Bookmarks

Security Toolkit — Full Archive

Identity & Access

Keycloak
Open source IdP handling OIDC, SAML, and preview SCIM provisioning, with WebAuthn and MFA policies configured through its admin console. Spin it up with `docker run quay.io/keycloak/keycloak` or a Helm chart — it's the default choice most teams reach for before evaluating anything commercial. Release 26.7.2 shipped August 19, 2026. **Pricing:** free, open source (Apache-2.0); Red Hat sells support separately.
OpenBao
When HashiCorp moved Vault to the Business Source License in 2023, this fork picked up the MPL-2.0 codebase and kept building. v2.6.2 landed August 18, 2026, and a February 2026 release added namespaces and HA read scaling that used to be Vault Enterprise-only. It handles secrets, certificates, and encryption keys, and now sits under Linux Foundation governance. Run it via `docker run openbao/openbao` or a Helm chart. **Pricing:** free, open source (MPL-2.0).
SimpleWebAuthn
A TypeScript library pair, `@simplewebauthn/server` and `/browser`, that implements passkey registration and authentication so you don't have to read the WebAuthn spec yourself. It's become the standard choice for Node and browser-based passkey flows; `npm install @simplewebauthn/server` gets you started. **Pricing:** free, open source (MIT).
Authentik
An open-source identity provider covering OAuth2/OIDC, SAML, LDAP, and RADIUS, with SCIM provisioning and MFA enforced through configurable auth-flow policies rather than a fixed login screen. Its "outposts" feature drops a reverse proxy in front of legacy apps that can't speak OIDC natively, so they get SSO without a rewrite. Release 2026.8.0 (August 18, 2026) followed the project earning official OpenID certification. Run it with `docker compose up` or a Helm chart. **Pricing:** free, open source (MIT core); a separate Enterprise license covers advanced features, and CC BY-SA 4.0 covers the docs.
OpenFGA
A relationship-based authorization engine implementing Google's Zanzibar model: define an authorization model plus relationship tuples, then query Check, Expand, or ListObjects over HTTP or gRPC to get a permission decision. It's the open engine behind Auth0 FGA and now a CNCF incubating project in its own right, useful when role-based access control stops scaling. `docker run openfga/openfga run` or `brew install openfga` gets a local instance running. v1.19.0 shipped August 25, 2026. **Pricing:** free, open source (Apache-2.0).
Hanko
A passkey-first authentication server with embeddable web components for the login UI, handling WebAuthn registration, MFA, social login, and SAML SSO without a password field in sight. v3, subtitled "Multitenancy," shipped July 27, 2026 and rebuilt the backend to serve multiple tenants natively, a shift from the single-tenant design of v2. Try the Docker Compose quickstart, or pull in `hanko-elements` with `npm install`. **Pricing:** free, open source (MIT for the frontend SDKs, AGPL-3.0 for the backend); a commercial license is available for organizations that need to avoid AGPL's copyleft terms.
Zitadel
Self-host Zitadel with Docker Compose or a Helm chart, or use the free cloud tier capped at 100 daily active users. One Go binary handles SSO, OIDC, SAML, WebAuthn passkeys, MFA, and SCIM provisioning, with multi-tenancy designed in from day one instead of retrofitted later. The core is AGPL-3.0; scaling self-hosted usage past the community tier needs a commercial license. **Pricing:** free, open source (AGPL-3.0); cloud free tier to 100 DAU, Pro from $100/month, enterprise self-host under a commercial license.
SpiceDB
SpiceDB implements the relationship-based authorization model Google described in its Zanzibar paper: define a schema and a set of relationship tuples, then ask Check, Expand, or ListObjects over gRPC or HTTP to get a permission decision. It's what Authzed built its own hosted product on top of, useful once role-based access control stops scaling to the permission graph you actually have. `docker run authzed/spicedb serve` gets a local instance running. **Pricing:** free, open source (Apache-2.0).
Infisical
Infisical started as a secrets manager and has grown a privileged-access-management layer on top: policy-gated access to infrastructure plus its own certificate authority for issuing short-lived certs, with near-daily patch releases through September 2026. `docker compose -f docker-compose.prod.yml up` self-hosts the whole stack, or sign up for the free cloud tier. **Pricing:** free, open source core (MIT); PAM and compliance features live in a separately licensed enterprise module.

Offensive & Recon

Metasploit Framework
Twenty-three years in, this is still the reference exploitation and post-exploitation framework: a module library, a console, and an RPC API for chaining payloads together. Install via `msfinstall` or apt, then run `msfconsole`. v6.5 added 422 modules over the past two years. **Pricing:** free, open source (3-clause BSD).
BloodHound Community Edition
Maps Active Directory and Azure attack paths as a graph, so you can see which low-privilege account sits three hops from Domain Admin instead of guessing. Feed it data with the SharpHound or AzureHound collectors, then explore relationships in the CE web UI, backed by Neo4j and Postgres. v9.6.0 shipped August 18, 2026. **Pricing:** free, open source (Apache-2.0); SpecterOps sells a separate commercial Enterprise SaaS.
Sliver
A Golang command-and-control framework built for red-team exercises, supporting mTLS, WireGuard, HTTP(S), and DNS transports for implant traffic. Run the server binary and generate implants through the CLI client. Bishop Fox keeps it actively maintained even though the last tagged release, v1.7.3, dates to February 2026. **Pricing:** free, open source (GPL-3.0).
NetExec
The CrackMapExec successor for enumerating and testing authentication across SMB, WinRM, RDP, LDAP, and MSSQL. `pipx install netexec` or pull the Docker image, then point `nxc` at your scoped protocol and hosts. Commit activity has stayed constant through August 2026. **Pricing:** free, open source (BSD-2-Clause).
Nuclei
A template-driven vulnerability scanner from ProjectDiscovery: point it at a target and it runs thousands of community-maintained YAML templates checking for CVEs, exposed admin panels, misconfigurations, and issues across web apps, APIs, DNS, and cloud configs. The template format is what makes it stick — writing a new check doesn't require touching Go code. `go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest`, or grab the Docker image. v3.11.1 shipped August 8, 2026. **Pricing:** free, open source (MIT); ProjectDiscovery also sells a hosted cloud tier for teams that want scheduled scanning without managing infrastructure.
Apache Caldera
An ATT&CK-mapped adversary emulation platform: deploy agents to endpoints, then run automated "abilities" that chain together real-world attacker techniques so blue teams get something realistic to detect against. MITRE built it over the past decade, then donated it to the Apache Software Foundation Incubator on May 20, 2026, moving governance from `mitre/caldera` to `apache/caldera` under vendor-neutral oversight. `git clone --recursive`, `pip install -r requirements.txt`, `python3 server.py --insecure --build`. **Pricing:** free, open source (Apache-2.0).
Ligolo-ng
A tunneling and pivoting tool that builds a userland network stack over a reverse TCP or TLS connection, letting a tester route traffic into a segmented network without setting up a SOCKS proxy chain. Download prebuilt binaries from the GitHub releases page, then run the `proxy` relay on your attack box and the `agent` implant on the pivot host. v0.9.1 (August 11, 2026) added a multiplayer web interface for teams running an engagement together. **Pricing:** free, open source (GPL-3.0).
Mythic
Payload agents and network transports live in separate repos from Mythic's core, pulled in through `mythic-cli` rather than bundled together, which is what's let this collaborative red-team C2 framework keep absorbing new agent types since 2018 without the core ever needing a rewrite. Stand up the server with `sudo make && sudo ./mythic-cli start`. **Pricing:** free, open source (BSD-3-Clause).
Impacket
Most Active Directory assessment tooling is quietly built on Impacket: a Python library implementing SMB, MSRPC, Kerberos, LDAP, and MSSQL/TDS at a low level, shipped with example scripts like secretsdump.py and psexec.py for authorized post-exploitation work. `pip install impacket` gets the library and scripts; development stayed active through September 2026 even though the last tagged release is older. **Pricing:** free (modified Apache Software License; SMBv1/NetBIOS components carry pysmb's original license terms).
subfinder
Unlike active scanners, subfinder only queries external OSINT sources for a domain's subdomains, which keeps it the enumeration step teams chain into httpx and naabu for the rest of a recon pipeline against infrastructure they're authorized to map. `go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest`; full coverage needs optional API keys for some sources. **Pricing:** free, open source (MIT).
Chisel
Version 1.12.0, shipped August 29, 2026, hardened Chisel's auth-string and fingerprint validation and added graceful shutdown on SIGTERM after three release candidates. The tool itself tunnels TCP and UDP over HTTP secured by SSH in a single static binary, the standard way to pivot into a segmented network without setting up a full SOCKS proxy chain. Grab a prebuilt binary from the releases page; upgraders from 1.11.x need to check the SOCKS5 auth and fingerprint format changes. **Pricing:** free, open source (MIT).

Defensive & Detection

Wazuh
A SIEM and XDR platform in one: log analysis, file integrity monitoring, vulnerability detection, and an endpoint agent, with nothing held back behind a paid tier. Start with the docker-compose quickstart or the official installer, then roll out agents via package or MSI. v4.14.7 shipped July 30, 2026. **Pricing:** free, open source (GPLv2); Wazuh Inc. sells optional cloud hosting and support.
Sigma (SigmaHQ)
The generic detection-rule format most SIEMs can consume one way or another. Write once, then convert with `pySigma` or `sigma-cli` into queries for Splunk, Elastic, Sentinel, or Wazuh. The July 9, 2026 release added coverage for CVE-2026-41089 alongside 20 new rules and 70 updates. **Pricing:** free; rules ship under the Detection Rule License 1.1, which requires attribution on reproduction rather than a standard MIT/Apache grant.
Velociraptor
Endpoint monitoring and DFIR built on its own query language, VQL, for fleet-wide artifact collection when you need to hunt across hundreds of machines at once. Deploy the server binary, then push the client via MSI, deb, or exe. v0.77.2 landed August 10, 2026 with a CVE fix. Rapid7 acquired the project in 2021 but kept it under AGPL. **Pricing:** free, open source (AGPL-3.0-or-later).
T-Pot
Bundles more than 20 honeypots, including LLM-based ones like Beelzebub and Galah, with an Elastic Stack front end so you're not standing up each sensor separately. The installer targets a dedicated Linux host, or you can run the Docker Compose stack. Deutsche Telekom Security's team was still committing fixes as of August 25, 2026, even though the last tagged release predates that. **Pricing:** free, open source (GPL-3.0).
Suricata
A network intrusion detection and prevention engine that inspects traffic against Snort-compatible rules, extracts files in transit, and logs structured protocol data to `eve.json` for downstream analysis. It's the reference open-source NIDS most SOCs already run somewhere in their stack. Install via your distro's package manager, then pull current rules with `suricata-update`. Release `suricata-8.0.6` shipped July 7, 2026. **Pricing:** free, open source (GPL-2.0); nonprofit maintainer OISF and third parties sell training and premium rule feeds separately.
YARA-X
A ground-up Rust rewrite of the classic YARA pattern-matching engine used to fingerprint malware families from file content. VirusTotal built it for memory safety and speed, and now runs it in production scanning billions of files a day — existing YARA rule syntax carries over, so it's a drop-in upgrade path rather than a new language to learn. Install via `cargo install`, a prebuilt CLI binary, or Python/Go/WASM bindings. v1.20.0 shipped August 24, 2026. **Pricing:** free, open source (BSD-3-Clause).
CrowdSec
Analyzes logs and HTTP requests locally to spot attack patterns, then shares and consumes anonymized threat intelligence across its user base so a scan pattern seen on one server can get blocked on thousands of others within hours. Enforcement happens through pluggable "bouncers" for nginx, iptables, and other chokepoints, plus an optional WAF layer. `curl -s https://install.crowdsec.net | sudo sh`, or run it via Docker or Kubernetes. v1.7.8 shipped May 11, 2026. **Pricing:** free, open source engine (MIT); paid Console and premium blocklist tiers sit on top for teams that want the hosted dashboard.
DFIR-IRIS
A web-based case management platform for incident response teams: track IOCs, build timelines, log evidence, and assign tasks from a shared workspace instead of a spreadsheet passed around over email. It's become the go-to free option since TheHive, long the default here, moved to a commercial-only model and pulled its public repos. `git clone`, check out a tagged release, copy the env template, and `docker compose up` brings up the app, database, queue, and worker together. v2.4.29 shipped August 10, 2026. **Pricing:** free, open source (LGPL-3.0).
Zeek
Instead of firing alerts directly, Zeek turns raw network traffic into structured, scriptable logs, connections, DNS, HTTP, TLS handshakes, that most SIEMs end up ingesting from underneath. Build it from source with the standard `./configure && make && sudo make install`, or grab a packaged build from zeek.org. **Pricing:** free, open source (BSD-3-Clause-style license).
osquery
Commercial EDR dashboards often sit on top of osquery's data layer: it exposes processes, open sockets, logged-in users, and installed packages as SQL tables queryable across an entire fleet at once. Install a package for your OS from osquery.io/downloads, or `brew install osquery` on macOS. **Pricing:** free, open source (dual Apache-2.0/GPL-2.0, your choice).
GRR Rapid Response
Google built GRR for its own incident response and still runs it internally: a lightweight client agent deployed across a fleet, controlled from a central server for pulling artifacts and running YARA scans at scale instead of walking to each machine by hand. Deploy the server through the docker-compose setup documented at grr-doc.readthedocs.io. **Pricing:** free, open source (Apache-2.0).
Zircolite
September 26, 2026's v4.1.0 release added Sigma correlation-rule support to Zircolite, so multi-event detections that used to need a real SIEM behind them now run standalone against a log file. Point it at EVTX, Sysmon-for-Linux, or Auditd output with `python3 zircolite.py --evtx sysmon.evtx --ruleset rules/rules_windows_merged.json`, or use the no-Python-required binary release. **Pricing:** free (code under LGPL-3.0; bundled rule sets carry their own licenses, including the Detection Rule License for SigmaHQ content).

OSINT & Investigation

Sherlock
Checks a username against 400-plus platforms to see where an account exists, useful for mapping exposure before an assessment. `pipx install sherlock-project` or run it via Docker, then `sherlock <username>`. It's the tool most OSINT lists lead with, and commit activity is current. **Pricing:** free, open source (MIT).
OWASP Amass
Passive and active reconnaissance for mapping an organization's external attack surface: subdomains, IP ranges, netblocks, ASNs. Grab the Go binary or Docker image and run `amass enum -d <domain>` against infrastructure you own. It's an OWASP flagship project; v5.1.1 shipped April 7, 2026. **Pricing:** free, open source (Apache-2.0); optional paid API integrations (WhoisXML, for example) improve result coverage.
ExifTool
Reads and strips EXIF, IPTC, XMP, and GPS metadata from thousands of file formats — the standard way to check what a photo or document is quietly carrying before you publish it, or to pull that data during an investigation. `exiftool -gps:all file.jpg` gets you the location fields in one line. Version 13.59 shipped May 27, 2026. **Pricing:** free (dual Artistic-1.0-Perl/GPL license).
SpiderFoot
An automated OSINT reconnaissance framework with over 200 modules that enumerate subdomains, email addresses, phone numbers, social accounts, breach exposure, open ports, and exposed cloud storage buckets, then correlate everything into a single scan report through a local web UI. It's the tool most OSINT toolkits list first for a reason: point it at a target and walk away. Run it via the Docker image or from source with `pip`. v4.0 is the current stable line. **Pricing:** free, open source (MIT); a hosted "HX" cloud edition exists separately.
IntelOwl
A self-hosted threat-intelligence aggregation platform: submit a file, IP, domain, URL, or hash once and it fans the query out to dozens of analyzers — VirusTotal, Shodan, YARA, ClamAV, mobile malware analysis, PCAP inspection — then returns the enriched, correlated results through one API call instead of a dozen separate lookups. Deploy it with the bundled `initialize.sh` script and Docker Compose stack. **Pricing:** free, open source (AGPL-3.0).
XposedOrNot
A breach-data search engine covering more than 11.5 billion exposed records: check whether an email shows up in a known breach, whether a password has leaked, or set up domain-wide monitoring with alerts if anything tied to your organization surfaces later. It recently opened up a phishing-domain scanner to its free tier, watching for newly registered lookalike domains aimed at a brand. No signup is needed for the basic email and password checks, and the project is open source on GitHub for teams that want to self-host it. **Pricing:** free — the maintainers state plainly that every tool on the site, including domain monitoring and the CXO dashboard, has no paid tier.
theHarvester
theHarvester is usually the first tool cited on every OSINT checklist, and for good reason: it pulls emails, subdomains, employee names, and open ports for a domain straight from public search engines without ever touching the target directly. `pip install theHarvester`, then run it against infrastructure you're scoped to look at. **Pricing:** free, open source (GPL-2.0).
Photon
Point Photon at a site and it crawls the whole thing, pulling out URLs, emails, social handles, files, subdomains, and JS endpoints as it goes, then exports the result to JSON or CSV instead of leaving you to scrape terminal output. `pip install photon-py`, then `python3 photon.py -u <url>`. **Pricing:** free, open source (GPL-3.0).
Maigret
Roughly 5,900 sites get checked against a single username when you run Maigret, which builds a dossier of matching accounts with recursive searching and exports to HTML, PDF, JSON, or CSV. Its September 18, 2026 release (v0.6.6) added optional AI-assisted analysis on top of the existing search, going well past the username tools most OSINT lists lead with. `pip install maigret` then `maigret <username>`, or run it as a web UI via Docker. **Pricing:** free, open source (MIT).

Privacy & Encryption

Tor Browser
Routes traffic through the Tor relay network to resist tracking and censorship — still the reference way to browse anonymously, and still actively shipped. Download the desktop build for Windows, macOS, or Linux, or the Android app, straight from the Tor Project. v15.0.20 shipped August 18, 2026. **Pricing:** free (Tor core is 3-clause BSD; the browser bundles Firefox under MPL-2.0).
age
A file-encryption tool and Go library with small, explicit keys and no config file to get wrong, increasingly the default replacement for `gpg -c` when you just need to encrypt a file to a recipient's public key. Install via your package manager or `go install filippo.io/age/cmd/...@latest`, then `age-keygen` and `age -r <pubkey>`. The 1.3 line added post-quantum support. **Pricing:** free, open source (BSD-3-Clause).
SimpleX Chat
An end-to-end encrypted messenger that skips persistent user identifiers entirely: no phone number, no account ID tying messages back to you across the network. Run the mobile apps or the terminal client, and self-host your own SMP relay if you'd rather not rely on the default servers. v7.1.0-beta.1 shipped August 20, 2026. **Pricing:** free, open source (AGPL-3.0).
VeraCrypt
On-the-fly disk, container, and hidden-volume encryption, built as the maintained successor to TrueCrypt after that project shut down. v1.26.29 (June 11, 2026) added Argon2id key derivation and patched two security issues, including one affecting hidden-volume deniability — worth updating for if you're running an older build. Grab an installer for Windows, macOS, or Linux from the project site, or build from source. **Pricing:** free (dual-licensed under Apache 2.0 and the TrueCrypt License 3.0, which restricts naming derivative works "VeraCrypt" or "TrueCrypt").
Briar
A peer-to-peer encrypted messenger with no central server: messages sync directly device-to-device over Tor when you're online, or over Bluetooth and Wi-Fi when you're not, which is the point for activists and journalists who need something that still works when the network doesn't cooperate. Install from F-Droid, Google Play, or a direct APK. v1.5.19 shipped July 13, 2026. **Pricing:** free, open source (GPL-3.0-or-later for the Android client, AGPL for the desktop build).
Betterleaks
A secrets scanner for git history, filesystems, GitHub and GitLab orgs, and cloud storage, built by Gitleaks' original author after losing control of the Gitleaks project and name. Instead of leaning on entropy heuristics, it scores matches using CEL-based contextual rules and BPE tokenization, which the maintainers report catches far more real secrets with fewer false positives — and its config is a drop-in replacement for existing Gitleaks setups. `brew install betterleaks`, `docker pull ghcr.io/betterleaks/betterleaks`, or `go install github.com/betterleaks/betterleaks@latest`. **Pricing:** free, open source (MIT).
KeePassXC
No cloud account required: KeePassXC keeps your passwords in a local AES-256 or ChaCha20 encrypted database file, with browser integration and a `keepassxc-cli` for scripting. Install it from your package manager or grab the AppImage. **Pricing:** free, open source (GPL-2/GPL-3, multi-licensed with some MIT/BSD/LGPL components).
Cryptomator
Cryptomator encrypts individual files and filenames before they ever reach Dropbox, Google Drive, or whatever cloud storage you're already using, mounting the encrypted vault as a virtual drive so nothing else in your workflow has to change. Install the desktop client from cryptomator.org or `brew install --cask cryptomator`; mobile apps are priced separately on their app stores. **Pricing:** free, open source desktop client (GPLv3); commercial license available for ISVs and resellers, mobile apps paid.
OnionShare
Host a file, a static site, or a chat room as a temporary Tor onion service straight from your own laptop, no third-party server involved anywhere in the chain, and that's the entirety of what OnionShare does. `pip install onionshare-cli`, or grab the Flatpak, Snap, or platform installer from onionshare.org. **Pricing:** free, open source (GPLv3).
Presidio
Microsoft spun Presidio out into an independent, community-governed organization called Data Privacy Stack in mid-2026, moving it off a single vendor's roadmap without changing what it does: detect and redact PII across text, images, and structured data using a mix of regex and NER, with pluggable operators to replace, hash, or encrypt whatever it finds. `pip install presidio-analyzer presidio-anonymizer` gets both halves running. **Pricing:** free, open source (MIT).

AppSec & Supply Chain

Semgrep
A semantic-grep SAST engine covering 30-plus languages with over 2,800 free community rules, fast enough to run on every commit instead of once a quarter. `pip install semgrep`, `brew install semgrep`, or pull the Docker image. The core engine ships under LGPL-2.1; cross-file dataflow, the Pro rule pack, and supply-chain scanning sit behind the paid AppSec Platform. **Pricing:** free open source engine; Platform free up to 10 contributors, then $30/contributor/month.
OSV-Scanner
Google's SCA scanner queries the OSV.dev vulnerability database across 20-plus ecosystems, and the v2 line rewrote the extraction pipeline on OSV-Scalibr, adding guided remediation and container-layer attribution. `go install github.com/google/osv-scanner/v2/cmd/osv-scanner@latest`, then `osv-scanner scan source -r .`. v2.5.0 shipped August 7, 2026. **Pricing:** free, open source (Apache-2.0), no paid tier.
Sigstore Cosign
Signs and verifies container images and other artifacts, keyless or key-based, and anchors them to the Rekor transparency log with in-toto/SLSA attestations. Most of the Sigstore ecosystem builds around it. Install via `brew install cosign` or the `sigstore/cosign-installer` GitHub Action. v3.1.3 shipped August 6, 2026, patching a verification-bypass CVE. **Pricing:** free, open source (Apache-2.0).
Socket CLI
Flags dependency confusion, typosquats, and malicious packages using behavioral analysis instead of matching against known CVEs, which catches supply-chain attacks before a CVE ever gets assigned. `npm install -g @socketsecurity/cli`, then `socket scan create`, or gate installs with `socket npm install`. The CLI is open source; the backing platform is proprietary. **Pricing:** free up to 1,000 scans/month; Team from $25/dev/month.
OWASP ZAP
A dynamic application security testing tool combining an intercepting proxy, a spider, and an active scanner, useful both for automated CI scans and as a manual pentesting proxy when you need to poke at requests by hand. It's one of OWASP's flagship projects and still among the most-used DAST tools around, with weekly development builds even though the last tagged stable release predates them. Download the desktop app, run the Docker image, or drive it headless in daemon mode. **Pricing:** free, open source (Apache-2.0).
GUAC
Ingests SBOMs (CycloneDX, SPDX), SLSA and in-toto attestations, OSV vulnerability data, and OpenSSF Scorecard results into a queryable graph, so instead of grepping through a pile of SBOM files you can ask "what depends on this library" or "where did this artifact come from" directly. v1.1.0 shipped March 13, 2026, building on the project's 1.0 milestone from mid-2025; it's incubating at OpenSSF with backing from Google, Kusari, Purdue, and Citi. The Docker Compose quickstart brings up the full local stack. **Pricing:** free, open source (Apache-2.0).
GuardDog
Scans PyPI, npm, Go modules, Rust crates, RubyGems, GitHub Actions, and VS Code extensions for malicious and typosquatted packages by correlating static-analysis signals — network access, obfuscation, install-time scripts — with threat indicators in the same file, rather than just flagging names that look similar to popular packages. That correlation step is what catches attacks a pure typosquat list misses. `uvx guarddog pypi scan requests`, `pip install guarddog`, or the Docker image. Currently on the v3 line. **Pricing:** free, open source (Apache-2.0).
Syft & Grype
Syft generates an SBOM (SPDX or CycloneDX) from a container image or filesystem, and its companion scanner, [Grype](https://github.com/anchore/grype), reads that SBOM, or scans directly, to flag known CVEs in OS and language packages, the pairing most teams default to before evaluating anything paid. Install either with `curl -sSfL https://get.anchore.io/syft | sudo sh` (swap in Grype's install URL for the scanner), or grab them via Homebrew or as container images. **Pricing:** free, open source (Apache-2.0).
OWASP Dependency-Track
Instead of a pile of SBOM reports to reconcile by hand, Dependency-Track ingests CycloneDX SBOMs continuously and cross-references every component against NVD, OSS Index, and GitHub Advisories in one dashboard. Deploy the API server and frontend containers with Docker Compose. **Pricing:** free, open source (Apache-2.0).
SonarQube Community Edition
SonarQube Community Edition scans more than 30 languages for bugs, code smells, and security hotspots, decorating pull requests and gating merges through a quality gate instead of producing a report nobody reads. `docker run sonarqube:community` gets a server running; scan a project with `sonar-scanner`. Paid Developer, Enterprise, and Data Center editions add more languages and rules under a separate commercial license. **Pricing:** free, open source (LGPL-3.0) for Community Edition; paid editions under a commercial license.
zizmor
zizmor moved out of an individual maintainer's GitHub namespace into its own `zizmorcore` organization this year, a sign of how far it's grown into the default scanner for GitHub Actions workflows. It's a static analyzer purpose-built for CI/CD configs, catching template-injection RCE, credential leakage, and overly broad `permissions:` blocks before a workflow ships. `pipx install zizmor`, `cargo install zizmor`, or `brew install zizmor`, then `zizmor .` against a repo. **Pricing:** free, open source (MIT).

Cloud & Infra Security

Prowler
Runs hundreds of checks against AWS, Azure, GCP, Kubernetes, and M365 for CIS, PCI-DSS, and SOC2 compliance — the CSPM CLI most teams reach for before paying for a hosted equivalent. `pip install prowler` or `docker run toniblyx/prowler`. v5.39.1 shipped August 18, 2026. **Pricing:** free, open source (Apache-2.0); Prowler Cloud is a separate paid hosted tier.
Kubescape
A CNCF-incubating platform scanning Kubernetes clusters and manifests for misconfiguration, vulnerabilities, RBAC issues, and runtime drift. Install with the one-line script, Homebrew, or `helm upgrade --install kubescape kubescape/kubescape-operator`. v4.0.12 shipped August 12, 2026, adding concurrent image-scan pipelines and runtime profile drift detection. **Pricing:** free, open source (Apache-2.0); maintainer ARMO sells a commercial management layer.
Trivy
One scanner for container images, IaC, SBOM generation, secrets, and misconfiguration, with enough overlap with the rest of this bucket that it's often the only scanner a small team runs. `brew install trivy` or `docker run aquasec/trivy`. v0.74.0 shipped August 14, 2026. Worth knowing: the project suffered a supply-chain compromise in March 2026 that's since been remediated. **Pricing:** free, open source (Apache-2.0); Aqua Security sells a commercial platform built on top.
Falco
CNCF-graduated runtime security using eBPF or a kernel module to catch abnormal syscalls, privilege escalation, and container escapes as they happen. Deploy as a Kubernetes DaemonSet via Helm, or try the Docker Compose demo first. **Pricing:** free, open source (Apache-2.0); Sysdig, the original creator, sells a commercial platform built on top.
Checkov
Static analysis for infrastructure as code across Terraform, CloudFormation, Kubernetes manifests, Helm, Bicep, ARM templates, and Dockerfiles, backed by over 1,000 built-in policies plus graph-based checks that catch misconfigurations spanning multiple resources. It also scans container images and OSS dependencies, so one tool covers both the IaC and the artifact it builds. `pip3 install checkov` or `brew install checkov`. v3.3.15 shipped August 27, 2026. **Pricing:** free, open source (Apache-2.0).
Tetragon
eBPF-based security observability that can enforce, not just alert: using kernel LSM hooks, it can synchronously block or kill a process the moment it does something it shouldn't, while tracking exec events, syscalls, network activity, and file access tagged with Kubernetes identity. That in-kernel blocking step is what separates it from detection-only runtime tools. Install via Helm chart or the `tetra` CLI. v1.7.1 shipped August 25, 2026. **Pricing:** free, open source (Apache-2.0, with some BPF components under BSD-2-Clause and GPL-2.0), a CNCF project originally from Isovalent.
Kyverno
A Kubernetes-native policy engine that validates, mutates, and generates cluster resources through admission control and background scans, using ordinary Kubernetes YAML instead of a separate policy language — a lower barrier to entry than Rego-based alternatives for teams already fluent in K8s manifests. It also verifies container image signatures at admission time. Install with the Helm chart in the repo's `/charts` directory. v1.19.0 shipped August 20, 2026. **Pricing:** free, open source (Apache-2.0), a CNCF incubating project.
Steampipe
Steampipe turns a CSPM check into a SQL `select` statement: cloud and SaaS state across roughly 140 plugins (AWS, Azure, GCP, Kubernetes, GitHub, and more) gets exposed through a Postgres-compatible interface, no ETL pipeline required. `brew install turbot/tap/steampipe` on macOS, or the install script on Linux. Worth flagging before you deploy it at work: it's AGPL-3.0, a copyleft license most CSPM CLIs in this space don't carry. **Pricing:** free, open source (AGPL-3.0).
KICS
Checkmarx maintains KICS as a static scanner for Terraform, CloudFormation, Kubernetes manifests, Docker, Ansible, and Helm, catching misconfigurations before any of it gets applied. Installation is documented at docs.kics.io rather than the README; the short version is a prebuilt binary or Docker image and a `kics scan` against your IaC directory. **Pricing:** free, open source (Apache-2.0).
StackRox
StackRox's v5.0.0 release candidate, out September 28, 2026, retires the legacy StackRox Scanner in favor of Scanner V4, turns on VM scanning by default for OpenShift Virtualization, and adds cosign signature verification, a real architectural shift rather than a point release. The stable line underneath is Red Hat's Kubernetes-native CNAPP, watching build, deploy, and runtime risk for containerized workloads. Install via Helm: `helm install stackrox-central-services stackrox/stackrox-central-services -n stackrox --create-namespace`. **Pricing:** free, open source (Apache-2.0).

Security AI & Agents

NVIDIA Garak
Probes an LLM or endpoint with adversarial prompts across 50-plus modules covering jailbreaks, prompt injection, data leakage, toxicity, and hallucination, then scores what comes back. `pip install garak`, then `garak --model_type openai --model_name gpt-4o-mini --probes promptinject`. NVIDIA's AI Red Team has backed it since 2023; v0.16.0 shipped August 4, 2026. **Pricing:** free, open source (Apache-2.0); you pay only for the target model's API calls.
Snyk agent-scan
Formerly Invariant Labs' mcp-scan, folded into Snyk after the acquisition. It scans installed MCP servers and agent configs for prompt-injection-laden tool descriptions, tool poisoning, and cross-origin tool shadowing, and can run as a proxy to guardrail live MCP traffic. `uvx snyk-agent-scan@latest` gets you the core scanner; a free Snyk account unlocks the rest. v0.6.0 shipped August 19, 2026. **Pricing:** free, open source core (Apache-2.0); deeper features require a Snyk account.
NeMo Guardrails
Defines programmable rails for LLM applications using Colang rules — block jailbreaks, restrict topics, validate input and output before and after a model call. `pip install nemoguardrails`, then write a `config.yml` and rail files. NVIDIA has maintained it since 2023; v0.23.0 shipped July 1, 2026. **Pricing:** free, open source (Apache-2.0). --- *28 tools this month. Offensive tooling is listed for systems you own or are authorized to test. Found a dead link or have something to add? Reply to the email.*
Microsoft PyRIT
An open automation framework for red-teaming generative AI systems: run standardized scenarios covering content harms, data leakage, and jailbreaks against OpenAI, Azure, Anthropic, Google, or custom HTTP endpoints, composing datasets and attack strategies for repeatable assessments across hundreds of objectives at once. `pyrit_scan` runs it from the command line, or `pyrit_shell` for an interactive session. Microsoft's AI Red Team has maintained it since 2024. **Pricing:** free, open source (MIT).
Promptfoo
A CLI for evaluating and red-teaming LLM applications: it generates adversarial test cases — jailbreaks, prompt injection, PII-leakage probes — against a target model or app and produces a vulnerability dashboard scored against frameworks like the OWASP LLM Top 10. OpenAI acquired the project on March 9, 2026, and the maintainers have committed in the README that it stays open source and MIT-licensed regardless. `npm install -g promptfoo` or `npx promptfoo@latest`. **Pricing:** free, open source core (MIT); a separate paid enterprise tier exists for teams that want managed hosting.
DeepTeam
Wraps your LLM or agent in a callback, then runs it through more than 50 vulnerability types and 20 adversarial attack methods — multi-turn jailbreaks, prompt injection, bias probes, SQL injection attempts through the model — mapped to OWASP LLM Top 10 and NIST categories, scoring each as pass or fail. `pip install -U deepteam` gets the framework running against a target you define in a few lines of Python. **Pricing:** free, open source (Apache-2.0).
Guardrails AI
Guardrails AI wraps an LLM call with input and output validators, PII detection, jailbreak and prompt-injection checks, schema enforcement, hallucination checks, pulled from a hub of reusable guards instead of hand-rolled regex. `pip install guardrails-ai` gets the framework running; guards install separately from the hub as you need them. **Pricing:** free, open source (Apache-2.0).
Meta PurpleLlama
PurpleLlama bundles Meta's LLM security tooling under one repo: Llama Guard classifies prompts and responses for unsafe content, Prompt Guard flags injection and jailbreak attempts, Code Shield filters insecure code an LLM tries to output, and the CyberSecEval benchmarks red-team a model across multiple risk categories. The evaluation code and Code Shield are MIT; the Llama Guard and Prompt Guard model weights ship under the more restrictive Llama Community License. **Pricing:** free; evals and Code Shield under MIT, model weights under the Llama Community License with its own usage terms.
Giskard
Giskard's v2 line scanned tabular ML models; v3.0.0, out August 26, 2026, ripped that out for a ground-up rewrite aimed at multi-turn testing of AI agents instead. The new `giskard-scan` command red-teams a model or agent for prompt injection, jailbreaks, and harmful output, plus deeper RAG evaluation. `pip install giskard` with the `[scan]` extra for the vulnerability scanner; needs Python 3.12 or newer. **Pricing:** free, open source (Apache-2.0). --- *28 tools this month. Offensive tooling is listed for systems you own or are authorized to test. Found a dead link or have something to add? Reply to the email.*

Labs & Learning

OWASP Juice Shop
A deliberately vulnerable web storefront with over 100 hacking challenges spanning the OWASP Top 10 — injection, broken auth, XSS — scored through an in-app leaderboard as you find each one. v20.0.0 (May 12, 2026) added prompt-injection and chatbot-manipulation challenges alongside the classic web bugs, and v20.2.0 (August 10, 2026) is current. `docker run -p 3000:3000 bkimminich/juice-shop` and you're solving challenges in under a minute. **Pricing:** free, open source (MIT).
CloudGoat
Deploys intentionally vulnerable AWS environments as scored scenarios — IAM privilege escalation, Lambda and ECS takeover, S3 breach chains — across 25 scenarios from easy to hard, torn down with the same tool once you're done. The scenario list now includes `agentcore_identity_confusion` and `bedrock_agent_hijacking`, which walk through hijacking a Bedrock agent's tool access rather than a traditional IAM path. `pipx install cloudgoat`, then `cloudgoat create <scenario-name>`. **Pricing:** free, open source (BSD-3-Clause); you pay only your own AWS bill while a scenario is running.
Damn Vulnerable AI Agent
Bills itself as the DVWA of AI agents: 21 intentionally broken agents across the OpenAI API, MCP, and A2A protocols, spanning 12 vulnerability categories like prompt injection, data exfiltration, and supply-chain attacks through tool poisoning. A built-in 22-challenge CTF board with a live scoreboard tracks progress, and it doubles as a place to see what agent identity controls actually stop. `docker run -p 9000:9000 -p 7001-7021:7001-7021 opena2a/dvaa:0.9.2`, then open `localhost:9000`. **Pricing:** free, open source (Apache-2.0). --- *28 tools this month. Offensive tooling is listed for systems you own or are authorized to test. Found a dead link or have something to add? Reply to the email.*