Bookmarks

Security Toolkit — August 28, 2026

Identity & Access

Authentik
An open-source identity provider covering OAuth2/OIDC, SAML, LDAP, and RADIUS, with SCIM provisioning and MFA enforced through configurable auth-flow policies rather than a fixed login screen. Its "outposts" feature drops a reverse proxy in front of legacy apps that can't speak OIDC natively, so they get SSO without a rewrite. Release 2026.8.0 (August 18, 2026) followed the project earning official OpenID certification. Run it with `docker compose up` or a Helm chart. **Pricing:** free, open source (MIT core); a separate Enterprise license covers advanced features, and CC BY-SA 4.0 covers the docs.
OpenFGA
A relationship-based authorization engine implementing Google's Zanzibar model: define an authorization model plus relationship tuples, then query Check, Expand, or ListObjects over HTTP or gRPC to get a permission decision. It's the open engine behind Auth0 FGA and now a CNCF incubating project in its own right, useful when role-based access control stops scaling. `docker run openfga/openfga run` or `brew install openfga` gets a local instance running. v1.19.0 shipped August 25, 2026. **Pricing:** free, open source (Apache-2.0).
Hanko
A passkey-first authentication server with embeddable web components for the login UI, handling WebAuthn registration, MFA, social login, and SAML SSO without a password field in sight. v3, subtitled "Multitenancy," shipped July 27, 2026 and rebuilt the backend to serve multiple tenants natively, a shift from the single-tenant design of v2. Try the Docker Compose quickstart, or pull in `hanko-elements` with `npm install`. **Pricing:** free, open source (MIT for the frontend SDKs, AGPL-3.0 for the backend); a commercial license is available for organizations that need to avoid AGPL's copyleft terms.

Offensive & Recon

Nuclei
A template-driven vulnerability scanner from ProjectDiscovery: point it at a target and it runs thousands of community-maintained YAML templates checking for CVEs, exposed admin panels, misconfigurations, and issues across web apps, APIs, DNS, and cloud configs. The template format is what makes it stick — writing a new check doesn't require touching Go code. `go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest`, or grab the Docker image. v3.11.1 shipped August 8, 2026. **Pricing:** free, open source (MIT); ProjectDiscovery also sells a hosted cloud tier for teams that want scheduled scanning without managing infrastructure.
Apache Caldera
An ATT&CK-mapped adversary emulation platform: deploy agents to endpoints, then run automated "abilities" that chain together real-world attacker techniques so blue teams get something realistic to detect against. MITRE built it over the past decade, then donated it to the Apache Software Foundation Incubator on May 20, 2026, moving governance from `mitre/caldera` to `apache/caldera` under vendor-neutral oversight. `git clone --recursive`, `pip install -r requirements.txt`, `python3 server.py --insecure --build`. **Pricing:** free, open source (Apache-2.0).
Ligolo-ng
A tunneling and pivoting tool that builds a userland network stack over a reverse TCP or TLS connection, letting a tester route traffic into a segmented network without setting up a SOCKS proxy chain. Download prebuilt binaries from the GitHub releases page, then run the `proxy` relay on your attack box and the `agent` implant on the pivot host. v0.9.1 (August 11, 2026) added a multiplayer web interface for teams running an engagement together. **Pricing:** free, open source (GPL-3.0).

Defensive & Detection

Suricata
A network intrusion detection and prevention engine that inspects traffic against Snort-compatible rules, extracts files in transit, and logs structured protocol data to `eve.json` for downstream analysis. It's the reference open-source NIDS most SOCs already run somewhere in their stack. Install via your distro's package manager, then pull current rules with `suricata-update`. Release `suricata-8.0.6` shipped July 7, 2026. **Pricing:** free, open source (GPL-2.0); nonprofit maintainer OISF and third parties sell training and premium rule feeds separately.
YARA-X
A ground-up Rust rewrite of the classic YARA pattern-matching engine used to fingerprint malware families from file content. VirusTotal built it for memory safety and speed, and now runs it in production scanning billions of files a day — existing YARA rule syntax carries over, so it's a drop-in upgrade path rather than a new language to learn. Install via `cargo install`, a prebuilt CLI binary, or Python/Go/WASM bindings. v1.20.0 shipped August 24, 2026. **Pricing:** free, open source (BSD-3-Clause).
CrowdSec
Analyzes logs and HTTP requests locally to spot attack patterns, then shares and consumes anonymized threat intelligence across its user base so a scan pattern seen on one server can get blocked on thousands of others within hours. Enforcement happens through pluggable "bouncers" for nginx, iptables, and other chokepoints, plus an optional WAF layer. `curl -s https://install.crowdsec.net | sudo sh`, or run it via Docker or Kubernetes. v1.7.8 shipped May 11, 2026. **Pricing:** free, open source engine (MIT); paid Console and premium blocklist tiers sit on top for teams that want the hosted dashboard.
DFIR-IRIS
A web-based case management platform for incident response teams: track IOCs, build timelines, log evidence, and assign tasks from a shared workspace instead of a spreadsheet passed around over email. It's become the go-to free option since TheHive, long the default here, moved to a commercial-only model and pulled its public repos. `git clone`, check out a tagged release, copy the env template, and `docker compose up` brings up the app, database, queue, and worker together. v2.4.29 shipped August 10, 2026. **Pricing:** free, open source (LGPL-3.0).

OSINT & Investigation

SpiderFoot
An automated OSINT reconnaissance framework with over 200 modules that enumerate subdomains, email addresses, phone numbers, social accounts, breach exposure, open ports, and exposed cloud storage buckets, then correlate everything into a single scan report through a local web UI. It's the tool most OSINT toolkits list first for a reason: point it at a target and walk away. Run it via the Docker image or from source with `pip`. v4.0 is the current stable line. **Pricing:** free, open source (MIT); a hosted "HX" cloud edition exists separately.
IntelOwl
A self-hosted threat-intelligence aggregation platform: submit a file, IP, domain, URL, or hash once and it fans the query out to dozens of analyzers — VirusTotal, Shodan, YARA, ClamAV, mobile malware analysis, PCAP inspection — then returns the enriched, correlated results through one API call instead of a dozen separate lookups. Deploy it with the bundled `initialize.sh` script and Docker Compose stack. **Pricing:** free, open source (AGPL-3.0).
XposedOrNot
A breach-data search engine covering more than 11.5 billion exposed records: check whether an email shows up in a known breach, whether a password has leaked, or set up domain-wide monitoring with alerts if anything tied to your organization surfaces later. It recently opened up a phishing-domain scanner to its free tier, watching for newly registered lookalike domains aimed at a brand. No signup is needed for the basic email and password checks, and the project is open source on GitHub for teams that want to self-host it. **Pricing:** free — the maintainers state plainly that every tool on the site, including domain monitoring and the CXO dashboard, has no paid tier.

Privacy & Encryption

VeraCrypt
On-the-fly disk, container, and hidden-volume encryption, built as the maintained successor to TrueCrypt after that project shut down. v1.26.29 (June 11, 2026) added Argon2id key derivation and patched two security issues, including one affecting hidden-volume deniability — worth updating for if you're running an older build. Grab an installer for Windows, macOS, or Linux from the project site, or build from source. **Pricing:** free (dual-licensed under Apache 2.0 and the TrueCrypt License 3.0, which restricts naming derivative works "VeraCrypt" or "TrueCrypt").
Briar
A peer-to-peer encrypted messenger with no central server: messages sync directly device-to-device over Tor when you're online, or over Bluetooth and Wi-Fi when you're not, which is the point for activists and journalists who need something that still works when the network doesn't cooperate. Install from F-Droid, Google Play, or a direct APK. v1.5.19 shipped July 13, 2026. **Pricing:** free, open source (GPL-3.0-or-later for the Android client, AGPL for the desktop build).
Betterleaks
A secrets scanner for git history, filesystems, GitHub and GitLab orgs, and cloud storage, built by Gitleaks' original author after losing control of the Gitleaks project and name. Instead of leaning on entropy heuristics, it scores matches using CEL-based contextual rules and BPE tokenization, which the maintainers report catches far more real secrets with fewer false positives — and its config is a drop-in replacement for existing Gitleaks setups. `brew install betterleaks`, `docker pull ghcr.io/betterleaks/betterleaks`, or `go install github.com/betterleaks/betterleaks@latest`. **Pricing:** free, open source (MIT).

AppSec & Supply Chain

OWASP ZAP
A dynamic application security testing tool combining an intercepting proxy, a spider, and an active scanner, useful both for automated CI scans and as a manual pentesting proxy when you need to poke at requests by hand. It's one of OWASP's flagship projects and still among the most-used DAST tools around, with weekly development builds even though the last tagged stable release predates them. Download the desktop app, run the Docker image, or drive it headless in daemon mode. **Pricing:** free, open source (Apache-2.0).
GUAC
Ingests SBOMs (CycloneDX, SPDX), SLSA and in-toto attestations, OSV vulnerability data, and OpenSSF Scorecard results into a queryable graph, so instead of grepping through a pile of SBOM files you can ask "what depends on this library" or "where did this artifact come from" directly. v1.1.0 shipped March 13, 2026, building on the project's 1.0 milestone from mid-2025; it's incubating at OpenSSF with backing from Google, Kusari, Purdue, and Citi. The Docker Compose quickstart brings up the full local stack. **Pricing:** free, open source (Apache-2.0).
GuardDog
Scans PyPI, npm, Go modules, Rust crates, RubyGems, GitHub Actions, and VS Code extensions for malicious and typosquatted packages by correlating static-analysis signals — network access, obfuscation, install-time scripts — with threat indicators in the same file, rather than just flagging names that look similar to popular packages. That correlation step is what catches attacks a pure typosquat list misses. `uvx guarddog pypi scan requests`, `pip install guarddog`, or the Docker image. Currently on the v3 line. **Pricing:** free, open source (Apache-2.0).

Cloud & Infra Security

Checkov
Static analysis for infrastructure as code across Terraform, CloudFormation, Kubernetes manifests, Helm, Bicep, ARM templates, and Dockerfiles, backed by over 1,000 built-in policies plus graph-based checks that catch misconfigurations spanning multiple resources. It also scans container images and OSS dependencies, so one tool covers both the IaC and the artifact it builds. `pip3 install checkov` or `brew install checkov`. v3.3.15 shipped August 27, 2026. **Pricing:** free, open source (Apache-2.0).
Tetragon
eBPF-based security observability that can enforce, not just alert: using kernel LSM hooks, it can synchronously block or kill a process the moment it does something it shouldn't, while tracking exec events, syscalls, network activity, and file access tagged with Kubernetes identity. That in-kernel blocking step is what separates it from detection-only runtime tools. Install via Helm chart or the `tetra` CLI. v1.7.1 shipped August 25, 2026. **Pricing:** free, open source (Apache-2.0, with some BPF components under BSD-2-Clause and GPL-2.0), a CNCF project originally from Isovalent.
Kyverno
A Kubernetes-native policy engine that validates, mutates, and generates cluster resources through admission control and background scans, using ordinary Kubernetes YAML instead of a separate policy language — a lower barrier to entry than Rego-based alternatives for teams already fluent in K8s manifests. It also verifies container image signatures at admission time. Install with the Helm chart in the repo's `/charts` directory. v1.19.0 shipped August 20, 2026. **Pricing:** free, open source (Apache-2.0), a CNCF incubating project.

Security AI & Agents

Microsoft PyRIT
An open automation framework for red-teaming generative AI systems: run standardized scenarios covering content harms, data leakage, and jailbreaks against OpenAI, Azure, Anthropic, Google, or custom HTTP endpoints, composing datasets and attack strategies for repeatable assessments across hundreds of objectives at once. `pyrit_scan` runs it from the command line, or `pyrit_shell` for an interactive session. Microsoft's AI Red Team has maintained it since 2024. **Pricing:** free, open source (MIT).
Promptfoo
A CLI for evaluating and red-teaming LLM applications: it generates adversarial test cases — jailbreaks, prompt injection, PII-leakage probes — against a target model or app and produces a vulnerability dashboard scored against frameworks like the OWASP LLM Top 10. OpenAI acquired the project on March 9, 2026, and the maintainers have committed in the README that it stays open source and MIT-licensed regardless. `npm install -g promptfoo` or `npx promptfoo@latest`. **Pricing:** free, open source core (MIT); a separate paid enterprise tier exists for teams that want managed hosting.
DeepTeam
Wraps your LLM or agent in a callback, then runs it through more than 50 vulnerability types and 20 adversarial attack methods — multi-turn jailbreaks, prompt injection, bias probes, SQL injection attempts through the model — mapped to OWASP LLM Top 10 and NIST categories, scoring each as pass or fail. `pip install -U deepteam` gets the framework running against a target you define in a few lines of Python. **Pricing:** free, open source (Apache-2.0).

Labs & Learning

OWASP Juice Shop
A deliberately vulnerable web storefront with over 100 hacking challenges spanning the OWASP Top 10 — injection, broken auth, XSS — scored through an in-app leaderboard as you find each one. v20.0.0 (May 12, 2026) added prompt-injection and chatbot-manipulation challenges alongside the classic web bugs, and v20.2.0 (August 10, 2026) is current. `docker run -p 3000:3000 bkimminich/juice-shop` and you're solving challenges in under a minute. **Pricing:** free, open source (MIT).
CloudGoat
Deploys intentionally vulnerable AWS environments as scored scenarios — IAM privilege escalation, Lambda and ECS takeover, S3 breach chains — across 25 scenarios from easy to hard, torn down with the same tool once you're done. The scenario list now includes `agentcore_identity_confusion` and `bedrock_agent_hijacking`, which walk through hijacking a Bedrock agent's tool access rather than a traditional IAM path. `pipx install cloudgoat`, then `cloudgoat create <scenario-name>`. **Pricing:** free, open source (BSD-3-Clause); you pay only your own AWS bill while a scenario is running.
Damn Vulnerable AI Agent
Bills itself as the DVWA of AI agents: 21 intentionally broken agents across the OpenAI API, MCP, and A2A protocols, spanning 12 vulnerability categories like prompt injection, data exfiltration, and supply-chain attacks through tool poisoning. A built-in 22-challenge CTF board with a live scoreboard tracks progress, and it doubles as a place to see what agent identity controls actually stop. `docker run -p 9000:9000 -p 7001-7021:7001-7021 opena2a/dvaa:0.9.2`, then open `localhost:9000`. **Pricing:** free, open source (Apache-2.0). --- *28 tools this month. Offensive tooling is listed for systems you own or are authorized to test. Found a dead link or have something to add? Reply to the email.*