detect-secrets helps teams detect and prevent credentials from entering source code using baselines, plugins, filters and Git hooks.
Read more
detect-secrets helps teams detect and prevent credentials from entering source code using baselines, plugins, filters and Git hooks.
Read more
Fluxion is a terminal-based security auditing tool for evaluating WPA and WPA2 network exposure through controlled captive-portal testing.
Read more
Gitleaks scans Git repositories, files and standard input for passwords, API keys, tokens and other hard-coded secrets in source code.
Read more
hcxtools is a command-line suite for converting, filtering and analysing wireless captures and authentication hashes during authorised security assessments.
Read more
Keysign is a GTK application that securely exchanges and signs OpenPGP keys over a local network or Bluetooth without relying on a keyserver.
Read more
y509 is a terminal interface for inspecting and validating X.509 certificate chains from files, stdin and live TLS or STARTTLS services.
Read more
Security is paramount. Security involves defense in depth. Approaching security one step at a time, with consistency and rigour, you can mitigate threats.
Read more
Vulnerability analysis is an essential activity for enterprise security. We recommend useful open source tools.
Read more
Jazzer uses code coverage to steer generated inputs towards unexplored paths, crashes and vulnerabilities.
Read more
Ronin is a Ruby toolkit for security research and development. It provides command-line tools and libraries
Read more
Linux has a good range of port scanners that help administrators identify and rectify weaknesses in a system.
Read more
syzkaller is an unsupervised, coverage-guided kernel fuzzer.
Read more
XMap is a fast network scanner for large-scale IPv4 and IPv6 research.
Read more
sx is a command-line network scanner designed to follow the UNIX philosophy.
Read more
Vulnerability scanning is an essential activity for enterprise security. We recommend the best free and open source vulnerability detection tools.
Read more
OSV-Scanner finds known vulnerabilities affecting your project’s dependencies.
Read more
An intrusion detection system is a device or software application that monitors a network or systems for malicious activity or policy violations.
Read more
Slips (Stratosphere Linux IPS) is an endpoint behavioural intrusion detection and prevention system.
Read more
testssl.sh is a command-line tool that checks a server’s service on any port for support of TLS/SSL ciphers and protocols as well as cryptographic flaws.
Read more
Vuls is an agentless vulnerability scanner that identifies security vulnerabilities affecting Linux, FreeBSD, Windows, macOS
Read more