Open Source Security Library
Legitimate, openly licensed security projects
Defensive and educational tooling with links to official project websites, repositories, licences and documentation.
What this library will never contain
Wireshark
IntermediateNetwork protocol analyser for inspecting traffic on networks you are authorised to monitor.
Zeek
AdvancedNetwork security monitor that turns traffic into high-fidelity logs for detection and analysis.
Suricata
AdvancedOpen-source IDS/IPS and network security monitoring engine.
OWASP ZAP
IntermediateWeb application security scanner for testing applications you own or are authorised to assess.
OWASP Juice Shop
BeginnerIntentionally vulnerable web application for safe, legal hands-on security practice.
OWASP Dependency-Check
IntermediateSoftware composition analysis tool that flags known-vulnerable dependencies.
OpenVAS / Greenbone
AdvancedVulnerability scanning framework for assessing systems under your control.
Autopsy
AdvancedDigital forensics platform for analysing disk images and investigating incidents.
Volatility 3
AdvancedMemory forensics framework used to analyse captured RAM images during investigations.
YARA
IntermediatePattern-matching engine for identifying and classifying malware samples in analysis labs.
Hashcat
AdvancedPassword auditing tool used by authorised administrators to test the strength of their own password hashes.
Tor Browser
BeginnerPrivacy-preserving browser that routes traffic through the Tor network.
GnuPG
IntermediateComplete implementation of the OpenPGP standard for encryption and digital signatures.
VeraCrypt
BeginnerDisk encryption software for protecting data at rest on laptops and removable media.
SpiderFoot
IntermediateOSINT automation tool for footprinting assets you own during authorised assessments.
Wazuh
AdvancedOpen-source security platform combining XDR and SIEM capabilities across endpoints and cloud.
TheHive
AdvancedScalable, collaborative security incident response platform for case management.
Lynis
IntermediateSecurity auditing tool for Linux and Unix-based systems you administer.
Prowler
IntermediateCloud security assessment tool for auditing AWS, Azure and GCP accounts you control.
Trivy
BeginnerScanner for container images, file systems and IaC that reports known vulnerabilities and misconfigurations.
picoCTF
BeginnerFree capture-the-flag platform with legal, purpose-built challenges for learners.
OWASP Amass
IntermediateAttack-surface mapping and external asset discovery for domains you own.