammers and harvesting bots.
- SBL / XBL / PBL / DBL / DROP / ROKSO β Spamhaus real-time anti-spam protection and blocklists.
- TheHive β scalable, open source security incident response platform.
- Tor Bulk Exit List β CollecTor data-collecting service providing Tor network data.
- virustotal β free online service analyzing files and URLs for malicious content detected by 70+ AV engines.
- OWASP β the Open Web Application Security Project, focused on improving the security of software.
- ironbee β open source universal web application security sensor and WAF framework.
- ModSecurity β toolkit for real-time web application monitoring, logging, and access control.
- NAXSI β open-source, high performance, low rules maintenance WAF for NGINX.
- sql_firewall β SQL Firewall extension for PostgreSQL.
- ACSTIS β scans web applications for AngularJS Client-Side Template Injection vulnerabilities.
- Infection Monkey β semi-automatic pen testing tool for mapping and pen-testing networks.
- Nikto β open source web server scanner performing comprehensive tests against web servers.
- OWASP Testing Checklist v4 β list of controls to test during a web vulnerability assessment.
- PTF β Penetration Testers Framework providing modular support for up-to-date tools.
- Recon-ng β full-featured Web Reconnaissance framework written in Python.
- sqlmap β open source penetration testing tool automating detection and exploitation of SQL injection.
- w3af β Web Application Attack and Audit Framework.
- ZAP β OWASP Zed Attack Proxy, easy-to-use integrated penetration testing tool.
- Sqreen β Runtime Application Self-Protection solution instrumenting and monitoring the app at runtime.
- OAuth 2 in Action β book teaching practical use and deployment of OAuth 2.
- Secure by Design β book identifying design patterns and coding styles that reduce security vulnerabilities.
- Securing DevOps β book exploring how DevOps and Security techniques apply together for safer cloud services.
- Semgrep β fast, open source static analysis tool for finding bugs and enforcing code standards.
- Understanding API Security β free eBook on how APIs are put together and how OAuth protects them.
- Usable Security Course β Coursera course on the intersection of security and usability.
- Apache Metron β integrates open source big data technologies for centralized security monitoring and analysis.
- Apache Spot β open source software for leveraging insights from flow and packet analysis.
- binarypig β scalable binary data extraction in Hadoop for malware processing and analytics.
- data_hacking β examples using IPython, Pandas, and Scikit Learn to get the most out of security data.
- hadoop-pcap β Hadoop library to read packet capture (PCAP) files.
- OpenSOC β integrates open source big data technologies for centralized security monitoring.
- Workbench β scalable Python framework for security research and development teams.
- aws-vault β store AWS credentials in the OSX Keychain or an encrypted file.
- blackbox β safely store secrets in a VCS repo using GPG.
- chamber β store secrets using AWS KMS and SSM Parameter Store.
- confidant β stores secrets in AWS DynamoDB, encrypted at rest and integrated with IAM.
- credstash β store secrets using AWS KMS and DynamoDB.
- dotgpg β tool for backing up and versioning production secrets or shared passwords securely.
- passbolt β open source, extensible password manager based on OpenPGP.
- redoctober β server for two-man rule style file encryption and decryption.
- Safe β a Vault CLI making reading and writing to Vault easier.
- Sops β editor of encrypted files supporting YAML, JSON and BINARY formats with AWS KMS and PGP.
- Vault β encrypted datastore secure enough to hold environment and application secrets.
- Checkov β static code analysis tool for infrastructure-as-code detecting security misconfigurations.
- Securing DevOps β book on security techniques for DevOps reviewing state-of-the-art practices.
- tfsec β static analysis security scanner for Terraform code.
- Best Linux Penetration Testing Distributions @ CyberPunk β description of main penetration testing distributions.
- Security @ Distrowatch β website reviewing and tracking open source security operating systems.
- Security related Operating Systems @ Rawsec β complete list of security related operating systems.
- Falco β cloud-native runtime security detecting unexpected behavior and configuration changes.
- Kube-bench β checks whether Kubernetes is deployed according to CIS security benchmarks.
- Kube-hunter β security scanner discovering vulnerabilities and security issues in Kubernetes clusters.
- Kubernetes CIS Benchmark β official CIS benchmark with security configuration guidelines for Kubernetes.
- Kubesec β scans Kubernetes resource manifests for security issues, providing risk scores.
- Open Policy Agent (OPA) β general-purpose policy engine for fine-grained, context-aware policies in Kubernetes.
- Trivy β comprehensive vulnerability scanner for container images, file systems and Kubernetes clusters.
- Azure Defender for Cloud β Microsoft Azure's unified security management with advanced threat protection.
- Cloud Custodian β cloud security policy automation tool managing governance across cloud environments.
- Cloud Security Alliance β provides best practices and security guidance for cloud computing environments.
- GCP Security Command Center β Google Cloud's security and risk management platform for threat detection and compliance.
- Prowler β open source cloud security tool for AWS, Azure and GCP security assessments and audits.
- ScoutSuite β multi-cloud security auditing tool providing comprehensive security posture assessments.
- Grype β vulnerability scanner for container images and filesystems.
- Nessus β widely used commercial vulnerability scanner.
- OpenVAS β open source vulnerability scanner.
- Qualys Community Edition β free version of Qualys vulnerability scanner.
- Rapid7 Nexpose β vulnerability and risk management scanner.
- Vuls β vulnerability scanner for Linux, FreeBSD and containers.
- HashiCorp Boundary β infrastructure access management.
- Keycloak β open source Identity and Access Management.
- OAuth 2.0 β authorization standard.
- OpenID Connect β identity layer on top of OAuth 2.0.
- OWASP Serverless Top 10 β list of top threats in serverless applications.
- PureSec β security for serverless functions.
- Snyk Serverless β Snyk security scanning for serverless applications.
- Android Security Awesome β collection of Android security related resources.
- Awesome CTF β curated list of CTF frameworks, libraries, resources and software.
- Awesome Cyber Skills β curated list of legal hacking environments to train cyber skills.
- Awesome Hacking β curated list of hacking tutorials, tools and resources.
- Awesome Honeypots β awesome list of honeypot resources.
- Awesome Incident Response β curated list of resources for incident response.
- Awesome Industrial Control System Security β resources related to ICS security.
- Awesome Linux Containers β curated list of Linux Containers frameworks, libraries and software.
- Awesome Malware Analysis β curated list of malware analysis tools and resources.
- Awesome PCAP Tools β tools for processing network traces.
- Awesome Pentest β collection of penetration testing resources, tools and shiny things.
- Awesome Pentest Cheat Sheets β cheat sheets useful for pentesting.
- Awesome Threat Detection and Hunting β curated list of threat detection and hunting resources.
- Awesome Threat Intelligence β curated list of threat intelligence resources.
- Awesome Web Hacking β list for learning about web application security.
- Awesome YARA β curated list of awesome YARA rules, tools, and people.
See CONTRIBUTING.md for guidelines.
MIT Β© Think Cube