Tools

Security tools for assessment and operations.

A curated catalog of command-line tools, scripts, and frameworks for cloud security, identity review, vulnerability analysis, testing, and defensive operations.

60 tools 15 categories Industry focused

Active Directory

5 tools

PingCastle

Assessment

Identify and remediate 80% of AD risk in 20% of the time. Comprehensive Active Directory security assessment tool that generates detailed reports on vulnerabilities and misconfigurations.

Purple Knight

Assessment

Discover Indicators of Exposure (IoEs) and Indicators of Compromise (IoCs) in hybrid AD environments. Free community tool for AD security posture assessment.

Locksmith

ADCS

Find and fix common misconfigurations in Active Directory Certificate Services. PowerShell tool that identifies vulnerable certificate templates and ESC attack vectors.

DSInternals

Forensics

Active Directory database forensics and password auditing. PowerShell module for offline ntds.dit analysis, password hash extraction, and credential auditing.

ADRecon

Enumeration

Extract and combine various artifacts from AD environment. Generates comprehensive Excel reports covering users, groups, GPOs, and security configurations.

Cloud Security

5 tools

Prowler

Multi-Cloud

Security assessment tool for AWS, Azure, GCP, and Kubernetes. Performs hundreds of security checks against cloud best practices and compliance frameworks like CIS, NIST, and PCI-DSS.

ScubaGear

M365

Automation to assess M365 tenant against CISA baselines. CISA's official tool for evaluating Microsoft 365 security configurations against SCuBA guidance.

Maester

M365

PowerShell-based test automation framework for Microsoft 365 security configuration monitoring. Continuous compliance monitoring with customizable test cases.

ScoutSuite

Multi-Cloud

Multi-cloud security auditing tool for AWS, Azure, GCP, and more. Generates comprehensive HTML reports with findings organized by service and severity.

Steampipe

Query Engine

Universal SQL interface for cloud APIs - query cloud resources with SQL. Supports hundreds of plugins for AWS, Azure, GCP, and SaaS applications.

Container Security

5 tools

Falco

Runtime Security

Cloud-native runtime security for containers and Kubernetes (CNCF). Detects anomalous activity in containers using system call monitoring and customizable rules.

Kyverno

Policy Engine

Kubernetes policy engine for security and automation. Define policies as Kubernetes resources to validate, mutate, and generate configurations.

Kubescape

Posture Management

Kubernetes security posture management and compliance. Scans clusters against NSA/CISA hardening guidelines and generates remediation recommendations.

Kube-bench

CIS Benchmark

Checks Kubernetes deployment against CIS Kubernetes Benchmark. Automated compliance checking for master and worker node configurations.

OPA Gatekeeper

Policy Enforcement

Policy controller for Kubernetes using Open Policy Agent. Enforce organizational policies as admission controller webhooks.

Detection Engineering

3 tools

Sigma Rules

SIEM Rules

Main Sigma rule repository for SIEM detection. Generic signature format for log events that can be converted to various SIEM query languages.

YARA Forge

YARA Rules

Automated YARA rule standardization and quality assurance. Validates and normalizes YARA rules for consistent detection capabilities.

Sysmon Config

Event Logging

Sysmon configuration file template with high-quality event tracing. Widely-used baseline configuration for Windows endpoint monitoring.

Endpoint Security

3 tools

Endpoint visibility and collection tool for digital forensics. Advanced artifact collection and hunting across thousands of endpoints using VQL queries.

Lynis

Security Auditing

Security auditing tool for Unix/Linux systems. Performs in-depth security scans covering system hardening, compliance, and vulnerability detection.

OSSEC

HIDS

Open source host-based intrusion detection system. Monitors file integrity, log analysis, rootkit detection, and real-time alerting.

Fuzzing

3 tools

AFL++

General

American Fuzzy Lop plus plus - improved fuzzing tool. Fork of AFL with many improvements including custom mutators, persistent mode, and QEMU support.

OSS-Fuzz

Continuous Fuzzing

Continuous fuzzing for open source software. Google's infrastructure for running fuzzers 24/7 against critical open source projects.

LibFuzzer

Library

In-process, coverage-guided, evolutionary fuzzing engine. LLVM-based fuzzer ideal for testing libraries and code units with minimal setup.

IAM

3 tools

BloodHound

Attack Paths

Reveal hidden relationships across identity and access management systems. Graph-based tool for mapping AD attack paths and identifying privilege escalation routes.

BloodHound CE

Attack Paths

Community Edition of BloodHound with enhanced features. Includes improved UI, API access, and extended query capabilities for enterprise environments.

ROADtools

Azure AD

Framework to interact with Azure AD for offensive and defensive security. Enumerate and analyze Azure AD configurations, permissions, and attack paths.

IaC Security

4 tools

Checkov

Static Analysis

Static analysis for Terraform, CloudFormation, Kubernetes, and more. Scans infrastructure as code for misconfigurations, secrets, and compliance violations.

tfsec

Terraform

Security scanner for Terraform code. Fast static analysis specifically designed for finding security issues in Terraform configurations.

Terrascan

Multi-IaC

Static code analyzer for infrastructure as code. Detects compliance and security violations across Terraform, Kubernetes, and cloud configs.

KICS

Multi-IaC

Keeping Infrastructure as Code Secure - find security vulnerabilities. Supports Terraform, Kubernetes, Docker, CloudFormation, and more.

Infrastructure

2 tools

Terraform

IaC

Infrastructure as Code tool. Define and provision cloud infrastructure using declarative configuration files with state management and drift detection.

Ansible

Automation

Agentless automation tool for configuration management. Define infrastructure state using YAML playbooks and execute over SSH without agents.

Network Security

5 tools

Responder

Pentesting

LLMNR, NBT-NS and MDNS poisoner with rogue authentication servers. Essential tool for capturing NTLMv2 hashes during internal penetration tests.

Zeek

Monitoring

Powerful network analysis framework for security monitoring. Generates detailed logs of network activity for threat hunting and incident response.

Suricata

IDS/IPS

High performance Network IDS, IPS and security monitoring. Multi-threaded engine with support for protocol detection and file extraction.

NetExec

Execution

Swiss army knife for pentesting networks (formerly CrackMapExec). Automates credential testing, command execution, and lateral movement across networks.

Arkime

Packet Capture

Large scale packet capture, indexing, and database system (formerly Moloch). Full packet capture with powerful search and session reconstruction.

Offensive Security

4 tools

Metasploit

Exploitation

Penetration testing framework. World's most used penetration testing software with extensive exploit database, payloads, and auxiliary modules.

PEASS-ng

Privilege Escalation

Privilege escalation enumeration suite for Windows and Linux. Comprehensive scripts for Windows and Linux privilege escalation vectors.

Sliver

C2 Framework

Modern adversary emulation and red team framework. Cross-platform implant framework with encrypted C2, staging, and evasion capabilities.

SQLMap

SQL Injection

Automatic SQL injection and database takeover tool. Detects and exploits SQL injection flaws with support for multiple database backends.

OSINT

4 tools

SecLists

Wordlists

Collection of multiple types of lists used during security assessments. Usernames, passwords, URLs, sensitive data patterns, and fuzzing payloads.

MISP

Threat Intelligence

Open source threat intelligence and sharing platform. Share, store, and correlate Indicators of Compromise across organizations.

TheHive

Incident Response

Scalable security incident response platform. Case management for SOC teams with Cortex integration for automated analysis.

OpenCTI

Threat Intelligence

Open cyber threat intelligence platform. Structured threat intelligence management with STIX2 support and relationship mapping.

Reconnaissance

3 tools

Nuclei

Vulnerability Scanning

Fast and customizable vulnerability scanner. Template-based scanning engine with thousands of community-contributed detection templates.

Amass

Discovery

In-depth attack surface mapping and asset discovery. Comprehensive subdomain enumeration using multiple data sources and techniques.

Subfinder

Subdomain

Fast passive subdomain enumeration tool. Discovers subdomains using passive sources without touching target infrastructure.

Secret Detection

3 tools

TruffleHog

Git Scanning

Find secrets in git repos with high entropy detection. Scans commit history for API keys, passwords, and other sensitive data leaks.

Gitleaks

Git Scanning

Fast secret scanner for git repos, files, and directories. Supports custom rules and integrates with CI/CD pipelines for pre-commit scanning.

git-secrets

Prevention

AWS secret prevention tool for git. Pre-commit hooks that prevent committing AWS credentials and other secrets to repositories.

Vulnerability Assessment

8 tools

Trivy

Container

Comprehensive security scanner for containers and IaC. Scans container images, filesystems, git repos, and Kubernetes manifests for vulnerabilities.

Dependency-Track

SBOM Management

Intelligent component analysis platform for supply chain security. Continuous SBOM analysis with vulnerability tracking across projects.

Grype

Container

Vulnerability scanner for container images and filesystems. Fast scanning with support for multiple vulnerability databases and SBOM input.

Semgrep

SAST

Lightweight static analysis for finding bugs and enforcing code standards. Pattern-based code scanning with extensive rule library.

OSV-Scanner

Dependency Scanning

Vulnerability scanner for dependencies using OSV database. Google's open-source vulnerability database scanner for package ecosystems.

Retire.js

JavaScript

Scanner detecting JavaScript libraries with known vulnerabilities, generates SBOM. CLI and browser extension for identifying outdated JS dependencies.

Bandit

Python

Security linter for Python code. Static analysis tool that finds common security issues in Python applications.

OpenVAS

Scanner

Full-featured vulnerability scanner and manager. Network vulnerability scanning with extensive plugin library and reporting.