Security Toolkit

September 28, 2026

28 tools this month across identity, offense, defense, OSINT, privacy, AppSec, cloud, and the guardrails going around AI agents, split roughly evenly between long-standing defaults and things that shipped or changed in the last few weeks.

🔑 Identity & Access

Zitadel

Self-host Zitadel with Docker Compose or a Helm chart, or use the free cloud tier capped at 100 daily active users. One Go binary handles SSO, OIDC, SAML, WebAuthn passkeys, MFA, and SCIM provisioning, with multi-tenancy designed in from day one instead of retrofitted later. The core is AGPL-3.0; scaling self-hosted usage past the community tier needs a commercial license. Pricing: free, open source (AGPL-3.0); cloud free tier to 100 DAU, Pro from $100/month, enterprise self-host under a commercial license.

SpiceDB

SpiceDB implements the relationship-based authorization model Google described in its Zanzibar paper: define a schema and a set of relationship tuples, then ask Check, Expand, or ListObjects over gRPC or HTTP to get a permission decision. It's what Authzed built its own hosted product on top of, useful once role-based access control stops scaling to the permission graph you actually have. docker run authzed/spicedb serve gets a local instance running. Pricing: free, open source (Apache-2.0).

Infisical

Infisical started as a secrets manager and has grown a privileged-access-management layer on top: policy-gated access to infrastructure plus its own certificate authority for issuing short-lived certs, with near-daily patch releases through September 2026. docker compose -f docker-compose.prod.yml up self-hosts the whole stack, or sign up for the free cloud tier. Pricing: free, open source core (MIT); PAM and compliance features live in a separately licensed enterprise module.

⚔️ Offensive & Recon

Every tool below is for systems you own or are contracted to test.

Mythic

Payload agents and network transports live in separate repos from Mythic's core, pulled in through mythic-cli rather than bundled together, which is what's let this collaborative red-team C2 framework keep absorbing new agent types since 2018 without the core ever needing a rewrite. Stand up the server with sudo make && sudo ./mythic-cli start. Pricing: free, open source (BSD-3-Clause).

Impacket

Most Active Directory assessment tooling is quietly built on Impacket: a Python library implementing SMB, MSRPC, Kerberos, LDAP, and MSSQL/TDS at a low level, shipped with example scripts like secretsdump.py and psexec.py for authorized post-exploitation work. pip install impacket gets the library and scripts; development stayed active through September 2026 even though the last tagged release is older. Pricing: free (modified Apache Software License; SMBv1/NetBIOS components carry pysmb's original license terms).

subfinder

Unlike active scanners, subfinder only queries external OSINT sources for a domain's subdomains, which keeps it the enumeration step teams chain into httpx and naabu for the rest of a recon pipeline against infrastructure they're authorized to map. go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest; full coverage needs optional API keys for some sources. Pricing: free, open source (MIT).

Chisel

Version 1.12.0, shipped August 29, 2026, hardened Chisel's auth-string and fingerprint validation and added graceful shutdown on SIGTERM after three release candidates. The tool itself tunnels TCP and UDP over HTTP secured by SSH in a single static binary, the standard way to pivot into a segmented network without setting up a full SOCKS proxy chain. Grab a prebuilt binary from the releases page; upgraders from 1.11.x need to check the SOCKS5 auth and fingerprint format changes. Pricing: free, open source (MIT).

🛡️ Defensive & Detection

Zeek

Instead of firing alerts directly, Zeek turns raw network traffic into structured, scriptable logs, connections, DNS, HTTP, TLS handshakes, that most SIEMs end up ingesting from underneath. Build it from source with the standard ./configure && make && sudo make install, or grab a packaged build from zeek.org. Pricing: free, open source (BSD-3-Clause-style license).

osquery

Commercial EDR dashboards often sit on top of osquery's data layer: it exposes processes, open sockets, logged-in users, and installed packages as SQL tables queryable across an entire fleet at once. Install a package for your OS from osquery.io/downloads, or brew install osquery on macOS. Pricing: free, open source (dual Apache-2.0/GPL-2.0, your choice).

GRR Rapid Response

Google built GRR for its own incident response and still runs it internally: a lightweight client agent deployed across a fleet, controlled from a central server for pulling artifacts and running YARA scans at scale instead of walking to each machine by hand. Deploy the server through the docker-compose setup documented at grr-doc.readthedocs.io. Pricing: free, open source (Apache-2.0).

Zircolite

September 26, 2026's v4.1.0 release added Sigma correlation-rule support to Zircolite, so multi-event detections that used to need a real SIEM behind them now run standalone against a log file. Point it at EVTX, Sysmon-for-Linux, or Auditd output with python3 zircolite.py --evtx sysmon.evtx --ruleset rules/rules_windows_merged.json, or use the no-Python-required binary release. Pricing: free (code under LGPL-3.0; bundled rule sets carry their own licenses, including the Detection Rule License for SigmaHQ content).

🕵️ OSINT & Investigation

theHarvester

theHarvester is usually the first tool cited on every OSINT checklist, and for good reason: it pulls emails, subdomains, employee names, and open ports for a domain straight from public search engines without ever touching the target directly. pip install theHarvester, then run it against infrastructure you're scoped to look at. Pricing: free, open source (GPL-2.0).

Photon

Point Photon at a site and it crawls the whole thing, pulling out URLs, emails, social handles, files, subdomains, and JS endpoints as it goes, then exports the result to JSON or CSV instead of leaving you to scrape terminal output. pip install photon-py, then python3 photon.py -u <url>. Pricing: free, open source (GPL-3.0).

Maigret

Roughly 5,900 sites get checked against a single username when you run Maigret, which builds a dossier of matching accounts with recursive searching and exports to HTML, PDF, JSON, or CSV. Its September 18, 2026 release (v0.6.6) added optional AI-assisted analysis on top of the existing search, going well past the username tools most OSINT lists lead with. pip install maigret then maigret <username>, or run it as a web UI via Docker. Pricing: free, open source (MIT).

🔒 Privacy & Encryption

KeePassXC

No cloud account required: KeePassXC keeps your passwords in a local AES-256 or ChaCha20 encrypted database file, with browser integration and a keepassxc-cli for scripting. Install it from your package manager or grab the AppImage. Pricing: free, open source (GPL-2/GPL-3, multi-licensed with some MIT/BSD/LGPL components).

Cryptomator

Cryptomator encrypts individual files and filenames before they ever reach Dropbox, Google Drive, or whatever cloud storage you're already using, mounting the encrypted vault as a virtual drive so nothing else in your workflow has to change. Install the desktop client from cryptomator.org or brew install --cask cryptomator; mobile apps are priced separately on their app stores. Pricing: free, open source desktop client (GPLv3); commercial license available for ISVs and resellers, mobile apps paid.

OnionShare

Host a file, a static site, or a chat room as a temporary Tor onion service straight from your own laptop, no third-party server involved anywhere in the chain, and that's the entirety of what OnionShare does. pip install onionshare-cli, or grab the Flatpak, Snap, or platform installer from onionshare.org. Pricing: free, open source (GPLv3).

Presidio

Microsoft spun Presidio out into an independent, community-governed organization called Data Privacy Stack in mid-2026, moving it off a single vendor's roadmap without changing what it does: detect and redact PII across text, images, and structured data using a mix of regex and NER, with pluggable operators to replace, hash, or encrypt whatever it finds. pip install presidio-analyzer presidio-anonymizer gets both halves running. Pricing: free, open source (MIT).

🧩 AppSec & Supply Chain

Syft & Grype

Syft generates an SBOM (SPDX or CycloneDX) from a container image or filesystem, and its companion scanner, Grype, reads that SBOM, or scans directly, to flag known CVEs in OS and language packages, the pairing most teams default to before evaluating anything paid. Install either with curl -sSfL https://get.anchore.io/syft | sudo sh (swap in Grype's install URL for the scanner), or grab them via Homebrew or as container images. Pricing: free, open source (Apache-2.0).

OWASP Dependency-Track

Instead of a pile of SBOM reports to reconcile by hand, Dependency-Track ingests CycloneDX SBOMs continuously and cross-references every component against NVD, OSS Index, and GitHub Advisories in one dashboard. Deploy the API server and frontend containers with Docker Compose. Pricing: free, open source (Apache-2.0).

SonarQube Community Edition

SonarQube Community Edition scans more than 30 languages for bugs, code smells, and security hotspots, decorating pull requests and gating merges through a quality gate instead of producing a report nobody reads. docker run sonarqube:community gets a server running; scan a project with sonar-scanner. Paid Developer, Enterprise, and Data Center editions add more languages and rules under a separate commercial license. Pricing: free, open source (LGPL-3.0) for Community Edition; paid editions under a commercial license.

zizmor

zizmor moved out of an individual maintainer's GitHub namespace into its own zizmorcore organization this year, a sign of how far it's grown into the default scanner for GitHub Actions workflows. It's a static analyzer purpose-built for CI/CD configs, catching template-injection RCE, credential leakage, and overly broad permissions: blocks before a workflow ships. pipx install zizmor, cargo install zizmor, or brew install zizmor, then zizmor . against a repo. Pricing: free, open source (MIT).

☁️ Cloud & Infra Security

Steampipe

Steampipe turns a CSPM check into a SQL select statement: cloud and SaaS state across roughly 140 plugins (AWS, Azure, GCP, Kubernetes, GitHub, and more) gets exposed through a Postgres-compatible interface, no ETL pipeline required. brew install turbot/tap/steampipe on macOS, or the install script on Linux. Worth flagging before you deploy it at work: it's AGPL-3.0, a copyleft license most CSPM CLIs in this space don't carry. Pricing: free, open source (AGPL-3.0).

KICS

Checkmarx maintains KICS as a static scanner for Terraform, CloudFormation, Kubernetes manifests, Docker, Ansible, and Helm, catching misconfigurations before any of it gets applied. Installation is documented at docs.kics.io rather than the README; the short version is a prebuilt binary or Docker image and a kics scan against your IaC directory. Pricing: free, open source (Apache-2.0).

StackRox

StackRox's v5.0.0 release candidate, out September 28, 2026, retires the legacy StackRox Scanner in favor of Scanner V4, turns on VM scanning by default for OpenShift Virtualization, and adds cosign signature verification, a real architectural shift rather than a point release. The stable line underneath is Red Hat's Kubernetes-native CNAPP, watching build, deploy, and runtime risk for containerized workloads. Install via Helm: helm install stackrox-central-services stackrox/stackrox-central-services -n stackrox --create-namespace. Pricing: free, open source (Apache-2.0).

🤖 Security AI & Agents

Guardrails AI

Guardrails AI wraps an LLM call with input and output validators, PII detection, jailbreak and prompt-injection checks, schema enforcement, hallucination checks, pulled from a hub of reusable guards instead of hand-rolled regex. pip install guardrails-ai gets the framework running; guards install separately from the hub as you need them. Pricing: free, open source (Apache-2.0).

Meta PurpleLlama

PurpleLlama bundles Meta's LLM security tooling under one repo: Llama Guard classifies prompts and responses for unsafe content, Prompt Guard flags injection and jailbreak attempts, Code Shield filters insecure code an LLM tries to output, and the CyberSecEval benchmarks red-team a model across multiple risk categories. The evaluation code and Code Shield are MIT; the Llama Guard and Prompt Guard model weights ship under the more restrictive Llama Community License. Pricing: free; evals and Code Shield under MIT, model weights under the Llama Community License with its own usage terms.

Giskard

Giskard's v2 line scanned tabular ML models; v3.0.0, out August 26, 2026, ripped that out for a ground-up rewrite aimed at multi-turn testing of AI agents instead. The new giskard-scan command red-teams a model or agent for prompt injection, jailbreaks, and harmful output, plus deeper RAG evaluation. pip install giskard with the [scan] extra for the vulnerability scanner; needs Python 3.12 or newer. Pricing: free, open source (Apache-2.0).