Bookmarks
Security Toolkit — September 28, 2026
Identity & Access
- Zitadel
- Self-host Zitadel with Docker Compose or a Helm chart, or use the free cloud tier capped at 100 daily active users. One Go binary handles SSO, OIDC, SAML, WebAuthn passkeys, MFA, and SCIM provisioning, with multi-tenancy designed in from day one instead of retrofitted later. The core is AGPL-3.0; scaling self-hosted usage past the community tier needs a commercial license. **Pricing:** free, open source (AGPL-3.0); cloud free tier to 100 DAU, Pro from $100/month, enterprise self-host under a commercial license.
- SpiceDB
- SpiceDB implements the relationship-based authorization model Google described in its Zanzibar paper: define a schema and a set of relationship tuples, then ask Check, Expand, or ListObjects over gRPC or HTTP to get a permission decision. It's what Authzed built its own hosted product on top of, useful once role-based access control stops scaling to the permission graph you actually have. `docker run authzed/spicedb serve` gets a local instance running. **Pricing:** free, open source (Apache-2.0).
- Infisical
- Infisical started as a secrets manager and has grown a privileged-access-management layer on top: policy-gated access to infrastructure plus its own certificate authority for issuing short-lived certs, with near-daily patch releases through September 2026. `docker compose -f docker-compose.prod.yml up` self-hosts the whole stack, or sign up for the free cloud tier. **Pricing:** free, open source core (MIT); PAM and compliance features live in a separately licensed enterprise module.
Offensive & Recon
- Mythic
- Payload agents and network transports live in separate repos from Mythic's core, pulled in through `mythic-cli` rather than bundled together, which is what's let this collaborative red-team C2 framework keep absorbing new agent types since 2018 without the core ever needing a rewrite. Stand up the server with `sudo make && sudo ./mythic-cli start`. **Pricing:** free, open source (BSD-3-Clause).
- Impacket
- Most Active Directory assessment tooling is quietly built on Impacket: a Python library implementing SMB, MSRPC, Kerberos, LDAP, and MSSQL/TDS at a low level, shipped with example scripts like secretsdump.py and psexec.py for authorized post-exploitation work. `pip install impacket` gets the library and scripts; development stayed active through September 2026 even though the last tagged release is older. **Pricing:** free (modified Apache Software License; SMBv1/NetBIOS components carry pysmb's original license terms).
- subfinder
- Unlike active scanners, subfinder only queries external OSINT sources for a domain's subdomains, which keeps it the enumeration step teams chain into httpx and naabu for the rest of a recon pipeline against infrastructure they're authorized to map. `go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest`; full coverage needs optional API keys for some sources. **Pricing:** free, open source (MIT).
- Chisel
- Version 1.12.0, shipped August 29, 2026, hardened Chisel's auth-string and fingerprint validation and added graceful shutdown on SIGTERM after three release candidates. The tool itself tunnels TCP and UDP over HTTP secured by SSH in a single static binary, the standard way to pivot into a segmented network without setting up a full SOCKS proxy chain. Grab a prebuilt binary from the releases page; upgraders from 1.11.x need to check the SOCKS5 auth and fingerprint format changes. **Pricing:** free, open source (MIT).
Defensive & Detection
- Zeek
- Instead of firing alerts directly, Zeek turns raw network traffic into structured, scriptable logs, connections, DNS, HTTP, TLS handshakes, that most SIEMs end up ingesting from underneath. Build it from source with the standard `./configure && make && sudo make install`, or grab a packaged build from zeek.org. **Pricing:** free, open source (BSD-3-Clause-style license).
- osquery
- Commercial EDR dashboards often sit on top of osquery's data layer: it exposes processes, open sockets, logged-in users, and installed packages as SQL tables queryable across an entire fleet at once. Install a package for your OS from osquery.io/downloads, or `brew install osquery` on macOS. **Pricing:** free, open source (dual Apache-2.0/GPL-2.0, your choice).
- GRR Rapid Response
- Google built GRR for its own incident response and still runs it internally: a lightweight client agent deployed across a fleet, controlled from a central server for pulling artifacts and running YARA scans at scale instead of walking to each machine by hand. Deploy the server through the docker-compose setup documented at grr-doc.readthedocs.io. **Pricing:** free, open source (Apache-2.0).
- Zircolite
- September 26, 2026's v4.1.0 release added Sigma correlation-rule support to Zircolite, so multi-event detections that used to need a real SIEM behind them now run standalone against a log file. Point it at EVTX, Sysmon-for-Linux, or Auditd output with `python3 zircolite.py --evtx sysmon.evtx --ruleset rules/rules_windows_merged.json`, or use the no-Python-required binary release. **Pricing:** free (code under LGPL-3.0; bundled rule sets carry their own licenses, including the Detection Rule License for SigmaHQ content).
OSINT & Investigation
- theHarvester
- theHarvester is usually the first tool cited on every OSINT checklist, and for good reason: it pulls emails, subdomains, employee names, and open ports for a domain straight from public search engines without ever touching the target directly. `pip install theHarvester`, then run it against infrastructure you're scoped to look at. **Pricing:** free, open source (GPL-2.0).
- Photon
- Point Photon at a site and it crawls the whole thing, pulling out URLs, emails, social handles, files, subdomains, and JS endpoints as it goes, then exports the result to JSON or CSV instead of leaving you to scrape terminal output. `pip install photon-py`, then `python3 photon.py -u <url>`. **Pricing:** free, open source (GPL-3.0).
- Maigret
- Roughly 5,900 sites get checked against a single username when you run Maigret, which builds a dossier of matching accounts with recursive searching and exports to HTML, PDF, JSON, or CSV. Its September 18, 2026 release (v0.6.6) added optional AI-assisted analysis on top of the existing search, going well past the username tools most OSINT lists lead with. `pip install maigret` then `maigret <username>`, or run it as a web UI via Docker. **Pricing:** free, open source (MIT).
Privacy & Encryption
- KeePassXC
- No cloud account required: KeePassXC keeps your passwords in a local AES-256 or ChaCha20 encrypted database file, with browser integration and a `keepassxc-cli` for scripting. Install it from your package manager or grab the AppImage. **Pricing:** free, open source (GPL-2/GPL-3, multi-licensed with some MIT/BSD/LGPL components).
- Cryptomator
- Cryptomator encrypts individual files and filenames before they ever reach Dropbox, Google Drive, or whatever cloud storage you're already using, mounting the encrypted vault as a virtual drive so nothing else in your workflow has to change. Install the desktop client from cryptomator.org or `brew install --cask cryptomator`; mobile apps are priced separately on their app stores. **Pricing:** free, open source desktop client (GPLv3); commercial license available for ISVs and resellers, mobile apps paid.
- OnionShare
- Host a file, a static site, or a chat room as a temporary Tor onion service straight from your own laptop, no third-party server involved anywhere in the chain, and that's the entirety of what OnionShare does. `pip install onionshare-cli`, or grab the Flatpak, Snap, or platform installer from onionshare.org. **Pricing:** free, open source (GPLv3).
- Presidio
- Microsoft spun Presidio out into an independent, community-governed organization called Data Privacy Stack in mid-2026, moving it off a single vendor's roadmap without changing what it does: detect and redact PII across text, images, and structured data using a mix of regex and NER, with pluggable operators to replace, hash, or encrypt whatever it finds. `pip install presidio-analyzer presidio-anonymizer` gets both halves running. **Pricing:** free, open source (MIT).
AppSec & Supply Chain
- Syft & Grype
- Syft generates an SBOM (SPDX or CycloneDX) from a container image or filesystem, and its companion scanner, [Grype](https://github.com/anchore/grype), reads that SBOM, or scans directly, to flag known CVEs in OS and language packages, the pairing most teams default to before evaluating anything paid. Install either with `curl -sSfL https://get.anchore.io/syft | sudo sh` (swap in Grype's install URL for the scanner), or grab them via Homebrew or as container images. **Pricing:** free, open source (Apache-2.0).
- OWASP Dependency-Track
- Instead of a pile of SBOM reports to reconcile by hand, Dependency-Track ingests CycloneDX SBOMs continuously and cross-references every component against NVD, OSS Index, and GitHub Advisories in one dashboard. Deploy the API server and frontend containers with Docker Compose. **Pricing:** free, open source (Apache-2.0).
- SonarQube Community Edition
- SonarQube Community Edition scans more than 30 languages for bugs, code smells, and security hotspots, decorating pull requests and gating merges through a quality gate instead of producing a report nobody reads. `docker run sonarqube:community` gets a server running; scan a project with `sonar-scanner`. Paid Developer, Enterprise, and Data Center editions add more languages and rules under a separate commercial license. **Pricing:** free, open source (LGPL-3.0) for Community Edition; paid editions under a commercial license.
- zizmor
- zizmor moved out of an individual maintainer's GitHub namespace into its own `zizmorcore` organization this year, a sign of how far it's grown into the default scanner for GitHub Actions workflows. It's a static analyzer purpose-built for CI/CD configs, catching template-injection RCE, credential leakage, and overly broad `permissions:` blocks before a workflow ships. `pipx install zizmor`, `cargo install zizmor`, or `brew install zizmor`, then `zizmor .` against a repo. **Pricing:** free, open source (MIT).
Cloud & Infra Security
- Steampipe
- Steampipe turns a CSPM check into a SQL `select` statement: cloud and SaaS state across roughly 140 plugins (AWS, Azure, GCP, Kubernetes, GitHub, and more) gets exposed through a Postgres-compatible interface, no ETL pipeline required. `brew install turbot/tap/steampipe` on macOS, or the install script on Linux. Worth flagging before you deploy it at work: it's AGPL-3.0, a copyleft license most CSPM CLIs in this space don't carry. **Pricing:** free, open source (AGPL-3.0).
- KICS
- Checkmarx maintains KICS as a static scanner for Terraform, CloudFormation, Kubernetes manifests, Docker, Ansible, and Helm, catching misconfigurations before any of it gets applied. Installation is documented at docs.kics.io rather than the README; the short version is a prebuilt binary or Docker image and a `kics scan` against your IaC directory. **Pricing:** free, open source (Apache-2.0).
- StackRox
- StackRox's v5.0.0 release candidate, out September 28, 2026, retires the legacy StackRox Scanner in favor of Scanner V4, turns on VM scanning by default for OpenShift Virtualization, and adds cosign signature verification, a real architectural shift rather than a point release. The stable line underneath is Red Hat's Kubernetes-native CNAPP, watching build, deploy, and runtime risk for containerized workloads. Install via Helm: `helm install stackrox-central-services stackrox/stackrox-central-services -n stackrox --create-namespace`. **Pricing:** free, open source (Apache-2.0).
Security AI & Agents
- Guardrails AI
- Guardrails AI wraps an LLM call with input and output validators, PII detection, jailbreak and prompt-injection checks, schema enforcement, hallucination checks, pulled from a hub of reusable guards instead of hand-rolled regex. `pip install guardrails-ai` gets the framework running; guards install separately from the hub as you need them. **Pricing:** free, open source (Apache-2.0).
- Meta PurpleLlama
- PurpleLlama bundles Meta's LLM security tooling under one repo: Llama Guard classifies prompts and responses for unsafe content, Prompt Guard flags injection and jailbreak attempts, Code Shield filters insecure code an LLM tries to output, and the CyberSecEval benchmarks red-team a model across multiple risk categories. The evaluation code and Code Shield are MIT; the Llama Guard and Prompt Guard model weights ship under the more restrictive Llama Community License. **Pricing:** free; evals and Code Shield under MIT, model weights under the Llama Community License with its own usage terms.
- Giskard
- Giskard's v2 line scanned tabular ML models; v3.0.0, out August 26, 2026, ripped that out for a ground-up rewrite aimed at multi-turn testing of AI agents instead. The new `giskard-scan` command red-teams a model or agent for prompt injection, jailbreaks, and harmful output, plus deeper RAG evaluation. `pip install giskard` with the `[scan]` extra for the vulnerability scanner; needs Python 3.12 or newer. **Pricing:** free, open source (Apache-2.0). --- *28 tools this month. Offensive tooling is listed for systems you own or are authorized to test. Found a dead link or have something to add? Reply to the email.*