Open Source Cybersecurity Tools Directory
Explore the curated index of authoritative open-source security projects, OSINT scripts, and core threat scanning databases. Supported by the ReconShield security research community.
Critical Security Disclaimer & Ethical Usage
All tools cataloged within this directory must be used strictly for ethical security auditing, authorized vulnerability testing, and educational research purposes. Executing active scans, port sweeps, or exploit probes against network infrastructures without explicit, written authorization from the asset owner is illegal and constitutes a violation of computer security laws (such as the US Computer Fraud and Abuse Act - CFAA). Users are fully responsible for ensuring compliance with local legal frameworks prior to launching scanning routines.
ReconShield Open Source Repositories
Security Headers Knowledge Base
Community-driven configuration templates, validation rules, and parser specifications for security headers (CSP, HSTS, XFO).
SSL/TLS Knowledge Base
Handshake profiling scripts, cipher suite risk classifications, and CA trust root verification databases.
Port Security Knowledge Base
Standard service banner signatures, risk metrics, and firewall configuration syntax definitions (UFW/iptables).
Subdomain Intelligence Knowledge Base
Passive enumeration heuristics, Certificate Transparency log parsers, and dangling DNS takeover templates.
Curated Industry-Standard Security Directory
OSINT (Open Source Intelligence) Tools
SpiderFoot
GithubAn automated OSINT reconnaissance tool that integrates with over 100 public data sources to gather intelligence on IPs, domain names, e-mails, and netblocks.
Recon-ng
GithubA full-featured Web-based Reconnaissance Framework written in Python, complete with independent modules, database interaction, and API integrations.
DNS & Domain Mapping Tools
OWASP Amass
GithubIn-depth DNS active and passive subdomain enumeration, mapping, and attack surface discovery using open-source data aggregation.
dnsrecon
GithubA powerful Python script used to perform DNS zone transfers, PTR record checks, wildcard resolution detection, and SRV record enumeration.
Email Security & Authentication Tools
SPF-Tools
GithubA suite of Python scripts designed to parse, analyze, and test SPF records, assisting in resolving lookup limits and syntax structure errors.
DKIMpy
GithubA Python library that implements DomainKeys Identified Mail (DKIM) and Author Domain Signing Practices (ADSP) signature verification and generation.
Vulnerability Scanners
Nuclei
GithubA fast and customizable vulnerability scanner based on simple YAML templates, allowing researchers to target specific CVE indicators.
OWASP ZAP (Zed Attack Proxy)
GithubA popular, open-source web application security testing utility designed to locate vulnerabilities like SQL injection and XSS.
Threat Intelligence Tools
MISP (Malware Information Sharing Platform)
GithubAn open-source threat intelligence platform used to share, store, and correlate Indicators of Compromise (IoCs) of targeted attacks.
OpenCTI
GithubA modern threat intelligence platform designed to structure, store, and visualize technical and tactical threat intelligence data.
Reconnaissance & Network Auditing Tools
Nmap (Network Mapper)
GithubThe industry-standard open-source network scanner used for host discovery, port scanning, OS identification, and service version checks.
Masscan
GithubAn extremely fast internet port scanner that transmits SYN packets asynchronously, capable of scanning the entire internet in under 6 minutes.
Contributor Covenant Guidelines
We welcome code reviews, issue alerts, and database updates. Please read our official contributor guidelines within the respective repository. Keep pull requests focused on adding vulnerability indicators, fixing documentation discrepancies, or extending Nginx/Apache configuration snippets.
MIT Licensing & Standard Permissions
All databases are free to copy, modify, distribute, and include in commercial applications. We believe that open access to cybersecurity signatures and standards is essential to secure modern digital ecosystems.