Sinisterly
Open source tools for information security specialists. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: Open source tools for information security specialists. (/Thread-Open-source-tools-for-information-security-specialists)



Open source tools for information security specialists. - radixtenshi - 06-22-2021

Here is a list of open source and free tools which will help in day to day operations in SOC teams and other cyber security professionals.
I know for some it's obvious, but for others it's not, so I leave these links for those.

It makes no sense to describe each tool, follow the links and study the necessary material :

Red Team - Penetration testing tools:
• osintframework (https://osintframework.com/)
• Wireshark (https://www.wireshark.org/)
• Metasploit (https://www.metasploit.com/)
• Burp suite (https://portswigger.net/burp)
• AngryIP (https://angryip.org/)
• SQLMap (https://sqlmap.org/)
• Seclist (https://github.com/danielmiessler/SecLists)
• Payloads (https://github.com/swisskyrepo/PayloadsAllTheThings)
• Exploit-DB (https://t.me/Social_engineering/1220)
• Free Tools from Thycotic (https://thycotic.com/solutions/free-it-tools/)
• Free AD Tools from ManageEngine (https://www.manageengine.com/products/free-windows-active-directory-tools/free-active-directory-tools-index.html?pos=free_tools&loc=Active_Directory&cat=title)
• SolarWinds Free IT Security Tools (https://www.solarwinds.com/free-tools)
• OWASP Dependency Check (https://owasp.org/www-project-dependency-check/)
• OWASP Dependency Track (https://owasp.org/www-project-dependency-track/)
• Container Scanning (https://docs.gitlab.com/ee/user/application_security/container_scanning/)

Incident Responce:
• Redline (https://www.fireeye.com/services/freeware/redline.html)
• Memoryze (https://www.fireeye.com/services/freeware/memoryze.html)
• Fakenet-NG (https://www.fireeye.com/services/freeware/fakenet-ng.html)
• Floss (https://www.fireeye.com/services/freeware/floss.html)
• Flare-VM (https://www.fireeye.com/services/freeware/flare-vm.html)
• FTKImager (https://accessdata.com/products-services/forensic-toolkit-ftk/ftkimager)
• SysInternals Suite (https://docs.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite)
• Registry browser (https://lockandcode.com/software/registry_browser)
• Regshot (https://sourceforge.net/projects/regshot/)
• CaptureBAT (https://www.honeynet.org/projects/old/capture-bat/)
• PEStudio (https://www.winitor.com/features)
• Rootkit revealer (https://docs.microsoft.com/en-us/sysinternals/downloads/rootkit-revealer)
• XAMPP (https://www.apachefriends.org/index.html)
• HxD (https://mh-nexus.de/en/hxd/)
• Beagle (https://github.com/yampelo/beagle)

Malware analysis:
• Any.run (https://any.run/)
• Hybrid Analysis (https://www.hybrid-analysis.com/)
• Manalyzer (https://manalyzer.org/)
• JoeSandbox (https://www.joesandbox.com/)
• Cuckoo Sandbox (https://cuckoosandbox.org/)
• Comodo Valkyrie (https://valkyrie.comodo.com/)
• Remnux (https://remnux.org/)
• SANS (https://www.sans.org/blog/-must-have-free-resources-for-malware-analysis/)
• Triage (https://tria.ge/)


RE: Open source tools for information security specialists. - applesauce - 07-28-2021

great list. thank you for the share