security Tools
469 tools found
u2f-zero
githubU2F USB token optimized for physical security, affordability, and style
wifipumpkin3
githubPowerful framework for rogue access point attack.
find-sec-bugs
githubThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
winscript
githubOpen-source tool to build your Windows script from scratch. It includes debloat, privacy, performance & app installing scripts.
brutespray
githubFast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
awesome-cloud-security
github๐ก๏ธ Awesome Cloud Security Resources โ๏ธ
awesome-iot-hacks
githubA Collection of Hacks in IoT Space so that we can address them (hopefully).
Malcolm
githubMalcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
solo1
githubSolo 1 firmware in C
cloudfox
githubAutomating situational awareness for cloud penetration tests.
creepjs
githubCreepy device and browser fingerprinting
agent-scan
githubSecurity scanner for AI agents, MCP servers and agent skills.
secure
githubHTTP middleware for Go that facilitates some quick security wins.
noseyparker
githubNosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
boofuzz
githubA fork and successor of the Sulley Fuzzing Framework
SSH-Snake
githubSSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.
caido
github๐ Caido releases, wiki and roadmap
stratus-red-team
github:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
awesome-embedded-and-iot-security
githubA curated list of awesome embedded and IoT security resources.
cargo-crev
githubA cryptographically verifiable code review system for the cargo (Rust) package manager.
burpgpt
githubA Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.
tirith
githubTerminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
accesscontrol
githubRole and Attribute based Access Control for Node.js
android-inline-hook
github:fire: ShadowHook is an Android inline hook library which supports thumb, arm32 and arm64.