Geek-Guy.com

Top ~100 Open Source Security Tools

1. Network Discovery & Scanning

Tool NameOfficial URLPurpose
Nmaphttps://nmap.org/Network exploration and security auditing
ZMaphttps://zmap.io/Fast internet-wide network scanner
Masscanhttps://github.com/robertdavidgraham/masscanTCP port scanner, spews SYN packets
Netcat (ncat)https://nmap.org/ncat/The “Swiss-army knife” for TCP/IP
Scapyhttps://scapy.net/Packet manipulation and sniffing

2. Vulnerability Scanning & Management

Tool NameOfficial URLPurpose
OpenVAS (GVM)https://www.openvas.org/Full-featured vulnerability scanner
Niktohttps://github.com/sullo/niktoWeb server vulnerability scanner
Nucleihttps://github.com/projectdiscovery/nucleiTemplate-based vulnerability scanner
DefectDojohttps://www.defectdojo.org/Vulnerability management orchestration
Wapitihttps://wapiti.sourceforge.io/Web application vulnerability scanner

3. Web Application Security

Tool NameOfficial URLPurpose
OWASP ZAPhttps://www.zaproxy.org/Integrated penetration testing tool for web apps
SQLmaphttps://sqlmap.org/Automatic SQL injection and takeover tool
Burp Suite (Community)https://portswigger.net/burp/communitydownloadWeb proxy and analysis
Wfuzzhttps://github.com/xmendez/wfuzzWeb application fuzzer
BeEFhttps://beefproject.com/Browser Exploitation Framework

4. Intrusion Detection & Prevention (IDS/IPS)

Tool NameOfficial URLPurpose
Snorthttps://www.snort.org/Network intrusion prevention system
Suricatahttps://suricata.io/High-performance network IDS/IPS/NSM
Zeek (Bro)https://zeek.org/Network security monitoring platform
OSSEChttps://www.ossec.net/Host-based IDS and log analysis
Wazuhhttps://wazuh.com/Unified XDR and SIEM platform

5. Digital Forensics & Incident Response (DFIR)

Tool NameOfficial URLPurpose
The Sleuth Kit (TSK)https://www.sleuthkit.org/File system analysis tools
Autopsyhttps://www.autopsy.com/Digital forensics platform
Volatilityhttps://www.volatilityfoundation.org/Memory forensics framework
GRRhttps://github.com/google/grrRemote live forensics framework
Velociraptorhttps://docs.velociraptor.app/Endpoint visibility and incident response

6. Password Cracking & Identity

Tool NameOfficial URLPurpose
John the Ripperhttps://www.openwall.com/john/Fast password cracker
Hashcathttps://hashcat.net/hashcat/Advanced password recovery tool
Hydrahttps://github.com/vanhauser-thc/thc-hydraNetwork login cracker
Mimikatzhttps://github.com/gentilkiwi/mimikatzWindows credential extraction
BloodHoundhttps://github.com/BloodHoundAD/BloodHoundActive Directory relationship mapping

7. Privacy, Encryption & VPN

Tool NameOfficial URLPurpose
OpenVPNhttps://openvpn.net/Secure tunneling and VPN
WireGuardhttps://www.wireguard.com/Modern, fast, and simple VPN
VeraCrypthttps://www.veracrypt.fr/On-the-fly disk encryption
GnuPG (GPG)https://gnupg.org/Secure communication and data storage
Torhttps://www.torproject.org/Anonymity and censorship circumvention

8. Security Distributions (Operating Systems)

Tool NameOfficial URLPurpose
Kali Linuxhttps://www.kali.org/Advanced penetration testing distro
Parrot Securityhttps://www.parrotsec.org/Security-focused OS for dev and ops
Qubes OShttps://www.qubes-os.org/Security through compartmentalization
Tailshttps://tails.net/Amnesic incognito live system
Security Onionhttps://securityonion.net/Threat hunting and log management distro

9. Cloud & Infrastructure Security

Tool NameOfficial URLPurpose
Falcohttps://falco.org/Cloud-native runtime security
Trivyhttps://github.com/aquasecurity/trivyVulnerability scanner for containers
Checkovhttps://www.checkov.io/Infrastructure as Code (IaC) scanning
Prowlerhttps://github.com/prowler-cloud/prowlerAWS/Azure/GCP security assessment
Cloud Custodianhttps://cloudcustodian.io/Rules engine for cloud management

10. Exploitation & Post-Exploitation

Tool NameOfficial URLPurpose
Metasploithttps://www.metasploit.com/Penetration testing framework
Empirehttps://github.com/BC-SECURITY/EmpirePowerShell and Python post-exploitation
Covenanthttps://github.com/cobbr/Covenant.NET command and control framework
Responderhttps://github.com/lgandx/ResponderLLMNR, NBT-NS and MDNS poisoner
Bettercaphttps://www.bettercap.org/Network attack and monitoring framework