RPM Consulting
RPM Consulting
  • Home
  • Services
  • Careers
  • Blog
  • Free Tools
  • Contact Us
  • More
    • Home
    • Services
    • Careers
    • Blog
    • Free Tools
    • Contact Us
  • Home
  • Services
  • Careers
  • Blog
  • Free Tools
  • Contact Us

Free Tools

Free cybersecurity tools

In the interest of assisting the cybersecurity in defending their systems, networks and data, we are providing links to a variety of freely available tools for download and use. We do not develop or maintain any of these, but we do hope their availability is helpful in keeping information secure. If you have any comments recommended resources that you don't see here, please feel free to contact us. 

Information Gathering and Reconnaissance

Nikto

OpenVAS

OpenVAS

Web server vulnerability, version and configuration tester. 


https://cirt.net/nikto2

OpenVAS

OpenVAS

OpenVAS

A vulnerability scanner capable of authenticated  and unauthenticated testing.


 https://www.openvas.org/ 

Photon

OpenVAS

Photon

 Open source intelligence (OSINT) tool designed to crawl the web.


https://github.com/s0md3v/Photon  

Nessus

DNS Dumpster

Photon

Vulnerability and configuration assessment tool featuring auditing, profiling, sensitive data discovery, patch management and analysis.


https://www.tenable.com/products/nessus


Shodan

DNS Dumpster

DNS Dumpster

Search engine for identifying Internet-connected Internet of Things (IoT) platforms, servers and various smart devices.


https://www.shodan.io/

DNS Dumpster

DNS Dumpster

DNS Dumpster

Free domain research web service for Domain Name Server (DNS) information such as hosts, subdomains and associated vulnerabilities.


https://dnsdumpster.com/

Darksearch.io

Wayback Machine

Wayback Machine

Dark web search engine with API for automaton of searches. Can be used from open web.


https://darksearch.io/

Wayback Machine

Wayback Machine

Wayback Machine

Digital archive of the web that allows for historic searches of web pages.


https://archive.org/web/

Intelligence X

Wayback Machine

Intelligence X

Digital archive of the web that allows for historic searches of web pages. No censoring of content.


https://intelx.io/

Packet Analysis

Wireshark

Wireshark

Wireshark

One of the most popular open source network traffic/packet analyzers.


https://www.wireshark.org/

TCP Dump

Wireshark

Wireshark

An older, simple, minimal, command-line packet analyzer. 


http://www.tcpdump.org/

Kismet

Wireshark

EtherApe

A wireless device detector and packet analyzer and intrusion detection system.


https://www.kismetwireless.net/

EtherApe

Aircrack-ng

EtherApe

EtherApe is an open-source graphical network monitoring and traffic analysis tool.


https://etherape.sourceforge.io/

Aircrack-ng

Aircrack-ng

Aircrack-ng

Suite of tools for monitoring packets, testing hardware, cracking passwords and launching attacks on Wi-Fi networks.


https://www.aircrack-ng.org/

Hping

Aircrack-ng

Aircrack-ng

TCP/IP packet crafter, tracer and response analysis tool.


http://www.hping.org/

Password Recovery/Cracking

Cain and Abel

John the Ripper

John the Ripper

 Windows-based tool capable of cracking encrypted passwords, sniffing network traffic, recording VoIP conversations, and analyzing routing protocols.


http://www.oxid.it/cain.html

John the Ripper

John the Ripper

John the Ripper

Password cracker available for many flavors of Unix, macOS, Windows, DOS, BeOS, and OpenVMS.


https://www.openwall.com/john/

Hashcat

John the Ripper

Hashcat

Highly-parallelized simultaneous cracking of multiple passwords.


https://hashcat.net/hashcat/

Medusa

THC-Hydra

Hashcat

Command-line parallel brute-forcer password cracker.


http://foofus.net/goons/jmk/medusa/medusa.html

THC-Hydra

THC-Hydra

THC-Hydra

Brute force password cracker. Available for Windows, Linux, Free BSD, Solaris and OS X.


https://github.com/vanhauser-thc/thc-hydra

Brutus

THC-Hydra

THC-Hydra

Remote password cracker that supports many different authentication types.


https://www.darknet.org.uk/2006/09/brutus-password-cracker-download-brutus-aet2zip-aet2/

Network Mapping

Nmap

MASSCAN: Mass IP port scanner

NetworkMiner

Open source network mapping, system discovery and OS detection tool.


https://nmap.org/

NetworkMiner

MASSCAN: Mass IP port scanner

NetworkMiner

Open source passive network sniffer and forensic analysis tool capable of enumerating operating systems, sessions, hostnames, open ports.


https://www.netresec.com/index.ashx?page=NetworkMiner

MASSCAN: Mass IP port scanner

MASSCAN: Mass IP port scanner

MASSCAN: Mass IP port scanner

Internet-scale port scanner. Known for speed. Includes web interface.


https://github.com/robertdavidgraham/masscan

Catci

Angry IP Scanner

MASSCAN: Mass IP port scanner

Free and open source network graphing solution. Can monitor network traffic by polling a network switch or router interface via SNMP.


https://www.cacti.net/

Nagios

Angry IP Scanner

Angry IP Scanner

Free and open source software system and network monitoring platform.


https://www.nagios.org/downloads/

Angry IP Scanner

Angry IP Scanner

Angry IP Scanner

Free and open-source network scanning utility with the ability to scan individual IP addresses.


https://angryip.org/download/

Intrusion Detection

Snort

Zeek (formerly Bro)

Zeek (formerly Bro)

Network intrusion detection/prevention, traffic analysis and packet logging.


https://www.snort.org/

Zeek (formerly Bro)

Zeek (formerly Bro)

Zeek (formerly Bro)

Network intrusion detection system that provides traffic logging and analysis.


 https://zeek.org/ 

Suricata

Zeek (formerly Bro)

OSSEC (Open Source Security)

Free and open source network threat detection engine. Can use Sort rulesets.


https://suricata-ids.org/

OSSEC (Open Source Security)

OSSEC (Open Source Security)

OSSEC (Open Source Security)

Open-source host-based intrusion detection system owned by Trend Micro


https://www.ossec.net/

Sguil

OSSEC (Open Source Security)

Samhain

Security monitoring platform; only runs on tcl/tk-based operating systems. 


https://bammv.github.io/sguil/index.html

Samhain

OSSEC (Open Source Security)

Samhain

Host-based IDS, file integrity checking, log file monitoring/analysis, rootkit detection, etc...


https://www.ossec.net/

Penetration Testing

Kali Linux

Kali Linux

Kali Linux

Kali Linux is a Debian-based Linux distribution which includes various penetration testing and forensics capabilities. 


https://www.kali.org/downloads/

Burp Suite

Kali Linux

Kali Linux

  Vulnerability scanning, penetration testing, and web app security platform for applictions.


https://portswigger.net/burp/communitydownload

Metasploit

Kali Linux

Zed Attack Proxy (ZAP)

A multi-purpose hacking framework with a large suite of tools.


https://www.metasploit.com/download

Zed Attack Proxy (ZAP)

Zed Attack Proxy (ZAP)

Zed Attack Proxy (ZAP)

A web application penetration-testing tool  with both automated and manual capabilities.


https://owasp.org/www-project-zap/

w3af

Zed Attack Proxy (ZAP)

sqlmap

An attack and audit framework that identifies and exploits web application vulnerabilities. 


http://w3af.org/

sqlmap

Zed Attack Proxy (ZAP)

sqlmap

An attack tool that automates detection and exploitation SQL injection vulnerabilities.


https://sqlmap.org/

Traffic Generation

Netcat

packETH

Netcat

Utility for generating outbound and inbound network traffic - a TCP or UDP connection.


https://nc110.sourceforge.io/

Scapy

packETH

Netcat

Linux and Unix utility for packet manipulation/generation as well as network scanning/discovery and packet sniffing. 


https://scapy.net/

packETH

packETH

Colasoft Packet Builder

Linux packet generator tool for ethernet.


http://packeth.sourceforge.net/packeth/Home.html

Colasoft Packet Builder

Colasoft Packet Builder

Colasoft Packet Builder

Crafts network packets to test cyber defenses.


https://www.colasoft.com/download/products/download_packet_builder.php

WireEdit

Colasoft Packet Builder

fragroute

WYSIWYG network packets editor that supports many protocols.


https://omnipacket.com/wireedit

fragroute

Colasoft Packet Builder

fragroute

A packet crafting tool which can intercept, modify, and rewrite egress network traffic.


https://www.monkey.org/~dugsong/fragroute/

Secure Storage and Communications

OpenSSH

Tor Browser

Tor Browser

OpenSSH is a suite of secure networking utilities including traffic encryption, secure tunneling and authentication and key management. 


http://www.openssh.com/on

Tor Browser

Tor Browser

Tor Browser

A browser and associated network designed for highly anonymized communication and access to the Dark Web.


https://www.torproject.org/download/

ProtonMail

Tor Browser

ProtonMail

Free end-to-end encrypted e-mail tat leverages both RSA and AES-256 for security.


https://protonmail.com/

Signal

Telegram Messenger

ProtonMail

A centralized, end-to-end encrypted messaging and video service.


https://signal.org/en/

Telegram Messenger

Telegram Messenger

Telegram Messenger

A cloud-based instant messaging and end-to-end encrypted VoIP application.


https://telegram.org/

VeraCrypt

Telegram Messenger

Telegram Messenger

Free open source disk encryption software for Windows, Mac OSX and Linux.


https://www.veracrypt.fr/en/Home.html

Malware and Forensic Analysis

Yara

FireEye's Redline

FireEye's Redline

A malware research and detection tool that utilizes a rules to create descriptions of malware families based on textual or binary patterns.


https://virustotal.github.io/yara/

FireEye's Redline

FireEye's Redline

FireEye's Redline

Memory forensics and file analysis for malware identification.


https://www.fireeye.com/services/freeware/redline.html

ANY.RUN

FireEye's Redline

Hybrid Analysis

Malware analysis sandbox with online virtual machine (VM) access.


https://app.any.run/

Hybrid Analysis

Hybrid Analysis

Hybrid Analysis

A malware analysis service that detects and analyzes threats using CrowdStrike’s Falcon Sandbox technology.


https://www.hybrid-analysis.com/

VirusTotal

Hybrid Analysis

VirusTotal

 A malware analysis service that detects and analyzes threats against known signatures from many antivirus signatures.


https://www.virustotal.com/gui/

Autopsy

Hybrid Analysis

VirusTotal

A GUI-based open source hard drive and smart phone digital forensic tool.


http://www.sleuthkit.org/autopsy/

Copyright © 2021 RPM Consulting - All Rights Reserved.