Open Source Security Library

Legitimate, openly licensed security projects

Defensive and educational tooling with links to official project websites, repositories, licences and documentation.

What this library will never contain

We do not host or link to pirated material, stolen credentials, malware, exploit kits, credential dumps, or unauthorized access tools. Projects listed here are for defensive, educational and authorized use only.

Wireshark

Intermediate

Network protocol analyser for inspecting traffic on networks you are authorised to monitor.

Category: Network security
License: GPL-2.0
Use: Defensive traffic analysis and troubleshooting

Zeek

Advanced

Network security monitor that turns traffic into high-fidelity logs for detection and analysis.

Category: Security monitoring
License: BSD-3-Clause
Use: Network monitoring and detection engineering

Suricata

Advanced

Open-source IDS/IPS and network security monitoring engine.

Category: Security monitoring
License: GPL-2.0
Use: Intrusion detection on authorised networks

OWASP ZAP

Intermediate

Web application security scanner for testing applications you own or are authorised to assess.

Category: Web security
License: Apache-2.0
Use: Authorised web application assessment

OWASP Juice Shop

Beginner

Intentionally vulnerable web application for safe, legal hands-on security practice.

Category: CTF/learning platforms
License: MIT
Use: Safe practice lab you run yourself

OWASP Dependency-Check

Intermediate

Software composition analysis tool that flags known-vulnerable dependencies.

Category: Secure development
License: Apache-2.0
Use: Supply-chain risk reduction in CI

OpenVAS / Greenbone

Advanced

Vulnerability scanning framework for assessing systems under your control.

Category: Vulnerability assessment
License: GPL-2.0
Use: Authorised vulnerability assessment

Autopsy

Advanced

Digital forensics platform for analysing disk images and investigating incidents.

Category: Digital forensics
License: Apache-2.0
Use: Forensic investigation of your own systems

Volatility 3

Advanced

Memory forensics framework used to analyse captured RAM images during investigations.

Category: Malware analysis
License: VSL / MIT-style
Use: Incident investigation and memory analysis

YARA

Intermediate

Pattern-matching engine for identifying and classifying malware samples in analysis labs.

Category: Malware analysis
License: BSD-3-Clause
Use: Detection rule writing and triage

Hashcat

Advanced

Password auditing tool used by authorised administrators to test the strength of their own password hashes.

Category: Password auditing
License: MIT
Use: Authorised internal password strength auditing only

Tor Browser

Beginner

Privacy-preserving browser that routes traffic through the Tor network.

Category: Privacy
License: BSD-3-Clause / MPL
Use: Personal privacy and censorship circumvention

GnuPG

Intermediate

Complete implementation of the OpenPGP standard for encryption and digital signatures.

Category: Encryption
License: GPL-3.0
Use: Encrypting and signing files and messages

VeraCrypt

Beginner

Disk encryption software for protecting data at rest on laptops and removable media.

Category: Encryption
License: Apache-2.0 / TrueCrypt License
Use: Device and volume encryption

SpiderFoot

Intermediate

OSINT automation tool for footprinting assets you own during authorised assessments.

Category: OSINT
License: MIT
Use: Attack-surface discovery for your own organisation

Wazuh

Advanced

Open-source security platform combining XDR and SIEM capabilities across endpoints and cloud.

Category: SIEM
License: GPL-2.0
Use: Log analysis, detection and compliance monitoring

TheHive

Advanced

Scalable, collaborative security incident response platform for case management.

Category: Incident response
License: AGPL-3.0
Use: Coordinating incident response cases

Lynis

Intermediate

Security auditing tool for Linux and Unix-based systems you administer.

Category: Linux security
License: GPL-3.0
Use: Hardening audits on your own hosts

Prowler

Intermediate

Cloud security assessment tool for auditing AWS, Azure and GCP accounts you control.

Category: Cloud security
License: Apache-2.0
Use: Cloud configuration and compliance auditing

Trivy

Beginner

Scanner for container images, file systems and IaC that reports known vulnerabilities and misconfigurations.

Category: Cloud security
License: Apache-2.0
Use: Container and IaC security scanning

picoCTF

Beginner

Free capture-the-flag platform with legal, purpose-built challenges for learners.

Category: CTF/learning platforms
License: Free educational platform
Use: Legal hands-on practice environment

OWASP Amass

Intermediate

Attack-surface mapping and external asset discovery for domains you own.

Category: OSINT
License: Apache-2.0
Use: Mapping your own external attack surface