bitrat is a fast command-line checksum tool supporting multiple hash algorithms, HMAC, parallel processing, and nested file hierarchies.
Read more
bitrat is a fast command-line checksum tool supporting multiple hash algorithms, HMAC, parallel processing, and nested file hierarchies.
Read more
Explore free and open source honeypot tools for detecting attacks, analysing malware, capturing credentials, and monitoring threats.
Read more
DRAKVUF Sandbox provides agentless, black-box malware analysis with a web interface, automated sandboxing and detailed behavioural reports.
Read more
paq is a fast BLAKE3 command-line tool for recursively hashing files and directories with deterministic output and parallel processing.
Read more
Nyxelf combines static and dynamic analysis, decompilation and a QEMU sandbox to investigate suspicious Linux ELF binaries through a graphical interface.
Read more
MISP is a threat intelligence platform for collecting, correlating, sharing, importing, exporting and automating security intelligence.
Read more
h0neytr4p is a configurable web honeypot that lets defenders create traps for reconnaissance and exploit attempts without deploying vulnerable applications.
Read more
SentryPeer is a SIP honeypot and fraud-detection tool that records hostile VoIP activity and can share collected data through peer-to-peer networking.
Read more
These tools typically search files and Git repositories for patterns that resemble known types of secrets.
Read more
Heralding is a credentials-catching honeypot that emulates common authentication services and records usernames, passwords, and session data.
Read more
Dionaea is a network honeypot that emulates vulnerable services, detects shellcode, captures attack activity, and supports numerous protocols.
Read more
OpenCanary is a lightweight, modular network honeypot that emulates common services and generates alerts when attackers interact with them.
Read more
Talisman scans Git changesets for passwords, tokens, private keys and other sensitive data before they are committed or pushed.
Read more
WHAD Client is a command-line framework for capturing, analysing, replaying and experimenting with traffic from supported wireless devices and protocols.
Read more
detect-secrets helps teams detect and prevent credentials from entering source code using baselines, plugins, filters and Git hooks.
Read more
Fluxion is a terminal-based security auditing tool for evaluating WPA and WPA2 network exposure through controlled captive-portal testing.
Read more
Gitleaks scans Git repositories, files and standard input for passwords, API keys, tokens and other hard-coded secrets in source code.
Read more
hcxtools is a command-line suite for converting, filtering and analysing wireless captures and authentication hashes during authorised security assessments.
Read more
Keysign is a GTK application that securely exchanges and signs OpenPGP keys over a local network or Bluetooth without relying on a keyserver.
Read more
y509 is a terminal interface for inspecting and validating X.509 certificate chains from files, stdin and live TLS or STARTTLS services.
Read more