
faraday
Open Source Vulnerability Management Platform

Open Source Vulnerability Management Platform

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

A Modern Orchestration Engine for Security

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Catch what's lurking in your Kafka clusters.

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Python script to scan Git repos for interesting strings

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…


Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

AI-powered offensive security testing using autonomous agents, directly in your terminal.

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…