Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: defensive (37)

Pentesting tools tagged defensive. See all tools or the category key.

Team (best effort)

arpon

A host-based solution to secure the ARP protocol and prevent MITM attacks via ARP spoofing or cache poisoning.

defensive Blue Team

arpstraw

Arp spoof detection tool.

defensive Blue Team

artillery

Blue team tool designed to protect Linux and Windows operating systems through multiple methods.

defensive Blue Team

artlas

Apache Real Time Logs Analyzer System.

defensive Blue Team

capa

The FLARE team's open-source tool to identify capabilities in executable files.

defensive Blue Team

detect-sniffer

Tool that detects sniffers in the network.

defensive Blue Team

fastnetmon

High performance DoS/DDoS load analyzer built on top of multiple packet capture engines.

defensive Blue Team

fssb

A low-level filesystem sandbox for Linux using syscall intercepts.

defensive Blue Team

honeycreds

Network credential injection to detect responder and other network poisoners.

defensive Blue Team

ifchk

A network interface promiscuous mode detection tool.

defensive Blue Team

jeopardize

A low(zero) cost threat intelligence & response tool against phishing domains.

defensive Blue Team

lorg

Apache Logfile Security Analyzer.

defensive Blue Team

malice

VirusTotal Wanna Be - Now with 100% more Hipster.

defensive Blue Team

malmon

Hosting exploit/backdoor detection daemon.

defensive Blue Team

maltrail

Malicious traffic detection system.

defensive Blue Team

mat

Metadata Anonymisation Toolkit composed of a GUI application, a CLI application and a library.

defensive Blue Team

munin-hashchecker

Online hash checker for Virustotal and other services

defensive Blue Team

nipe

A script to make Tor Network your default gateway.

defensive Blue Team

orjail

A more secure way to force programs to exclusively use tor network.

defensive Blue Team

osfooler-ng

Prevents remote active/passive OS fingerprinting by tools like nmap or p0f.

defensive Blue Team

persistencesniper

Hunt persistences implanted in Windows machines.

defensive Blue Team

procscope

Process-scoped runtime investigation tool using eBPF.

defensive Blue Team

prowler

Tool for AWS security assessment, auditing and hardening.

defensive Blue Team

quicksand-lite

Command line tool for scanning streams within office documents plus xor db attack.

defensive Blue Team

sigma

Generic Signature Format for SIEM Systems

defensive Blue Team

sooty

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

defensive Blue Team

suricata

An Open Source Next Generation Intrusion Detection and Prevention Engine.

defensive Blue Team

tabi

BGP Hijack Detection.

defensive Blue Team

tfsec

Security scanner for your Terraform code.

defensive Blue Team

threatspec

Project to integrate threat modelling into development process.

defensive Blue Team

tor-autocircuit

Tor Autocircuit was developed to give users a finer control over Tor circuit creation. The tool exposes the functionalit

defensive Blue Team

tor-browser

Tor Browser Bundle: anonymous browsing using Firefox and Tor.

defensive Blue Team

tor-router

A tool that allow you to make TOR your default gateway and send all internet connections under TOR (as transparent proxy

defensive Blue Team

tyton

Kernel-Mode Rootkit Hunter.

defensive Blue Team

usb-canary

A Linux or OSX tool that uses psutil to monitor devices while your computer is locked. In the case it detects someone pl

defensive Blue Team

yeti

A platform meant to organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified

defensive Blue Team

zeus

AWS Auditing & Hardening Tool.

defensive Blue Team