
If you want to see the best free cybersecurity tools, then you’ll LOVE this article.
We at CyberX actually tested all 84 of these solutions.
If you just want to broaden your knowledge, read them all. If you are looking for something specific, use the buttons to jump to the section you need.
Enjoy:
I want Cybersecurity Tools that help with:
Networking & OS Hardening
OpenVPN
Medium Skill Level Free – Paid/Pro Version Available
OpenVPN is an open source VPN solution. The solution consists of the server component that runs at your central location and the clients that are installed on the user’s computers (????). Users can ensure that their internet traffic is protected when out of the office if they use the VPN.

Official Website: https://openvpn.net
ModSecurity
Intermediate Skill Level
ModSecurity is the “Swiss Army Knife” of web application firewalls. If you are a web application developer, you must look into this tool. Its capabilities are almost astounding. They include: real time monitoring and access control, HTTP traffic logging, continuous passive security, and web application hardening.

Official Website: https://modsecurity.org/
Two Factor Auth (2FA)
Intermediate Skill Level
Two Factor Auth is a repository tool for finding sites and apps that support multi-factor authorization. If you are deciding between sites based on 2FA, or simply want to know if a site you use supports it, check out this site.

Official Website: https://twofactorauth.org/
SafePad
Beginner Skill Level
SafePad allows you to encrypt files in which you want to store confidential information. It allows for the use of dual password/encryption key to make it even more secure.

Official Website: https://github.com/stephenhaunts/SafePad
IP Tracker Online
Intermediate Skill Level
IP Tracker Online works great if you need to investigate a suspicious email. You will need to extract the header of the email to paste in for analysis. The tool will show you the IP addresses the message has traversed to reach you.

Official Website: https://www.iptrackeronline.com
Networking & Security Auditing Tools
NMAP
Nmap the “network mapper” is a great tool for network discovery and security auditing. The tool analyzes IP packets to gain a ton of information about systems including: the services running on the system, operating system, presence and type of firewalls, and more. There is the traditional command line version, but the Zenmap graphic user interface (GUI) is a nice add-on.

Official Website: https://nmap.org/
ZENMAP
Medium Skill Level
Zenmap is the official GUI for the Nmap utility. If you prefer graphical tools over CLI (command line interface), this tool will suite you perfectly. Like Nmap, it runs on multiples operating systems. Even better, if you repeatedly perform the same scans, you can save the settings and even save and revisit the results.

Official Website: https://nmap.org/zenmap
WhatsUp Gold Starter
Intermediate Skill Level
WhatsUp Gold Starter is a free network security scanner. It can help you discover, secure, and manage the devices on your networks. You can also set up alerts for various KPIs.

Official Website: https://www.ipswitch.com/resources/free-tools/
HPing
Beginner Skill Level
As it’s name suggests, HPing is a tool for ping testing of all kinds. Unlike other ping testers, HPing can send more than just ICMP requests. Because of this, the tool can be used to test firewalls, advanced TCP stack testing and so much more.

Official Website: http://www.hping.org/
PacketFence
Medium Skill Level
If you are looking for a complete open source network security management solution, PacketFence is an option. The solution includes capabilities for: 802.1x authentication, Guest Access Portal, VLAN management, TLS traffic encryption, bandwidth management, and much more. PacketFence works with a wide range of network equipment brands making it an effective solution.

Official Website: https://packetfence.org/
Gophish
Beginner Skill Level
To assist in increasing security awareness among your organization’s users, Gophish provides a platform for phishing attack simulation. Gophish provides several great templates for phishing emails, but it also allows you to import the HTML from an email that you want to use. It tracks which users fell for the phish, allowing you to take necessary steps to re-train them before the bad guys get to them. Another amazing feature of Gophish is that you don’t have to build all the landing pages for your “attacks.” Simply put the URL into Gophish and it will import the web code and create an identical page.

Official Website: https://getgophish.com/
WireShark
Intermediate Skill Level CyberX Favorite
WireShark is one of the most used security scanning tools. If you want to understand and analyze the traffic traversing your network, you NEED to get WireShark. With just a few filters and settings, you can analyze your network traffic on a packet bases.

Official Website: https://www.wireshark.org/
Security Information and Event Management (SIEM) Tools
SIEMonster
Intermediate Skill Level
Looking for a SIEM (Security Information and Event Management) solution that will help your enterprise correlate and monitor security events on a budget? SIEMonster may be the perfect solution for you. It provides an easy to navigate console to correlate the data from an unlimited number of endpoints.

Official Website: https://siemonster.com/
Event Log Consolidator
Intermediate Skill Level
Event Log Consolidator by Solarwinds makes reviewing Windows Machine’s logs easier. You can view the logs from up to 5 machines in one place. The tool also allows you to set up alerts for certain events.

Official Website: https://www.solarwinds.com
Log Fusion
Intermediate Skill Level
LogFusion is a log management tool for Windows. It supports advanced high-lighting and customizations. You can even sync settings across computers.

Official Website: https://www.logfusion.ca/
Netwrix Event Log Manager
Intermediate Skill Level
Netwrix Event Log Manager collects event logs from across your network and sends alerts in real time.

Official Website: https://www.netwrix.com
Splunk
Intermediate Skill Level
Splunk is a well-known name in the cybersecurity tools and software industry. The free version of their SIEM tools allows for collecting and indexing of log data, visualization of trends, and is designed specifically for small offices.

Official Website: https://www.splunk.com/
LogRythm NetMon
Intermediate Skill Level
If you are looking for free cybersecurity tools to help you gain insight into the deep areas of your network, LogRythm Netmon is a tool you should consider. It can help you find anomalies in DNS, SMNP, Kerberos, and other protocols. Furthermore, Netmon allows you to log and categorize the locations your network traffic goes.

Official Website: https://logrhythm.com
CorreLog
Intermediate Skill Level
CorreLog is another free SIEM solution for monitoring security environments. The agent is light-weight and non-intrusive.

Official Website: https://correlog.com
Sumo Logic
Intermediate Skill Level
SumoLogic allows you to track and analyze various network security events in customizable dashboards. It also allows you to set up notifications to alert you should an investigation need to begin immediately.

Official Website: https://www.sumologic.com/
Alienvault OSSIM
Intermediate Skill Level CyberX Favorite
A complete SIEM and network security tool. Alienvault Ossim proactively scans your network looking for devices. The solution utilizes a client installed on monitored devices. Things that Ossim monitors include: vulnerability assessment, intrusion detection, behavioral monitoring, and SIEM correlation.

Official Website: https://www.alienvault.com
Offensive Cybersecurity Tools
Aircrack-ng
Intermediate Skill Level CyberX Favorite
If you need to harden the security of your wireless network, Aircrack-ng is likely a tool that you’ll want to look into. Aircrack captures wifi authentication segments and attempts to break the passcode.

Official Website: https://www.aircrack-ng.org/
Breach Discovery
Breach Alarm
Beginner Skill Level
Breach Alarm crawls the deep parts of the internet to discovery if your credentials have been compromised. Simply put in your email address and it will tell you whether or not you should change your password.

Official Website: https://breachalarm.com/
Have I Been Pwned?
Beginner Skill Level
Have i been pwned tracks large data breaches and crawls the internet looking for list and databases of compromised accounts. Enter your email address and it will tell you if any of your accounts have been published anywhere.

Official Website: https://haveibeenpwned.com/
Internet Security
AdBlocker
Beginner Skill Level
If you want to improve the security of your internet usage, you should look into AdBlock. Not only will it filter out those annoying ads, it will protect you from the ads that malicious users promote to infect your machines.

Official Website: https://chrome.google.com
Shrink The Web
Beginner Skill Level
While the tool is maybe not intended to be used as a cybersecurity tool, it can be a great help. If you have a suspicious link and want to check it out, simply put it in Shrink The Web and get a screenshot.

Official Website: https://www.shrinktheweb.com/
CheckShortURL
Beginner Skill Level
CheckShortURL is another of several free cybersecurity tools for checking where shortened URLs are actually taking you. Trust but verify!

Official Website: https://www.checkshorturl.com/
Browserling
Beginner Skill Level
Browserling is one of the best free internet security tools in our arsenal. Need to check out a site before visiting? Simply put the URL in Browserling and get a 3 minute remote session to check it out.

Official Website: https://www.browserling.com/
NoScript
Beginner Skill Level
NoScript is a great free internet security tool for preventing falling victim to cross-site scripting and other types of script web attacks. It works on Firefox and other Mozilla-based browsers.

Official Website: https://noscript.net/
uBlock Origin
Beginner Skill Level
UBlock is not like typical ad blockers. It Block many more types of malicious activities on the web.

Official Website: https://github.com/gorhill/uBlock
Check Short URL
Beginner Skill Level
Check Short URL works on nearly all URL shortened types and allow you to “expand” the link to find its destination.

Official Website: https://www.checkshorturl.com/
Get Link Info
Beginner Skill Level
Get Link Info is another of many free internet security tools that allow you to determine the final destination of those shortened URLs. Discover phishing attempts before you enter data!

Official Website: http://www.getlinkinfo.com/
URL2PNG
Beginner Skill Level
If you are not sure whether a link is safe or actually what it appears to be, you can uses this service to get a screenshot of it without ever visiting the questionable site.

Official Website: https://www.url2png.com/
Browser Shots
Beginner Skill Level
Browser Shots is another of the cybersecurity tools that allows you to get screenshots of a website before visiting. This can be especially useful in checking out questionable links.

Official Website: http://browsershots.org/
Screenshot Machine
Beginner Skill Level
Screenshot Machine will take a screenshot of any URL that you put in. You can then download the image and review. This is great if you want to see where a shortened URL goes.

Official Website: https://screenshotmachine.com/
Wheregoes
Beginner Skill Level
Wheregoes gives you greater insight into shortened URLs by showing you where it is taking you.

Official Website: http://wheregoes.com/
Redirect Detective
Beginner Skill Level
Redirect Detective helps you analyze short links to determine if they actually direct you to a malicious site. It’s one of the necessary cybersecurity tools necessary for safe internet usage.

Official Website: http://redirectdetective.com/
ScriptSafe
Beginner Skill Level
If you use Chrome and want to improve the security of your browser, you should look at ScriptSafe extension. It allows you to select which sites you want to trust to run scripts.

Official Website: https://chrome.google.com/webstore/
Dragon Internet Browser
Beginner Skill Level
If you are looking for a more secure internet browser, Comodo’s Dragon Internet Browser is a great choice. Not only does it offer security, it also is pretty fast.

Official Website: https://www.comodo.com
Google Chrome Cleanup Tool
Beginner Skill Level
Google Chrome Cleanup Tool is a free internet security software that Google provides for removing malware and various browser redirects. It you are having tabs or adds that won’t go away, try using these free cybersecurity tools to cleanup your browser.

Official Website: https://support.google.com/chrome/
Redirect Check
Beginner Skill Level
If you want to be sure that a site or a link is not redirecting you past a drive-by-download, you can use Redirect Check to get all the the header redirects.

Official Website: http://redirectcheck.com
Ghostery
Beginner Skill Level CyberX Favorite
Don’t like tracking cookies? Or want a little more sense of privacy on the web? Ghostery allows you to block tracking cookies and ads. You can enable them on the sites of your choice.

Official Website: https://www.ghostery.com/
HTTPS Everywhere
Beginner Skill Level CyberX Favorite
HTTPS Everywhere adds an extra layer of security to your web traffic by forcing HTTPS encrypted traffic instead of regular HTTP unencrypted traffic. This is important especially if you are visiting sites that require you to login or enter data.

Official Website: https://www.eff.org/https-everywhere
Disconnect
Beginner Skill Level
Disconnect secures your mobile devices and browsers by blocking all data from being sent in the background. You get your privacy back!

Official Website: https://disconnect.me/
Virus Total
Beginner Skill Level
Virus Total allows you to check the security of a website against over 50 malware and antivirus checks.

Official Website: https://www.virustotal.com/
Scan URL
Beginner Skill Level
Scan URL is one of the best free internet security tools for verifying the safety of a website before you visit. Scan URL will check the given website against Google Safe Browsing Diagnostic, PhishTank, Web of Trust (WOT), and several other services.

Official Website: https://scanurl.net/
Site Safety Center
Beginner Skill Level
Site Safety Center by TrendMicro is one of the largest website security scanning tools. If it hasn’t already rated a website, you can add a request.

Official Website: https://global.sitesafety.trendmicro.com/
Sucuri SiteCheck
Beginner Skill Level
Sucuri SiteCheck is a one of the best free cybersecurity tools for checking websites. When you enter a URL, it scans the site looking for malware and viruses. It also checks the site’s blacklist history before giving you a result.

Official Website: https://sitecheck.sucuri.net/
Quttera
Beginner Skill Level
If you want to check the security of a website before you visit, you can use Quttera to perform a site scan. Quttera will tell you if it detects malicious files on the site.

Official Website: http://quttera.com/
Scrim
Beginner Skill Level
Scrim allows you to share email addresses in a way that only humans can interact with. Instead of pasting your email address somewhere (where bots can collect it), you can scrim it. The receiving party will have to follow the link and verify that they are a human before seeing the email address.

Official Website: http://scr.im/
Email Security
MailWasher
Beginner Skill Level
If you are tired of spam email, or malware in your emails, you can use MailWasher to scan your emails before they are downloaded to your computer.

Official Website: https://www.mailwasher.net/
SPAMfighter
Beginner Skill Level
SPAMfilter is a free email security tool that filters your emails to identify spam and stop it from bombarding you. It is 100% free for home users.

Official Website: https://www.spamfighter.com
Spamihilator
Beginner Skill Level
Spamihilator uses several filters, a learning algorithm, and a probability calculator to determine emails that are spam. It also includes a user training area so that you can help the system better understand which emails it should block.

Official Website: https://www.spamihilator.com/en/
SpamBully
Beginner Skill Level
SpamBully is another email security tool with a TON of options. The tool uses intelligent learning to learn and block spam, allows for spam reporting to fight back at spammers (talk about bully), auto delete options and much more.

Official Website: http://www.spambully.com/
Messaging Tools – End to End Encryption
Signal
Beginner Skill Level CyberX Favorite
Signal is a complete end to end encryption messaging app. Capabilities include: encrypted video/audio calls, encrypted messaging, and timed auto-delete messages.

Official Website: https://signal.org/
Off The Record
Beginner Skill Level
Off The Record is another encrypted messaging solution available for those wanting privacy. It allows private messaging and includes: encryption, authentication, reputability, and perfect forward secrecy.

Official Website: https://otr.cypherpunks.ca/index.php
Openswan
Intermediate Skill Level
Openswan is an IPsec tool for Linux. You can use the tool to set up secure VPNs that support IKWv2, X.509 certificates, NAT traversal and more. If you run into problems, the developer is even willing to give you assistance.

Official Website: https://www.openswan.org/
Tinc
Intermediate Skill Level
Tinc is an open source VPN solution that you can use to secure your internet traffic. Using the encrypted traffic, you can share data across the internet without having to worry about it being read.

Official Website: https://www.tinc-vpn.org/
SoftEther
Intermediate Skill Level
SoftEther is another free VPN tool that you can use to secure your internet traffic. It works on Windows, Mac, iOS, and Android. SoftEther fits greatly into a BYOD environment.

Official Website: https://www.softether.org/
StrongSwan
Intermediate Skill Level
StrongSwan is a free IPsec-based VPN solutions that runs on Linux, Android, Mac, iOS, and Windows clients. Besides the regular encryption options, it supports Elliptic Curve Diffie Hellman cryptography. There’s an accompanying app for Android devices.

Official Website: https://www.strongswan.org
CyberSecurity Frameworks & Operating Systems
Kali Linux
Beginner Skill Level CyberX Favorite
Kali Linux is THE go to operating system for professionals doing any kind of work around cyber security. The operating system comes ready to go with every cybersecurity tool and capability needed to perform any kind of security work. All of the apps installed are open source. It is one of the free cybersecurity tools that I couldn’t live without.

Official Website: https://www.kali.org/
Tails
Intermediate Skill Level CyberX Favorite
“Privacy for anyone anywhere” is Tails’ motto. Tails is a Debian based operating system that focuses on privacy and anonymity. The live iso allows you to use the internet anonymously while leaving NO traces on the host computer. It also uses some of the best encryption tools to to encrypt files and communications.

Official Website: https://tails.boum.org/
Qubes
Intermediate Skill Level CyberX Favorite
Qubes is a security focused operating system. It provides security by the utilization of compartmentalization. Components of the OS and apps are compartmentalized into qubes. It also allows for the running of Windows apps on Windows App VMs.

Official Website: https://www.qubes-os.org/
Metasploit
Beginner Skill Level CyberX Favorite
Metasploit is probably one of the most well known and used penetration testing frameworks. Rapid7 calls it “The world’s most used penetration testing framework.” The framework includes a ton of exploits and payloads that you can use across all systems to gain access.

Official Website: https://www.metasploit.com/
Samurai Web Testing Framework
Intermediate Skill Level
Samurai Web Testing Framework is a complete set of tools for performing web penetration testing. It runs on Virtualbox and VMware virtual machines.

Official Website: http://www.samurai-wtf.org/
ThreadFix
Intermediate Skill Level
ThreadFix is a software vulnerability management system for developers and their security teams. The solution includes multiple components and subdirectories that make it easier and quicker to identify, track, and resolve software vulnerabilities during the software development lifecycle.

Official Website: https://github.com/denimgroup/threadfix
OWASP Python Security Project
Intermediate Skill Level
This open source solution is built to aid python developers in creating programs and apps that are more resilient to attacks. Python Security Project does this by hardening key components of the python framework.

Official Website: http://www.pythonsecurity.org/
Free Cybersecurity Tools for Reconaissance
TheHarvester
Intermediate Skill Level
Can’t have too many cybersecurity tools for reconnaissance can you? A successful attack begins with thorough recon right? TheHarvester, by Kali, is another tool to add to your toolkit. It will assist in gathering domains, email addresses, employee names, SHODAN info and more.

Official Website: https://tools.kali.org/information-gathering/theharvester
Fierce Domain Scanner
Intermediate Skill Level
Fierce domain scanner is kind of a pre-reconnaissance tool. It was created by David Pepper due to his frustration with other network recon tools that only work on contiguous IP ranges. Fierce Domain Scanner works by using DNS to find other IP ranges associated with the domain.

Official Website: https://fierce.pl
Maltego
Intermediate Skill Level
If you do reconnaissance for penetration testing or just counter surveillance, you’ll love maltego. This tool can assist you in uncovering large amounts of data about your targets. Maltego can find everything from IP addresses, domain names, and DNS entries, to employee email addresses.

Official Website: https://www.paterva.com
Vulnerability Scanning Tools
OWASP Zed Attack Proxy Project (ZAP)
Intermediate Skill Level
When it comes to testing the security of web apps that you have developed or need to verify the security of, ZAP is one of the most common tools. This completely open source, cross-platform tools allows you to perform both active and passive scan of the web app and even includes spiders that are able to crawl it. ZAP will generate reports on its finds and has several components that can be added on.

Official Website: https://www.zaproxy.org/
CVE Details
Intermediate Skill Level
CVE Details gives you information about CVEs. Simply perform a search based on CVE number, vulnerability category, or vendor, and get lots of great info!

Official Website: https://www.cvedetails.com/
Burp Suite
Intermediate Skill Level CyberX Favorite
If you’re looking to perform automated vulnerability scanning of web apps, you NEED to check out burp suite. The tool uses numerous components to test all features of web apps. If you know Java, Python, or Ruby, you can create your own extensions as well.

Official Website: https://portswigger.net/burp
Nessus
Beginner Skill Level CyberX Favorite
Nessus is a vulnerability scanner of choice. It allows you to perform thorough scans of a network to identify vulnerabilities. The home edition is free and can be used on up to 16 IP addresses.

Official Website: https://www.tenable.com/nessus
Malwarebytes
Beginner Skill Level CyberX Favorite
Malwarebytes is a free malware removal software that has been around for quite a while. That said, it works great!

Official Website: https://www.malwarebytes.com/
Password Management, Recovery & Attack Tools
Cain and Abel
Intermediate Skill Level
Cain and Abel is one of the more well know free cybersecurity tools for password recovery. The tool, built for the Microsoft OS, allows for the recovery or discovery of passwords using a variety of methods including network sniffing, brute force and dictionary attacks.

Official Website: http://www.oxid.it
Thycotic Secret Server
Intermediate Skill Level
Secret Server is an advanced password manager tool that is especially useful for IT team administrators. Secret server allows IT team managers to track which team members have access to which passwords and change them when necessary. Like other password managers, the tool allows you to create strong passwords without being forced to memorize them.

Official Website: https://thycotic.com
LastPass
Beginner Skill Level CyberX Favorite
Proper password practices are a foundation of security, right? But remembering so many complex passwords is hard! LastPass will make using strong passwords a breeze! No need to come up with and remember so many hard passwords. LastPass does all of the work for you.

Official Website: https://www.lastpass.com/
KeePass
Beginner Skill Level
If you are looking for a password management tool but don’t quite trust storing that data in the cloud, KeePass is a solution for you. The open source tool allows you to manage all of your passwords without having to remember them or write them down.

Official Website: https://keepass.info/
DUO
Beginner Skill Level
DUO is a great two factor authentication solution that you can use to enforce an added layer of security in your environment. It’s free for up to ten users and can be used to secure numerous platforms including Microsoft products, LastPass, Cisco, Juniper, WordPress, and many more.

Official Website: https://duo.com/
Sticky Password
Beginner Skill Level
Sticky Password is another of many cybersecurity tools for managing multiple passwords. An added benefit that it offers is the ability to remember about populate form fields. No more need to manually fill in forms!

Official Website: https://www.stickypassword.com/
Ophcrack
Beginner Skill Level CyberX Favorite
Ophcrack is a password cracker for Windows that works by utilizing rainbow tables. The graphical user interface makes it very easy to use. It is especially useful for recovering forgotten Windows passwords.

Official Website: http://ophcrack.sourceforge.net/
John the Ripper
Intermediate Skill Level
John the Ripper is one of the cybersecurity tools for password cracking that most security people have heard of. The tool is a password cracker that works on most familiar operating systems: Linux, Android, MacOS, and Unix.

Official Website: http://www.openwall.com/john/
So…What Are Your Thoughts?
Now we want to hear from you.
What are your thoughts on this list?
Is there another free cybersecurity tool that we missed?
Please:
Let us know by leaving a comment below.
I feel like you should mention that only Nessus Home is free and it’s limited to 16 ip’s
You’re right @TenableGuy. Edited. Thanks for the suggestion. That is an important point to make.
you can talk about Hackmetrix, it integrates the best open source scanners in a user friendly interface
Thanks Adriel. I’ve never heard of hackmetrix. I’ve got my scan scheduled!
Centrify has many free tools under the “ Express” label. SSO, AD bridging, Privilege, and more.
Terry, thanks for the tip. That looks REALLY interesting. I’ll definitely be giving it a try.