Tools starting with F
Looking for new tools to extend your tool box? The top 100 list of best security tools is a great start.
Fail2Ban is an intrusion prevention software framework that protects computer servers from brute-force attacks
Faraday is collaboration tool for pentest assignments and vulnerability management. It allows integration with a number of other security tools.
Fierce is a security tool that helps with DNS reconnaissance. It can locate non-contiguous IP space, but using DNS information.
fimap is a tool written in Python to find, prepare, audit, exploit local and remote file inclusion bugs in web applications.
Findsploit is a simple script to search both local and online exploit databases. Typically this is used by penetration testers during a security assignment.
FIR (Fast Incident Response)
FIR is an incident response tool written in the Django framework. It provides a web interface to deal with the creation and management of security-related incidents.
FireAway is a security tool to test the security of a firewall by trying to bypass its rules. It will use different methods to hide data or avoid detection by the firewall itself. This tool can be used for both defensive as offensive security.
FireHOL is promoted as an iptables stateful packet filtering firewall for humans. It also comes with FireQOS, which a bandwidth shaper based on tc.
Flunym0us is a security scanner for WordPress and Moodle installations. The tool tests the security of the installation by performing enumeration attempts.
The fsociety toolkit is a penetration framework containing other security tools. The project states that is includes all the tools that are used in the Mr. Robot tv series.
Fuzzapi is a security tool to test a REST API using fuzzing. It can be used for security assessments and penetration tests.
- Maltrail (malicious traffic detection system)
- Wapiti (vulnerability scanner for web applications)
- Vuls (agentless vulnerability scanner)
- Cppcheck (static code analyzer)
- Zeek (network security monitoring tool)
- XSStrike (XSS detection and exploitation suite)
- Decentraleyes (local CDN emulation for privacy)
- RootHelper (script to retrieve exploitation tools)
- graudit (static code analysis tool)
- Suhosin7 (Suhosin security extension for PHP 7.x)
- gosec (Golang security checker)
- siemstress (basic SIEM solution)
- Malice (VirusTotal clone)
- Bleach (sanitizing library for Django)
- CMSeeK (CMS detection and exploitation)
- BDA (vulnerability scan for Hadoop and Spark)
- radare2 (reverse engineering tool and binary analysis)
- Malscan (malware scanner for web servers)
- Termineter (smart meter security framework)
- massh-enum (OpenSSH user enumeration)
- GitMiner (Git data miner)
- Hash Buster (find cleartext of hash)
- CMSmap (reconnaissance tool for popular CMS frameworks)
- Cutter (graphical user interface for radare2)