Top #sec Tools & Software
Explore 441 hand-picked tools and software tagged with sec โ ranked by popularity and community signals.
oryx
github๐ต๏ธโโ๏ธ TUI for sniffing network traffic using eBPF on Linux
fibratus
githubAdversary tradecraft detection, protection, and hunting
smart-contract-vulnerabilities
githubA collection of smart contract vulnerabilities along with prevention methods
u2f-zero
githubU2F USB token optimized for physical security, affordability, and style
wifipumpkin3
githubPowerful framework for rogue access point attack.
find-sec-bugs
githubThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
winscript
githubOpen-source tool to build your Windows script from scratch. It includes debloat, privacy, performance & app installing scripts.
brutespray
githubFast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
awesome-cloud-security
github๐ก๏ธ Awesome Cloud Security Resources โ๏ธ
awesome-iot-hacks
githubA Collection of Hacks in IoT Space so that we can address them (hopefully).
Malcolm
githubMalcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
solo1
githubSolo 1 firmware in C
cloudfox
githubAutomating situational awareness for cloud penetration tests.
creepjs
githubCreepy device and browser fingerprinting
agent-scan
githubSecurity scanner for AI agents, MCP servers and agent skills.
secure
githubHTTP middleware for Go that facilitates some quick security wins.
noseyparker
githubNosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
boofuzz
githubA fork and successor of the Sulley Fuzzing Framework
caido
github๐ Caido releases, wiki and roadmap
awesome-embedded-and-iot-security
githubA curated list of awesome embedded and IoT security resources.
cargo-crev
githubA cryptographically verifiable code review system for the cargo (Rust) package manager.
tirith
githubTerminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
accesscontrol
githubRole and Attribute based Access Control for Node.js
android-inline-hook
github:fire: ShadowHook is an Android inline hook library which supports thumb, arm32 and arm64.