Tools
Security tools for assessment and operations.
A curated catalog of command-line tools, scripts, and frameworks for cloud security, identity review, vulnerability analysis, testing, and defensive operations.
Active Directory
5 toolsPingCastle
AssessmentIdentify and remediate 80% of AD risk in 20% of the time. Comprehensive Active Directory security assessment tool that generates detailed reports on vulnerabilities and misconfigurations.
Purple Knight
AssessmentDiscover Indicators of Exposure (IoEs) and Indicators of Compromise (IoCs) in hybrid AD environments. Free community tool for AD security posture assessment.
Locksmith
ADCSFind and fix common misconfigurations in Active Directory Certificate Services. PowerShell tool that identifies vulnerable certificate templates and ESC attack vectors.
DSInternals
ForensicsActive Directory database forensics and password auditing. PowerShell module for offline ntds.dit analysis, password hash extraction, and credential auditing.
ADRecon
EnumerationExtract and combine various artifacts from AD environment. Generates comprehensive Excel reports covering users, groups, GPOs, and security configurations.
Cloud Security
5 toolsProwler
Multi-CloudSecurity assessment tool for AWS, Azure, GCP, and Kubernetes. Performs hundreds of security checks against cloud best practices and compliance frameworks like CIS, NIST, and PCI-DSS.
ScubaGear
M365Automation to assess M365 tenant against CISA baselines. CISA's official tool for evaluating Microsoft 365 security configurations against SCuBA guidance.
Maester
M365PowerShell-based test automation framework for Microsoft 365 security configuration monitoring. Continuous compliance monitoring with customizable test cases.
ScoutSuite
Multi-CloudMulti-cloud security auditing tool for AWS, Azure, GCP, and more. Generates comprehensive HTML reports with findings organized by service and severity.
Steampipe
Query EngineUniversal SQL interface for cloud APIs - query cloud resources with SQL. Supports hundreds of plugins for AWS, Azure, GCP, and SaaS applications.
Container Security
5 toolsFalco
Runtime SecurityCloud-native runtime security for containers and Kubernetes (CNCF). Detects anomalous activity in containers using system call monitoring and customizable rules.
Kyverno
Policy EngineKubernetes policy engine for security and automation. Define policies as Kubernetes resources to validate, mutate, and generate configurations.
Kubescape
Posture ManagementKubernetes security posture management and compliance. Scans clusters against NSA/CISA hardening guidelines and generates remediation recommendations.
Kube-bench
CIS BenchmarkChecks Kubernetes deployment against CIS Kubernetes Benchmark. Automated compliance checking for master and worker node configurations.
OPA Gatekeeper
Policy EnforcementPolicy controller for Kubernetes using Open Policy Agent. Enforce organizational policies as admission controller webhooks.
Detection Engineering
3 toolsSigma Rules
SIEM RulesMain Sigma rule repository for SIEM detection. Generic signature format for log events that can be converted to various SIEM query languages.
YARA Forge
YARA RulesAutomated YARA rule standardization and quality assurance. Validates and normalizes YARA rules for consistent detection capabilities.
Sysmon Config
Event LoggingSysmon configuration file template with high-quality event tracing. Widely-used baseline configuration for Windows endpoint monitoring.
Endpoint Security
3 toolsVelociraptor
DFIREndpoint visibility and collection tool for digital forensics. Advanced artifact collection and hunting across thousands of endpoints using VQL queries.
Lynis
Security AuditingSecurity auditing tool for Unix/Linux systems. Performs in-depth security scans covering system hardening, compliance, and vulnerability detection.
OSSEC
HIDSOpen source host-based intrusion detection system. Monitors file integrity, log analysis, rootkit detection, and real-time alerting.
Fuzzing
3 toolsAFL++
GeneralAmerican Fuzzy Lop plus plus - improved fuzzing tool. Fork of AFL with many improvements including custom mutators, persistent mode, and QEMU support.
OSS-Fuzz
Continuous FuzzingContinuous fuzzing for open source software. Google's infrastructure for running fuzzers 24/7 against critical open source projects.
LibFuzzer
LibraryIn-process, coverage-guided, evolutionary fuzzing engine. LLVM-based fuzzer ideal for testing libraries and code units with minimal setup.
IAM
3 toolsBloodHound
Attack PathsReveal hidden relationships across identity and access management systems. Graph-based tool for mapping AD attack paths and identifying privilege escalation routes.
BloodHound CE
Attack PathsCommunity Edition of BloodHound with enhanced features. Includes improved UI, API access, and extended query capabilities for enterprise environments.
ROADtools
Azure ADFramework to interact with Azure AD for offensive and defensive security. Enumerate and analyze Azure AD configurations, permissions, and attack paths.
IaC Security
4 toolsCheckov
Static AnalysisStatic analysis for Terraform, CloudFormation, Kubernetes, and more. Scans infrastructure as code for misconfigurations, secrets, and compliance violations.
tfsec
TerraformSecurity scanner for Terraform code. Fast static analysis specifically designed for finding security issues in Terraform configurations.
Terrascan
Multi-IaCStatic code analyzer for infrastructure as code. Detects compliance and security violations across Terraform, Kubernetes, and cloud configs.
KICS
Multi-IaCKeeping Infrastructure as Code Secure - find security vulnerabilities. Supports Terraform, Kubernetes, Docker, CloudFormation, and more.
Infrastructure
2 toolsTerraform
IaCInfrastructure as Code tool. Define and provision cloud infrastructure using declarative configuration files with state management and drift detection.
Ansible
AutomationAgentless automation tool for configuration management. Define infrastructure state using YAML playbooks and execute over SSH without agents.
Network Security
5 toolsResponder
PentestingLLMNR, NBT-NS and MDNS poisoner with rogue authentication servers. Essential tool for capturing NTLMv2 hashes during internal penetration tests.
Zeek
MonitoringPowerful network analysis framework for security monitoring. Generates detailed logs of network activity for threat hunting and incident response.
Suricata
IDS/IPSHigh performance Network IDS, IPS and security monitoring. Multi-threaded engine with support for protocol detection and file extraction.
NetExec
ExecutionSwiss army knife for pentesting networks (formerly CrackMapExec). Automates credential testing, command execution, and lateral movement across networks.
Arkime
Packet CaptureLarge scale packet capture, indexing, and database system (formerly Moloch). Full packet capture with powerful search and session reconstruction.
Offensive Security
4 toolsMetasploit
ExploitationPenetration testing framework. World's most used penetration testing software with extensive exploit database, payloads, and auxiliary modules.
PEASS-ng
Privilege EscalationPrivilege escalation enumeration suite for Windows and Linux. Comprehensive scripts for Windows and Linux privilege escalation vectors.
Sliver
C2 FrameworkModern adversary emulation and red team framework. Cross-platform implant framework with encrypted C2, staging, and evasion capabilities.
SQLMap
SQL InjectionAutomatic SQL injection and database takeover tool. Detects and exploits SQL injection flaws with support for multiple database backends.
OSINT
4 toolsSecLists
WordlistsCollection of multiple types of lists used during security assessments. Usernames, passwords, URLs, sensitive data patterns, and fuzzing payloads.
MISP
Threat IntelligenceOpen source threat intelligence and sharing platform. Share, store, and correlate Indicators of Compromise across organizations.
TheHive
Incident ResponseScalable security incident response platform. Case management for SOC teams with Cortex integration for automated analysis.
OpenCTI
Threat IntelligenceOpen cyber threat intelligence platform. Structured threat intelligence management with STIX2 support and relationship mapping.
Reconnaissance
3 toolsNuclei
Vulnerability ScanningFast and customizable vulnerability scanner. Template-based scanning engine with thousands of community-contributed detection templates.
Amass
DiscoveryIn-depth attack surface mapping and asset discovery. Comprehensive subdomain enumeration using multiple data sources and techniques.
Subfinder
SubdomainFast passive subdomain enumeration tool. Discovers subdomains using passive sources without touching target infrastructure.
Secret Detection
3 toolsTruffleHog
Git ScanningFind secrets in git repos with high entropy detection. Scans commit history for API keys, passwords, and other sensitive data leaks.
Gitleaks
Git ScanningFast secret scanner for git repos, files, and directories. Supports custom rules and integrates with CI/CD pipelines for pre-commit scanning.
git-secrets
PreventionAWS secret prevention tool for git. Pre-commit hooks that prevent committing AWS credentials and other secrets to repositories.
Vulnerability Assessment
8 toolsTrivy
ContainerComprehensive security scanner for containers and IaC. Scans container images, filesystems, git repos, and Kubernetes manifests for vulnerabilities.
Dependency-Track
SBOM ManagementIntelligent component analysis platform for supply chain security. Continuous SBOM analysis with vulnerability tracking across projects.
Grype
ContainerVulnerability scanner for container images and filesystems. Fast scanning with support for multiple vulnerability databases and SBOM input.
Semgrep
SASTLightweight static analysis for finding bugs and enforcing code standards. Pattern-based code scanning with extensive rule library.
OSV-Scanner
Dependency ScanningVulnerability scanner for dependencies using OSV database. Google's open-source vulnerability database scanner for package ecosystems.
Retire.js
JavaScriptScanner detecting JavaScript libraries with known vulnerabilities, generates SBOM. CLI and browser extension for identifying outdated JS dependencies.
Bandit
PythonSecurity linter for Python code. Static analysis tool that finds common security issues in Python applications.
OpenVAS
ScannerFull-featured vulnerability scanner and manager. Network vulnerability scanning with extensive plugin library and reporting.