Security & OSINT Tools Library

Explore and search our hand-picked collection of open-source security research, CTI, and intelligence investigation tools.

Breach Intelligence

Dehashed is a breach data search engine that allows security professionals to search for compromised credentials, email addresses, usernames, and passwords across multiple data breaches.

Penetration Testing

Impacket is a collection of Python classes for working with network protocols, widely used by penetration testers for Windows and Active Directory attacks including SMB, Kerberos, and NTLM relay.

Social Media Intelligence

Sherlock is a powerful social media OSINT tool that hunts for usernames across over 300 social networks and platforms.

Digital Forensics

KAPE (Kroll Artifact Parser and Extractor) is a free triage tool that rapidly collects and parses forensic artifacts from Windows systems, dramatically speeding up incident response and digital forensics.

OSINT

The world's first search engine for internet-connected devices, enabling cybersecurity professionals to discover exposed systems, analyze network infrastructure, and assess global attack surfaces.

OSINT

OWASP open-source subdomain enumeration and network mapping tool using passive and active techniques to discover attack surfaces.

Certificate Intelligence

CRT.sh is a certificate transparency log search engine that provides comprehensive visibility into SSL/TLS certificates issued for domains worldwide.

Endpoint Visibility

osquery is an open-source endpoint visibility agent that exposes operating system state as a relational database, letting security teams query processes, files, users, and network connections using SQL.

IP Intelligence

IPinfo is a comprehensive IP address intelligence platform that provides geolocation, ASN, carrier, and threat data for any IP address.

Threat Detection

A powerful library manager for Sigma detection rules, supporting validation, conversion to SIEM queries, and rule organization for enterprise threat detection across multiple platforms.

Malware Analysis

Azul is an open-source malware analysis platform released by the Australian Signals Directorate in 2026 that scales to handle tens of millions of malware samples.

OSINT

Industry-leading threat intelligence platform that analyzes files, URLs, and IP addresses using 70+ antivirus engines and threat detection systems.

Threat Intelligence

Group-IB Free Tools provides free malware analysis, email security, and threat intelligence resources including Threat Hunting Platform and TDS detection.

OSINT

Fast, passive subdomain discovery tool written in Go that uses certificate transparency logs, search engines, and DNS data sources.

Network Analysis

Wireshark is a free, open-source packet analyzer used for network troubleshooting, traffic analysis, and forensic investigations.

Security Operations

Velociraptor is an open-source endpoint visibility and collection tool using VQL queries for advanced incident response and digital forensics.

Digital Forensics

Volatility 3 is the reference open-source memory forensics framework for analyzing RAM captures to uncover hidden processes, injected code, network connections, and malware artifacts on compromised systems.

OSINT Framework

Recon-ng is a full-featured reconnaissance framework written in Python, designed for OSINT gathering with a modular architecture and interactive command-line interface.

Internet Intelligence

ZoomEye is a leading Chinese cyberspace search engine developed by Knownsec's 404 Lab that provides comprehensive internet asset discovery and network mapping.

Reverse Engineering

Ghidra is a free and open-source software reverse engineering suite developed by the NSA that provides disassembly, decompilation, scripting, and collaborative analysis of binaries across many architectures.

Digital Forensics

SIFT Workstation is a free, open-source digital forensics and incident response platform maintained by SANS with a comprehensive collection of forensic tools.

Digital Forensics

Autopsy is a free, open-source digital forensics platform providing a graphical interface for disk analysis, file recovery, and timeline investigations.

Malware Analysis

Joe Sandbox is a powerful deep malware analysis platform providing automated behavioral analysis, phishing detection, and advanced threat intelligence.

Threat Detection

MITRE ATT&CK Navigator is a free web-based tool for visualizing, annotating, and comparing coverage of adversary tactics and techniques from the MITRE ATT&CK knowledge base.

OSINT

Industry-leading graphical link analysis and data visualization tool for OSINT investigations, enabling analysts to uncover hidden relationships between entities like domains, IP addresses, people, and organizations through an intuitive visual interface.

Digital Forensics

CAINE is a free, open-source GNU/Linux live distribution created specifically for digital forensics with an integrated forensic environment.

OSINT

Open-source intelligence automation platform that integrates with over 200 data sources to perform comprehensive reconnaissance, threat intelligence gathering, and attack surface mapping for cybersecurity professionals and investigators.

Network Analysis

Gephi is a free, open-source network analysis and visualization tool used to map relationships and uncover hidden connections in data.

DNS Intelligence

DNSDumpster is a free domain research tool that provides comprehensive DNS enumeration, subdomain discovery, and mapping of DNS infrastructure.

Network Security

Zeek is a powerful open-source network security monitor that turns raw traffic into rich, structured logs of connections, protocols, files, and application-layer activity for threat hunting and NSM.

OSINT

Comprehensive internet-wide scanning platform providing visibility into hosts, networks, and certificates, enabling security teams to discover and analyze global attack surfaces.

Security Operations

Intezer is an AI-powered SOC platform that won Best Autonomous Security Operations Platform 2026, providing forensic-grade AI for alert triage and investigation.

Technology Fingerprinting

Wappalyzer is a technology fingerprinting tool that identifies content management systems, frameworks, and libraries used by websites through browser extension and API.

Threat Intelligence

Bitsight is a leading enterprise cyber threat intelligence platform that monitors over 40 million organizations globally with AI-enriched OSINT and dark web monitoring.

Malware Analysis

YARA is a powerful open-source pattern matching tool designed for identifying and classifying malware through custom rule creation.

OSINT Framework

OSINT Framework is a comprehensive curated directory of open-source intelligence tools organized by intelligence category and purpose.

Vulnerability Scanning

Nuclei is a fast, template-driven vulnerability scanner that uses a community-powered library of YAML templates to detect CVEs, misconfigurations, exposed panels, and default credentials at scale.

Network Intelligence

GreyNoise is a cybersecurity platform that analyzes and categorizes internet-wide scanning activity to help security professionals distinguish between random scans and targeted threats.

Threat Intelligence

ThreatConnect is a comprehensive threat intelligence platform acquired by Dataminr in 2025, offering TI Ops, Risk Quantifier, and Polarity capabilities.

Technology Intelligence

BuiltWith is a comprehensive technology profiler that identifies websites' technology stack, including frameworks, CMS, analytics, and hosting providers.

Malware Analysis

FLARE VM is a free, open-source Windows-based malware analysis distribution created by FireEye/Mandiant with over 80 pre-configured reverse engineering tools.

Threat Intelligence

AlienVault OTX (Open Threat Exchange) is a community-powered threat intelligence platform that enables sharing and collaboration on global security threats.

Internet Intelligence

Modat is a European internet intelligence platform that provides unique Device DNA and internet scanning intelligence with a focus on cybersecurity and asset discovery.

DNS Intelligence

SecurityTrails is a comprehensive domain and DNS intelligence platform that provides historical DNS data, subdomain discovery, and passive DNS reconnaissance capabilities.

Internet Intelligence

Quake is a Chinese network asset discovery engine developed by 360 that provides comprehensive scanning and intelligence on internet-connected infrastructure.

Antivirus

ClamAV is an open-source antivirus engine designed for detecting malware, viruses, and malicious content with support for YARA rules.

Internet Intelligence

Global Eagle is a Chinese cyberspace mapping platform developed by Qi'anxin that provides comprehensive internet asset discovery and intelligence.

Vulnerability Intelligence

Exploit-DB is a comprehensive database of exploits, vulnerabilities, and proof-of-concept code maintained by Offensive Security.

OSINT

Command-line OSINT tool for gathering emails, subdomains, and employee names from public sources including search engines, PGP key servers, and social media platforms.

Malware Analysis

ANY.RUN is a cloud-based interactive malware sandbox that provides real-time analysis with over 600,000 security professionals and 15,000 organizations globally.

Vulnerability Intelligence

Vulners is a comprehensive vulnerability database that aggregates security advisories, CVEs, exploits, and vulnerability intelligence from multiple sources.

OSINT

Popular service for checking if email addresses or passwords have been exposed in data breaches, providing essential security intelligence.

Threat Intelligence

MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform designed for sharing, storing, and correlating indicators of compromise and threat data.

Threat Intelligence

SOCRadar Free Tools is a comprehensive OSINT platform offering free threat intelligence tools for SOC analysts and security professionals.

Web Analysis

URLScan.io is a free website scanner and threat analysis platform that captures screenshots, DOM snapshots, and HTTP details of any URL.

OSINT Framework

NetSpecter is a browser-based OSINT and passive reconnaissance tool that requires no installation, no API keys, and offers over 90+ investigative modules.

Endpoint Security

Fail2Ban is a lightweight open-source intrusion prevention tool that monitors log files and dynamically bans IP addresses showing malicious behavior such as brute-force login attempts.

Web Analysis

Webamon is a London-based threat intelligence platform that scans, monitors, and indexes the web daily, positioning itself as The Google of Threat Intelligence.

Email Intelligence

Hunter.io is an email discovery and verification platform that helps find, verify, and connect with professional email addresses associated with domains.

OSINT

Free, community-driven platform for sharing Indicators of Compromise (IOCs) related to malware infrastructure, enabling threat intelligence enrichment.

Internet Intelligence

FOFA is a leading Chinese cyberspace search engine that indexes internet-connected devices with over 350,000 fingerprint rules and 4 billion assets.

Malware Analysis

Hybrid Analysis is a powerful malware analysis platform that provides dynamic and static analysis of suspicious files and URLs with comprehensive threat intelligence.

Social Media Intelligence

Maigret is a free, open-source username search tool that checks over 3,000 platforms for username presence and digital footprint analysis.

Network Security

Suricata is a high-performance, open-source network IDS, IPS, and network security monitoring engine that inspects traffic in real time using multi-threaded, signature-based, and protocol-aware analysis.

Threat Intelligence

Hudson Rock provides free cybercrime intelligence tools for checking email, username, and domain exposure to infostealer malware.

Threat Intelligence

Flare is an identity-first cyber threat intelligence platform recognized as Most Innovative CTI Platform and included in the Gartner Magic Quadrant for Cyber Threat Intelligence.

Security Operations

Wazuh is the leading open-source SIEM and XDR platform that unifies threat prevention, detection, and response across endpoints, cloud, and container environments.

Identity Security

BloodHound is an open-source Active Directory and Azure AD attack path analysis tool that uses graph theory to reveal hidden privilege escalation paths and lateral movement routes in identity infrastructure.

Data Analysis

CyberChef is the Cyber Swiss Army Knife - a powerful web-based tool for data transformation, encoding, encryption, and analysis developed by GCHQ.