# Cybersecurity Tools

#### Seach More

- [10 Top Open Source Penetration Testing Tools](https://www.esecurityplanet.com/applications/open-source-penetration-testing-tools/)
- [OSV-Scanner](https://osv.dev/)
- [5 Tools to Scan a Linux Server for Malware and Rootkits (tecmint.com)](https://www.tecmint.com/scan-linux-for-malware-and-rootkits/)
- [Hottest cybersecurity open-source tools of the month: May 2025 - Help Net Security](https://www.helpnetsecurity.com/2025/05/28/hottest-cybersecurity-open-source-tools-of-the-month-may-2025/)

#### Online Tools

<table class="md-table" id="bkmrk-%E7%B6%B2%E7%AB%99-%E5%8A%9F%E8%83%BD%E6%8F%8F%E8%BF%B0-shodan.io-%E6%90%9C%E7%B4%A2"><thead><tr class="md-end-block md-focus-container"><th><span class="td-span md-focus"><span class="md-plain md-expand">網站</span></span></th><th><span class="td-span"><span class="md-plain">功能描述</span></span></th></tr></thead><tbody><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">shodan.io</span></span></td><td><span class="td-span"><span class="md-plain">搜索互聯網連接設備的搜索引擎。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">censys.io</span></span></td><td><span class="td-span"><span class="md-plain">提供互聯網設備和網絡資產信息的搜索平台。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">hunter.io</span></span></td><td><span class="td-span"><span class="md-plain">查找與特定域名相關的電子郵件地址的工具。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">fullhunt.io</span></span></td><td><span class="td-span"><span class="md-plain">自動化攻擊面管理和漏洞發現平台。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">onyphe.io</span></span></td><td><span class="td-span"><span class="md-plain">網絡資產搜索和網絡安全信息收集引擎。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">socradar.io</span></span></td><td><span class="td-span"><span class="md-plain">提供實時網絡威脅情報和數字風險保護服務。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">binaryedge.io</span></span></td><td><span class="td-span"><span class="md-plain">互聯網範圍掃描和網絡風險評估平台。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">ivre.rocks</span></span></td><td><span class="td-span"><span class="md-plain">開源網絡偵察框架。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">crt.sh</span></span></td><td><span class="td-span"><span class="md-plain">搜索和查詢SSL/TLS證書的數據庫。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">vulners.com</span></span></td><td><span class="td-span"><span class="md-plain">綜合性漏洞數據庫和安全內容存儲庫。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">publicwww.com</span></span></td><td><span class="td-span"><span class="md-plain">源代碼搜索引擎,用於在網頁源碼中查找特定代碼片段。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">pulsedive.com</span></span></td><td><span class="td-span"><span class="md-plain">威脅情報和網絡安全數據聚合平台。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">intelx.io</span></span></td><td><span class="td-span"><span class="md-plain">多源開放源情報(OSINT)搜索和分析工具。</span></span></td></tr><tr class="md-end-block"><td><span class="td-span"><span class="md-plain">wigle.net</span></span></td><td><span class="td-span"><span class="md-plain">無線網絡數據庫和地圖服務。</span></span></td></tr><tr class="md-end-block md-focus-container"><td><span class="td-span"><span class="md-plain">viz.greynoise.io</span></span></td><td><span class="td-span md-focus"><span class="md-plain md-expand">分析和可視化互聯網噪聲和惡意活動的平台。</span></span></td></tr></tbody></table>

#### Vulnerability Scanner

- [OpenVAS](https://osslab.tw/books/cybersecurity/page/openvas "OpenVAS")
- [Nessus](https://osslab.tw/books/cybersecurity/page/nessus "Nessus")
- [RustScan : The Modern Port Scanner](https://github.com/RustScan/RustScan)
- [Vuls](https://vuls.io/) : Agentless Vulnerability Scanner for Linux/FreeBSD 
    - GitHub: [https://github.com/future-architect/vuls](https://github.com/future-architect/vuls)
    - [Vuls: A Free, Open Source Vulnerability Scanner for Linux - The New Stack](https://thenewstack.io/vuls-a-free-open-source-vulnerability-scanner-for-linux/)
    - [Vuls: Open-source agentless vulnerability scanner - Help Net Security](https://www.helpnetsecurity.com/2025/05/05/vuls-open-source-agentless-vulnerability-scanner/)

#### Tools

##### -Wazuh

The Open Source Security Platform

- [https://wazuh.com/](https://wazuh.com/)
- YT: [this Cybersecurity Platform is FREE](https://www.youtube.com/watch?v=i68atPbB8uQ)
- YT: [you need this FREE CyberSecurity tool](https://www.youtube.com/watch?v=3CaG2GI1kn0)
- YT: [Wazuh Open Source SIEM Tutorial - YouTube](https://www.youtube.com/watch?v=u4tMvUCUXqY)
- YT: [Wazuh! Powerful, Open Source Endpoint Security Monitoring!](https://www.youtube.com/watch?v=dwr-4CXtOso)

##### -Web Check

All-in-one OSINT tool for analysing any website

- [Web Check (web-check.xyz)](https://web-check.xyz/)
- GitHub: [https://github.com/Lissy93/web-check](https://github.com/Lissy93/web-check)

##### -OWASP: Nettacker

Automated Penetration Testing Framework (自動滲透測試框架)

- [OWASP/Nettacker: Automated Penetration Testing Framework](https://github.com/OWASP/Nettacker)

##### -WAF: Web Application Firewall

- [GoTestWAF](https://github.com/wallarm/gotestwaf)
- [Test and evaluate your WAF before hackers](https://lab.wallarm.com/test-your-waf-before-hackers/)
- [SafeLine](https://waf.chaitin.com/) - A self-hosted WAF(Web Application Firewall) 
    - YT: [SafeLine: A Feature-Rich WAF with a Catch (or Two)](https://www.youtube.com/watch?v=AwfNqWvMVTI)
- [waf-checker](https://github.com/PAPAMICA/waf-checker)

##### -Pi-Alert: WiFi/LAN 連網裝置偵測

- [Pi.Alert](https://github.com/pucherot/Pi.Alert)
- \[Video\] [Pi Alert - Open Source, Self Hosted, Network Device Change Notification and Intrusion Detection](https://www.youtube.com/watch?v=oKl3WFQloE4)

##### -WatchYourLAN

- GitHub: [https://github.com/aceberg/WatchYourLAN](https://github.com/aceberg/WatchYourLAN)

##### <span style="color: rgb(187, 187, 187); font-family: var(--font-heading, var(--font-body)); font-size: 1.4em; font-weight: 400;">-ntopng</span>

Network traffic monitor

- [ntopng – ntop](https://www.ntop.org/products/traffic-analysis/ntop/)
- YT: [NTopNG - A Free, Open Source, Self Hosted, Network Monitoring and Analysis Tool. - YouTube](https://www.youtube.com/watch?v=sJkLmjaj02E&list=PLjLkaXQ35322Of0hhUfhlMuGEl-feXZQB)

##### -ImHex: Hex Editor

A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM

- GitHub: [https://github.com/WerWolv/ImHex/](https://github.com/WerWolv/ImHex/)

##### -OSSIEM

Open Source SIEM Stack, Wazuh + Graylog + Velociraptor + Copilot

- GitHub: [https://github.com/socfortress/OSSIEM](https://github.com/socfortress/OSSIEM)

##### -Fishing Test

- [pfish](https://github.com/pow1e/pfish) - 轻量级的无害化钓鱼

##### -CISO Assistant

CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management

- GitHub: [https://github.com/intuitem/ciso-assistant-community](https://github.com/intuitem/ciso-assistant-community)

##### -Cybersecurity OS platforms

- [TOP VIRTUAL MACHINES FOR CYBERSECURITY PROFESSIONALS | by Flavio Queiroz | CTI Flash Insights | Medium](https://medium.com/cti-insights/top-virtual-machines-for-cybersecurity-professionals-b111930c2ba2)
- [Kali Linux](https://www.kali.org/)
- [ParrotOS](https://www.parrotsec.org/)

##### -MISP

MISP (Malware Information Sharing Platform)

- [https://www.misp-project.org/](https://www.misp-project.org/)