Tools starting with F
Looking for new tools to extend your tool box? The top 100 list of best security tools is a great start.
FIR (Fast Incident Response)
FIR is an incident response tool written in the Django framework. It provides a web interface to deal with the creation and management of security-related incidents.
Fail2Ban is an intrusion prevention software framework that protects computer servers from brute-force attacks
Faraday is collaboration tool for pentest assignments and vulnerability management. It allows integration with a number of other security tools.
Fierce is a security tool that helps with DNS reconnaissance. It can locate non-contiguous IP space, but using DNS information.
Findsploit is a simple script to search both local and online exploit databases. Typically this is used by penetration testers during a security assignment.
FireAway is a security tool to test the security of a firewall by trying to bypass its rules. It will use different methods to hide data or avoid detection by the firewall itself. This tool can be used for both defensive as offensive security.
FireHOL is promoted as an iptables stateful packet filtering firewall for humans. It also comes with FireQOS, which a bandwidth shaper based on tc.
Fuzzapi is a security tool to test a REST API using fuzzing. It can be used for security assessments and penetration tests.
fimap is a tool written in Python to find, prepare, audit, exploit local and remote file inclusion bugs in web applications.
Flunym0us is a security scanner for WordPress and Moodle installations. The tool tests the security of the installation by performing enumeration attempts.
The fsociety toolkit is a penetration framework containing other security tools. The project states that is includes all the tools that are used in the Mr. Robot tv series.
- OpenSCAP (suite with tools and security data)
- Lynis (security scanner and compliance auditing tool)
- BlackBox (store secrets in Git/Mercurial/Subversion)
- salt-scanner (Linux vulnerability scanner)
- Infection Monkey (security testing for data centers and networks)
- Anchore Engine (container analysis and inspection)
- Zeek (network security monitoring tool)
- ZAP (web application analysis)
- Maltrail (malicious traffic detection system)
- Wapiti (vulnerability scanner for web applications)
- Vuls (agentless vulnerability scanner)
- Cppcheck (static code analyzer)
- XSStrike (XSS detection and exploitation suite)
- Decentraleyes (local CDN emulation for privacy)
- RootHelper (script to retrieve exploitation tools)
- graudit (static code analysis tool)
- Suhosin7 (Suhosin security extension for PHP 7.x)
- gosec (Golang security checker)
- siemstress (basic SIEM solution)
- CMSeeK (CMS detection and exploitation)
- Malice (VirusTotal clone)
- Bleach (sanitizing library for Django)
- Prowler (AWS benchmark tool)
- Termineter (smart meter security framework)