h0neytr4p is a configurable web honeypot that lets defenders create traps for reconnaissance and exploit attempts without deploying vulnerable applications.
Read more
h0neytr4p is a configurable web honeypot that lets defenders create traps for reconnaissance and exploit attempts without deploying vulnerable applications.
Read more
SentryPeer is a SIP honeypot and fraud-detection tool that records hostile VoIP activity and can share collected data through peer-to-peer networking.
Read more
These tools typically search files and Git repositories for patterns that resemble known types of secrets.
Read more
Heralding is a credentials-catching honeypot that emulates common authentication services and records usernames, passwords, and session data.
Read more
Dionaea is a network honeypot that emulates vulnerable services, detects shellcode, captures attack activity, and supports numerous protocols.
Read more
OpenCanary is a lightweight, modular network honeypot that emulates common services and generates alerts when attackers interact with them.
Read more
Talisman scans Git changesets for passwords, tokens, private keys and other sensitive data before they are committed or pushed.
Read more
WHAD Client is a command-line framework for capturing, analysing, replaying and experimenting with traffic from supported wireless devices and protocols.
Read more
detect-secrets helps teams detect and prevent credentials from entering source code using baselines, plugins, filters and Git hooks.
Read more
Fluxion is a terminal-based security auditing tool for evaluating WPA and WPA2 network exposure through controlled captive-portal testing.
Read more
Gitleaks scans Git repositories, files and standard input for passwords, API keys, tokens and other hard-coded secrets in source code.
Read more
hcxtools is a command-line suite for converting, filtering and analysing wireless captures and authentication hashes during authorised security assessments.
Read more
Keysign is a GTK application that securely exchanges and signs OpenPGP keys over a local network or Bluetooth without relying on a keyserver.
Read more
y509 is a terminal interface for inspecting and validating X.509 certificate chains from files, stdin and live TLS or STARTTLS services.
Read more
Security is paramount. Security involves defense in depth. Approaching security one step at a time, with consistency and rigour, you can mitigate threats.
Read more
Vulnerability analysis is an essential activity for enterprise security. We recommend useful open source tools.
Read more
Jazzer uses code coverage to steer generated inputs towards unexplored paths, crashes and vulnerabilities.
Read more
Ronin is a Ruby toolkit for security research and development. It provides command-line tools and libraries
Read more
Linux has a good range of port scanners that help administrators identify and rectify weaknesses in a system.
Read more
syzkaller is an unsupervised, coverage-guided kernel fuzzer.
Read more