Kali Linux
Linux distribution for authorized penetration testing, security assessments, and forensic workflows.
Discover, compare, and explore tools for defensive operations, authorized testing, forensics, cloud security, threat intelligence, and more.
Search, filter, sort, and explore tools with detailed information and links.
Linux distribution for authorized penetration testing, security assessments, and forensic workflows.
Intercept web requests and assess applications through controlled security testing workflows.
Collect cloud and endpoint telemetry, correlate detections, and investigate security incidents.
Investigate events, build detection rules, and hunt across indexed security telemetry.
Discover hosts, enumerate services, and assess network exposure in authorized environments.
Use versioned templates to check systems for known security misconfigurations and exposures.
Map identity permissions and visualize potential attack paths in directory environments.
Examine disk images, files, and artifacts during digital forensic investigations.
Disassemble and decompile software for reverse engineering and malware analysis.
Visualize relationships between publicly available entities and investigation findings.
Structure, correlate, and share threat indicators and related intelligence with teams.
Organize cyber threat intelligence and map relationships among actors, malware, and indicators.
Query operating-system state with SQL-style queries for fleet visibility and investigations.
Open-source proxy and scanner for testing web application security during authorized assessments.
Assess security configurations and compliance posture across cloud environments.
Inspect cloud security configurations and surface audit findings across providers.
Integrated platform for network visibility, intrusion detection, log analysis, and threat hunting.
Explore publicly indexed internet-connected devices and exposed services.
Detect suspicious traffic using signatures, protocol inspection, and network event logging.
Collect endpoint artifacts and run targeted investigations across systems.
Look up files, hashes, domains, and URLs using aggregated security analysis results.
Analyze memory captures to inspect processes, modules, and other volatile system artifacts.
Monitor endpoints, analyze security events, and assess configuration and file integrity.
Write pattern-matching rules to identify families and characteristics in suspicious files.
Produce rich network event logs and support security monitoring and incident investigations.
Try a different search term or clear your filters.
Three handpicked tools from the directory.
Capture and inspect network packets to troubleshoot protocols and investigate suspicious traffic.
Analyze security events, build detections, and investigate incidents across diverse log sources.
Open-source framework used to validate vulnerabilities and develop controlled exploit tests.
Discover tools based on the work you are trying to accomplish.
SIEM, endpoint monitoring, and network visibility for a practical defensive operations stack.
Explore collection →Forensic collection, memory analysis, endpoint triage, and investigation workflows.
Explore collection →Proxies, scanners, and authorized application-security testing workflows.
Explore collection →Threat intelligence, endpoint visibility, detection engineering, and investigation tooling.
Explore collection →Third-party product names and brand marks remain the property of their respective owners and are shown only to identify the tools listed in this directory. No sponsorship or endorsement is implied. Where logo usage is restricted or a verified product-specific mark is not configured, CORVASEC displays the existing tool initials instead.