Discover, compare, and save the best security auditing alternatives.
Showing 18 tools
Syft is a CLI tool and library for generating a Software Bill of Materials (SBOM) from container images, filesystems, and archives. It provides a comprehensive inventory of software components, including dependencies and licenses, and pairs with a scanner such as Grype for vulnerability detection, enabling users to manage and secure their software supply chain.
✦ Best for devops and security teams needing free, comprehensive sboms for containers
CrowdSec is an open-source security solution that leverages community‑driven threat intelligence to protect servers, containers, and applications from malicious traffic. It parses logs, detects attacks, and automatically bans offending IPs using a shared blacklist that evolves with real‑world data. The platform provides ready‑made parsers and scenarios, a powerful API, and integrations with firewalls, proxies, and orchestration tools, enabling both small teams and large enterprises to benefit from collective cyber‑threat intelligence without vendor lock‑in.
✦ Best for sysadmins/devops needing free, community‑driven ip blocking
John the Ripper Jumbo is a powerful offline password cracking tool that can recover passwords from a wide variety of hash and cipher formats. It runs on many operating systems and leverages CPUs, GPUs, and even some FPGAs for high‑performance cracking. The project is open‑source and continuously updated with new algorithms, making it a go‑to solution for security researchers, penetration testers, and system administrators who need to audit password strength.
✦ Best for security auditors needing high‑performance, customizable offline hash cracking
Connaisseur is an admission controller that integrates Container Image Signature Verification into a Kubernetes cluster. It ensures that only trusted container images are deployed to the cluster, thereby enhancing the security and integrity of the cluster. By verifying the digital signatures of container images, Connaisseur prevents malicious or tampered images from being deployed, thus reducing the risk of security breaches and attacks.
✦ Best for kubernetes admins seeking robust image security
Prowler is an open-source cloud security platform that automates security and compliance across any cloud environment. It helps organizations ensure their cloud infrastructure is secure and compliant with industry standards.
✦ Best for tech-savvy cloud security teams
SpiderFoot is an open-source intelligence automation tool designed to help organizations map their attack surface and gather threat intelligence. It automates the process of gathering and analyzing data from various sources, providing a comprehensive view of an organization's security posture.
✦ Best for large organizations with in-house security teams
Lynis is a security auditing tool for Linux, macOS, and UNIX-based systems. It assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Lynis is agentless and installation is optional. It provides a comprehensive security scan and suggests remediation steps to improve system security.
✦ Best for experienced system administrators and security professionals
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. It helps identify vulnerabilities and weaknesses in mobile apps, ensuring the security and integrity of the application.
✦ Best for experienced security professionals and developers
Velociraptor is a digital forensics and incident response tool that allows users to collect and analyze data from endpoints. It provides a flexible and scalable platform for automating and streamlining digital forensic workflows.
✦ Best for experienced dfir teams seeking automation and scalability.
Strix is an open-source AI penetration testing platform designed to help developers and security teams proactively find and fix vulnerabilities in their applications. By leveraging artificial intelligence, it automates the security testing process to uncover hidden flaws before malicious actors can exploit them. The tool streamlines application security by integrating advanced AI capabilities into your workflow, making continuous security assessments accessible and efficient. It empowers teams to maintain high code quality and robust defense mechanisms without requiring dedicated manual penetration testing for every release.
✦ Best for tech-savvy security teams and developers
Dirsearch is a command-line utility designed to uncover sensitive files, admin panels, and forgotten backup archives on web servers. It leverages a comprehensive wordlist to systematically request paths and provides multi-threaded scanning, flexible extension filtering, and recursive brute-forcing capabilities.
✦ Best for experienced security professionals and penetration testers
T-Pot is an advanced, all-in-one multi-honeypot platform developed by Deutsche Telekom Security. It aggregates various honeypot sensors into a unified Docker-based environment, enabling security professionals to monitor, analyze, and log cyber attacks in real-time. The platform integrates a robust backend featuring the Elastic Stack (ELK), Suricata, and other analytical tools to visualize threat intelligence and telemetry data. It serves as an essential deployment for organizations and researchers looking to study malicious actor behavior and improve threat detection capabilities.
✦ Best for experienced security teams with dedicated resources