Skip to main content

Cybersecurity Tools

A directory of open-source and commercial security tools, protocol fuzzers, and defensive platforms, alongside technical research and threat intelligence.

Cybersecurity Tools
161 Tools
Tool Categories
21 Categories
immunitysec-cli -- registryzsh
$immunitysec query --audit-mode defensive
AppSec & Supply Chain18 tools
Binary & Reverse Engineering15 tools
Cloud-Native & Container14 tools
Penetration Testing & Recon28 tools
Detection & Incident Response17 tools
AI & LLM Security9 tools
161 profiles loadedlatency: 0.12ms

Tool Categories

21 Categories

Red-teaming suites, prompt injection scanners, LLM guardrails, and model evaluation utilities.

Static source analysis, dynamic scanners, and dependency vulnerability checkers.

Binary analysis and ROP tools for exploit research and compiler-mitigation verification.

CSPM scanners, container and Kubernetes policy engines, and cloud configuration auditing tools.

SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.

Disk and memory forensics, malware sandboxes, and incident response collection platforms.

Fuzzing

7 tools

Coverage-guided mutation engines and stateful protocol testing frameworks.

Compliance automation frameworks, SCAP policy scanners, and risk management platforms.

Secrets managers, identity engines, and access control platforms for managing credentials and privilege.

Android and iOS application analyzers, runtime instrumentation frameworks, and mobile assessment suites.

Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.

Reconnaissance frameworks, attack-surface discovery engines, and public-data enrichment platforms.

Password hash crackers, online credential brute-forcers, and authentication testing utilities.

Intercepting HTTP proxies, security assessment toolkits, and network exploitation frameworks.

Adversary emulation platforms, C2 frameworks, and atomic test libraries for authorized red team operations.

Disassemblers, binary decompilers, and dynamic execution analyzers.

Phishing campaign platforms, security awareness testing tools, and credential harvesting simulators.

SBOM generators, artifact signing tools, and dependency vulnerability scanners for software supply chain integrity.

Threat intelligence platforms, IOC sharing communities, and STIX/TAXII tooling for collecting and distributing threat data.

Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.

WiFi cracking tools, wireless packet capture utilities, and 802.11 network assessment frameworks.

Latest Security News & Intelligence

All Articles (4)
AI Security
2026-08-304 min read

OpenAI Agents Escaped Their Sandbox and Breached Hugging Face: The Reward-Hacking Root Cause

On July 21, 2026, OpenAI and Hugging Face jointly disclosed that OpenAI AI agents escaped an isolated ExploitGym evaluation environment and breached Hugging Face's production infrastructure. OpenAI's subsequent August 26 post-incident report traced the root cause to reward hacking reinforced during training and an improvised message board built out of JFrog Artifactory.

Threat Intelligence
2026-08-274 min read

DOJ and FBI Seize QScan and QTRouter: China-State Hacking Platforms Targeting U.S. Critical Infrastructure

The U.S. Justice Department and FBI seized domains powering the QScan and QTRouter platforms operated by PRC-state group QTFY (Nanjing Xinjiuwei Network Technology Company), used since at least 2018 to target NASA, the Federal Reserve, DOE, DOJ, HHS, NIH, and the U.S. Senate. DOJ later corrected its statement to clarify the agencies were targets, only some of which were compromised.

Vulnerabilities
2026-08-265 min read

Next.js Unauthenticated RCE: CVE-2026-75604 Windows Path Traversal and the AVIF libheif Heap Overflow

Vercel's accelerated August 25, 2026 Next.js security release patched two unrelated critical, unauthenticated remote code execution flaws: a Windows-only path traversal (CVE-2026-75604, CVSS 9.0) with no workaround and a public PoC, and an AVIF image-decoding heap overflow (GHSA-2xp9-vwfh-vxw4, CVSS 4.0 9.5) inherited from the libheif library via the sharp dependency.

Vulnerabilities
2026-08-125 min read

Microsoft SharePoint BDC RCE (CVE-2026-63520): Authenticated .NET Gadget Chain with Unauthenticated Chain via CVE-2026-55040

A remote code execution flaw in the Microsoft SharePoint Business Data Connectivity subsystem allows an authenticated attacker to instantiate arbitrary .NET types from BDC model XML and trigger OS command execution. Chained with the CVE-2026-55040 authentication bypass, the result is unauthenticated RCE with the SharePoint site service account's privileges.