Skip to main content
Skip to main content
PANOPTICON
back

SecOps Tools Catalog

161 hand-picked tools across 14 SecOps categories. Quality > quantity — every entry has a clear primary use-case and an honest pricing tag.

OSINT-only directory with deeper recon coverage: OSINT Framework. Tools that work end-to-end inside this portfolio: /dfir tile grid. Paid services are listed for landscape awareness — they're not proxied or invoked on your behalf.

pricing:
categories:

Showing 161 of 161

  • Maltego Freemium
    industry-standard

    Graph-based investigation platform. Community Edition is free with limited transforms; full transforms in paid tiers.

  • SpiderFoot Open Source

    Automated OSINT scanner — 200+ modules pivoting from a single starting point (domain, IP, person).

    source
  • Sherlock Open Source

    Username enumeration across 400+ social networks. The canonical username-pivot CLI.

    source
  • theHarvester Open Source

    Email + subdomain + name harvesting from public sources (search engines, PGP key servers, LinkedIn, etc).

    source
  • recon-ng Open Source

    Modular framework for web-based recon, modeled after Metasploit. Extensible via marketplace modules.

    source
  • Shodan Freemium
    industry-standard

    Search engine for internet-exposed devices and services. Free tier limited; query credits sold per query.

  • Censys Freemium

    Internet-wide scan data (hosts + certificates + leaked configs). Free tier limited; paid for higher quotas.

  • BinaryEdge Freemium

    Internet attack-surface intelligence — exposed services, leaks, ICS/SCADA detection.

  • FOFA Freemium

    Chinese-origin alternative to Shodan. Strong coverage of APAC infrastructure; useful for cross-checking.

  • Search across breach dumps, paste sites, dark-web mirrors, leaked git repos. Free tier shows preview only.

  • WhatsMyName Open Source

    Browser-based username search across 580+ sites. The data file is also consumed by other OSINT tools.

    source
  • Volatility 3 Open Source
    industry-standard

    Memory forensics framework. The de facto tool for extracting processes, network connections, and injected code from RAM dumps.

    source
  • Autopsy Open Source

    Disk-image forensics GUI built on The Sleuth Kit. Timeline analysis, keyword search, deleted-file recovery.

    source
  • The Sleuth Kit Open Source

    CLI library underpinning Autopsy. Filesystem-level forensics for NTFS / FAT / ExFAT / Ext / HFS+.

    source
  • Super-timeline generator — extracts timestamps from 200+ artifacts and produces a single CSV/JSON timeline.

    source
  • KAPE Free

    Kroll's triage collector — runs on a target host, extracts forensic artifacts in under 10 minutes. Free for non-commercial use.

  • Velociraptor Open Source

    Endpoint visibility and DFIR-at-scale. Custom VQL queries against fleets of agents — collect, hunt, respond.

    source
  • osquery Open Source

    Treat the OS as a SQL database. Query running processes, listening sockets, kernel modules, etc.

    source
  • TheHive Freemium

    Open-source SIRP (Security Incident Response Platform). Case management + observable enrichment via Cortex.

    source
  • Cortex Open Source

    Observable analyzer + responder engine. ~100 analyzers (VirusTotal, abuse.ch, MISP, etc) callable from TheHive.

    source
  • MISP Open Source
    industry-standard

    Threat-intelligence sharing platform. Standard format for IOC exchange between teams; integrates with most SIEMs.

    source
  • Google's remote-live-forensics framework. Hunt for IOCs across thousands of endpoints from a central console.

    source
  • Commercial DFIR suite — disk + mobile + cloud + memory in one workflow. Paid; widely used by LE.

  • OpenCTI Open Source

    STIX-2.1-native threat-intelligence platform. Knowledge-graph relationships, connectors for 100+ sources.

    source
  • MITRE ATT&CK Open Source
    industry-standard

    Adversary tactics + techniques knowledge base. The shared vocabulary for describing attacker behaviour.

  • Layer the ATT&CK matrix with your detection coverage, actor tradecraft, or threat assessment.

    source
  • essential

    URLhaus / MalwareBazaar / ThreatFox — free IOC feeds. Free API key on signup.

  • Crowdsourced threat-intel pulses. Free API; integrates everywhere.

  • Google Cloud / Mandiant TI platform. APT tracking, TTPs, finished intel reports. Enterprise-grade.

  • AI-driven threat-intel platform. Wide source coverage, expensive.

  • CrowdSec Freemium

    Crowdsourced IP-reputation engine. Open-source agent + community blocklist; paid SaaS for premium feeds.

    source
  • GreyNoise Freemium

    Identifies internet-background-noise scanners vs targeted activity. Free community tier (limited queries).

  • Webamon Freemium
    essential

    Threat-intel platform with Lucene-searchable IOC sweeps, fingerprint pivoting via MD5/SHA1/SHA256/SSDEEP hashes, and a Community API for sandbox + screenshot + infrastructure-graph lookups.

  • Cloud-based malware sandbox with screenshot capture and infrastructure graph. Free via Webamon Community API (sign-up).

  • garak Open Source
    essential

    NVIDIA's LLM vulnerability scanner. Probes for prompt injection, jailbreaks, data leakage, toxic outputs.

    source
  • PyRIT Open Source

    Microsoft's Python Risk Identification Tool for generative AI. Automated red-teaming framework.

    source
  • promptfoo Open Source

    LLM eval + red-teaming. Configurable test suites for prompt injection, jailbreaks, harmful content.

    source
  • Guardrails AI Open Source

    Validation library for LLM outputs. Composable validators (PII detection, toxicity, schema compliance).

    source
  • NeMo Guardrails Open Source

    NVIDIA's programmable guardrails layer for LLM apps. Define dialogue + safety rails in Colang DSL.

    source
  • Hosted LLM-firewall API — prompt-injection + jailbreak + PII detection. Free tier limited; paid for production.

  • essential

    Reference list of the top LLM-application risks (prompt injection, training-data poisoning, etc). Required reading.

  • Linux Foundation AI library for evaluating ML model robustness against adversarial examples.

    source
  • MITRE ATLAS Open Source

    ATT&CK-style tactics + techniques for adversarial attacks on AI/ML systems.

  • VirusTotal Freemium
    industry-standard

    Multi-engine AV scanner + sandbox + relationship graph. Free tier limited (4/min); enterprise tier deep.

  • ANY.RUN Freemium

    Interactive malware sandbox. Free tier requires public submissions; paid tier private + advanced features.

  • Joe Sandbox Freemium

    Deep behavioural analysis sandbox (Windows/Linux/macOS/Android/iOS). Cloud Basic is free with public reports.

  • CrowdStrike Falcon Sandbox — free public submissions, API for vetted researchers.

  • Sample sharing platform from abuse.ch. Free hash + sample download for vetted researchers.

  • capa Open Source

    Mandiant's capability detector for executables. Tells you what a binary CAN do without running it.

    source
  • YARA Open Source
    industry-standard

    Pattern-matching language for malware classification. The lingua franca of malware research.

    source
  • Ghidra Open Source

    NSA-released reverse-engineering framework. Free IDA Pro alternative — disassembler + decompiler + scripting.

    source
  • radare2 Open Source

    CLI reverse-engineering framework. Steep learning curve; powerful for scripted analysis. iaito GUI also available.

    source
  • industry-standard

    Industry-standard interactive disassembler. Hex-Rays decompiler is the gold standard. Expensive.

  • REMnux Open Source

    Linux distribution for malware analysis. Hundreds of pre-installed tools + curated workflows.

  • FLARE-VM Open Source

    Mandiant's Windows VM provisioner for malware analysis + reverse engineering.

    source
  • PE-Studio Freemium

    Static PE file analyzer. Highlights anomalies, imports, sections, indicators. Free for non-commercial use.

  • Detect It Easy Open Source

    PE/ELF/Mach-O packer + compiler detector. Plugin-based; modern alternative to PEiD.

    source
  • NVD Free
    industry-standard

    NIST National Vulnerability Database. Authoritative source for CVE metadata + CVSS scores. Free API.

  • essential

    Known Exploited Vulnerabilities catalog. The "patch this first" list — every entry has confirmed exploitation.

  • EPSS Free

    Exploit Prediction Scoring System — probability that a CVE will be exploited in the next 30 days. Free API.

  • Google's open-source vulnerability database. Excellent for SBOM and dependency-graph queries.

    source
  • GitHub-curated advisories for npm, PyPI, Maven, NuGet, Composer, RubyGems, Cargo, Pub. Free API.

  • Offensive Security exploit archive. PoCs, shellcodes, exploit techniques — historical + current.

  • Independent KEV catalog — earlier exploitation signals than CISA, broader source set. Free API tier.

  • Nuclei Open Source
    essential

    Template-based vulnerability scanner. ~9000 community templates; the modern web-vuln scanner.

    source
  • Industry-standard vulnerability scanner. Paid (Pro/Expert/Manager); free Essentials limited to 16 hosts.

  • Cloud-native vuln management platform. Enterprise-tier; competes with Tenable + Rapid7.

  • gitleaks Open Source
    essential

    Secret scanning for git repos. ~150 default rules; pre-commit + CI-friendly. The standard.

    source
  • trufflehog Open Source

    Secret scanner with hundreds of detectors and live verification (calls the API to confirm a secret is valid).

    source
  • detect-secrets Open Source

    Yelp's pre-commit-friendly secret scanner. Pluggable detectors with baseline-management for false positives.

    source
  • Curated regex pattern database (~1600) for secret detection. Foundation for custom DLP scanners.

    source
  • GitGuardian Freemium

    Hosted secret-detection across git, Slack, Jira. Free tier limited; paid for org-scale + remediation.

  • AI-driven DLP across SaaS apps (Slack, Jira, GitHub, Confluence, M365). Strong PII/PHI detection.

  • Enterprise data governance + DLP across M365 / Azure / on-prem. Bundled with E5 licensing.

  • Mozilla SOPS Open Source

    Encrypts secrets at rest with KMS / GPG / age. Diff-friendly format; works in git workflows.

    source
  • Sigma Open Source
    industry-standard

    Generic SIEM-agnostic signature format. Convert one rule to Splunk/Sentinel/Elastic/QRadar. SigmaHQ ruleset = thousands of rules.

    source
  • Modern Sigma rule converter. Replaces the legacy sigmac. Plugins for each backend.

    source
  • Atomic Red Team Open Source
    essential

    Red Canary library of small, portable test scripts mapped to ATT&CK. Validate detections atomically.

    source
  • CALDERA Open Source

    MITRE adversary-emulation platform. Automated red-team campaigns mapped to ATT&CK.

    source
  • Falco Open Source

    CNCF runtime-security engine. eBPF + custom rule language for container + Kubernetes threat detection.

    source
  • SigmaHQ Rules Open Source

    Open Sigma ruleset — thousands of rules across Windows, Linux, cloud, network. Curated by the community.

    source
  • Elastic Security detection rules. TOML format with full ATT&CK mapping; ~1000 rules.

    source
  • Splunk Enterprise Security Content Update. SPL + ATT&CK mapping; updated continuously.

    source
  • Azure-Sentinel Open Source

    Microsoft Sentinel KQL detection rules. The largest open-source KQL detection collection.

    source
  • GoXDR Open Source

    Curated KQL query library for Sentinel + Defender XDR. 100+ queries covering identity attacks, NTLM abuse, LDAP recon, lateral movement, and shadow IT.

    source
  • LimaCharlie Freemium

    SecOps cloud — EDR + log + automation primitives, pay-per-event. Free for small workloads.

  • Panther Freemium

    Detection-as-code SIEM (Python rules, YAML data models). Cloud-native; commercial.

  • Asset + relationship security graph + queryable detection. JupiterOne; community tier exists.

  • MXToolbox Freemium

    Email + DNS diagnostics. Free quick-checks (DMARC, SPF, MX, blacklists); paid monitoring.

  • EasyDMARC Freemium

    DMARC report aggregator + email-auth wizard. Free tier for small domains.

  • dmarcian Freemium

    Established DMARC analytics platform. Free community tier; paid for larger domains.

  • Mail-Tester Freemium

    Send a test email, get a deliverability + auth + content score. Free 3 tests/day.

  • Enterprise email gateway + threat protection. Industry leader in BEC + impostor protection.

  • Cloud email security gateway. Strong archiving + continuity story.

  • AI-driven BEC + account-takeover detection. API-based (no MX change). Strong analyst feedback.

  • Defense-in-depth for already-delivered email. Re-authenticate before exposing PII; sweep retroactively.

  • Email-address reputation lookup — breach hits, social presence, sender history. Free API.

  • Wireshark Open Source
    industry-standard

    The packet capture + analysis tool. Indispensable for any network forensics work.

    source
  • Zeek Open Source

    Network analysis framework (formerly Bro). Generates rich connection logs + protocol metadata.

    source
  • Suricata Open Source

    High-performance IDS/IPS + NSM. Compatible with Snort rules + ET ruleset.

    source
  • Snort Open Source

    The original signature-based IDS. Snort 3 is the actively maintained version; massive rule ecosystem.

  • Nmap Open Source
    industry-standard

    Network scanner. Service detection + scriptable via NSE. Foundational.

    source
  • Masscan Open Source

    Internet-scale port scanner. Scans the entire internet in minutes; pair with Nmap for service detection.

    source
  • naabu Open Source

    ProjectDiscovery's fast port scanner. Pipes cleanly into nuclei/httpx for chained recon.

    source
  • RITA Open Source

    Real Intelligence Threat Analytics — beaconing detection on Zeek logs. Active Countermeasures.

    source
  • Prowler Open Source

    Multi-cloud CSPM (AWS/Azure/GCP/K8s). 400+ checks against CIS, NIST, GDPR, etc. Open-source CLI + paid SaaS.

    source
  • ScoutSuite Open Source

    NCC Group multi-cloud auditing tool. AWS / Azure / GCP / OCI / AliCloud. Static HTML report.

    source
  • Checkov Open Source

    IaC + image + secrets scanning. Terraform / CloudFormation / Helm / K8s / Dockerfile / GHA.

    source
  • Trivy Open Source
    essential

    Aqua all-in-one vuln + IaC + secret + license + SBOM scanner. The reference container scanner.

    source
  • kube-bench Open Source

    Aqua tool that runs the CIS Kubernetes Benchmark against a cluster. Quick hardening audit.

    source
  • kube-hunter Open Source

    Hunts for security weaknesses in Kubernetes clusters. Active + passive modes.

    source
  • Pacu Open Source

    AWS exploitation framework — privilege escalation, persistence, exfiltration. Rhino Security.

    source
  • Granular cloud-attack technique simulator. Test your detections against real cloud TTPs.

    source
  • Wiz Paid

    Cloud security platform — agentless CSPM/CWPP/CIEM. Acquired by Google for $32B in 2024.

  • Burp Suite Freemium
    industry-standard

    Web app proxy + scanner. Community Edition is free (no scanner); Professional is the bug-bounty standard.

  • Caido Freemium

    Modern web pentesting suite — Burp alternative, Rust-based. Free tier capable; Pro paid.

  • OWASP ZAP Open Source

    OWASP's free web app scanner. Solid for CI integration; weaker than Burp for manual workflows.

    source
  • sqlmap Open Source

    Automated SQL injection + database takeover. The reference tool for confirming + exploiting SQLi.

    source
  • ffuf Open Source

    Fast web fuzzer (Go). Replaces dirb / wfuzz / dirsearch for most workflows.

    source
  • OWASP Amass Open Source

    In-depth attack-surface mapping + asset discovery. The thorough subdomain enumerator.

    source
  • subfinder Open Source

    ProjectDiscovery's passive subdomain enumerator. Fast, scriptable, pipes into the rest of the PD ecosystem.

    source
  • httpx Open Source

    Fast HTTP toolkit + probe. Tech-stack fingerprinting, status checks, screenshots.

    source
  • Semgrep Freemium
    essential

    Lightweight static analysis with a rule registry that reads like grep but understands syntax. OSS engine + paid SaaS.

    source
  • GitHub's variant analysis engine. Free for OSS + GitHub-Native; query language is the differentiator.

  • Snyk Freemium

    Developer-first SCA + SAST + IaC + container scanning. Free tier generous; paid for org-wide.

  • HashiCorp Vault Open Source
    industry-standard

    The reference secrets manager. OSS Community Edition + Enterprise (BSL licensed).

    source
  • Infisical Freemium

    Open-source secrets platform. Pleasant UI, modern git integration; SaaS or self-hosted.

    source
  • age Open Source

    Modern file encryption tool. Designed as a simpler PGP replacement; pairs with SOPS.

    source
  • Keycloak Open Source

    The reference open-source IAM. SAML + OIDC + federation, customizable themes, Red Hat SSO upstream.

    source
  • Teleport Freemium

    Identity-aware access proxy for SSH / K8s / DB / desktop. OSS Community + paid Enterprise.

    source
  • Tailscale Freemium

    WireGuard-based zero-config VPN. Free for up to 100 devices; identity-first networking.

  • industry-standard

    The exploitation framework. Thousands of modules, post-exploitation, listeners. Rapid7 maintains.

    source
  • Commercial adversary-emulation C2 framework. Industry standard for red teams; widely abused by criminals too.

  • Sliver Open Source

    Open-source cross-platform C2. Cobalt Strike alternative. Bishop Fox.

    source
  • Havoc Open Source

    Modern post-exploitation C2. Cross-platform implant + customizable evasion.

    source
  • Mythic Open Source

    Multiplayer C2 framework with pluggable agents. Strong for long-engagement red teams.

    source
  • BloodHound Freemium
    essential

    AD + Azure attack-path graph. Community Edition (free) + Enterprise. The reference AD recon tool.

    source
  • Impacket Open Source

    Python network-protocol library + offensive scripts (psexec, secretsdump, ntlmrelayx, etc).

    source
  • Adversary-emulation platform — same project as listed under Detection Engineering, complementary use cases.

    source
  • Akamai/Guardicore continuous breach + attack simulation. Auto-spreads through your network safely.

    source
  • DeepFind.Me Freemium

    Comprehensive OSINT platform — username search (50+ platforms), geolocation, email/domain recon, metadata extraction, dark-web link checker, crypto wallet tracking, and steganography tools. REST API available.

  • Curated directory of OSINT tools with community collections, featured tools, and new-tool discovery. Covers the full spectrum of open-source intelligence gathering.

  • Curated OSINT and cybersecurity tools directory — categorized tools for reconnaissance, social media investigation, and digital forensics investigations.

  • All-in-one website analysis — DNS, SSL/TLS, security headers, WHOIS, tech stack detection, performance audit, and security misconfiguration scanning from a single URL.

  • Interactive security tools suite — domain/DNS auditor, host checker, clickjacking PoC generator, GitHub leaks scanner, cloud IAM auditor (PEASS), and AI security chatbot.

  • Google-backed open-source vulnerability database — ecosystem-agnostic schema covering PyPI, npm, Go, Maven, Rust, and more. REST API and deterministic query by commit hash.

  • Aggregated threat intelligence from 500+ public blacklists. Searchable IP/domain database with categorized blocklist downloads (malware, spam, phishing, crypto, DGA, bad reputation).

  • Threat intelligence platform — cross-reference IOCs, track threat actor campaigns, and browse curated OSINT tools. Community-driven threat data aggregation.

  • Interactive Sigma rule browser — search and filter detection rules with live SIEM conversion previews for Splunk, Elasticsearch, QRadar, Microsoft Sentinel, and more.

  • Open-source IP blocklist with live statistics and downloadable feeds. Covers malicious IPs across multiple threat categories. REST API for automated ingestion.

    source
  • Interactive threat intelligence mindmap — visual navigation of TTPs, threat actors, campaigns, and detection strategies aligned with the MITRE ATT&CK framework.

  • Comprehensive insider threat framework — indicators, detection methods, mitigation playbooks, and real-world case studies across insider personas and attack vectors.

  • OSINT and threat intelligence search platform — unified queries across multiple data sources for indicator lookups, threat actor profiling, and infrastructure discovery.

  • Curated catalog of cybersecurity tools — penetration testing, forensics, OSINT, red teaming, and blue team operations. Categorized with search and filtering.

  • Security research publications — attack surface management insights, vulnerability disclosures, APT tracking, and adversary infrastructure analysis.

  • AIDefend Freemium

    AI-powered cybersecurity defense — automated threat detection, AI-driven incident response orchestration, and continuous security posture management.

  • Interactive application security training — hands-on labs covering OWASP Top 10, API security testing, secure coding practices, and vulnerability remediation.

  • Curated AI/ML security resource hub — academic papers, offensive/defensive tools, CTF challenges, and frameworks for adversarial ML and LLM red teaming.

  • Interactive visual mapping of the OWASP AI security landscape — explore AI-specific threats, vulnerabilities, and controls across the ML development lifecycle.

  • Threat intelligence dashboard — live IOC feeds, campaign tracking, and real-time security event monitoring from Mjolnir Security.

  • AI-powered security assistant — threat intelligence queries, security automation workflows, and chatbot-driven incident response guidance.