Cybersecurity Tools
Cybersecurity Tools tools -- a subcategory of Security & Authentication
Replace Popular SaaS
45 Tools
Web-Check
32KAll-in-one OSINT tool for analyzing any website. Discover security, performance, and technology insights.
Nuclei
28KYAML-template-driven vulnerability scanner with 8,000+ community templates for CVEs, misconfigurations, and exposed panels — free for core scanning.
KeePassXC
26KKeePassXC is a self-hosted password managers replacement for 1Password, Dashlane, and more.
Infisical Community Edition
25KEnd-to-end encrypted platform for managing secrets, certificates, and SSH keys across development workflows.
Matomo
21KThe Google Analytics replacement that actually owns its data story — 1.4 million websites trust it because there is no other way for data to leave.
Authentik
21KAuthentik is a self-hosted authentication & SSO tool with support for Authentication, Identity Management, security.
Fail2Ban
17KDaemon to ban hosts that cause multiple authentication errors - fail2ban/fail2ban
Bytebase
14KBytebase lets you run comprehensive platform for database schema migrations entirely on your own server.
OpenVPN
13KOpenVPN gives you secure remote access VPN solutions on your own infrastructure.
CrowdSec
13KCrowdSec lets you run participative protection against malicious IPs entirely on your own server.
Zero
10KFor privacy & encryption, Zero is a self-hosted solution that provides email application.
BunkerWeb
10KBunkerWeb gives you web Application Firewall (WAF) that will protect your web services on your own infrastructure.
Firezone
8.5KReleased under Apache-2.0, Firezone provides replace your VPN on self-hosted infrastructure.
Tuta
7.4KTuta is a self-hosted privacy & encryption tool with support for privacy, security, email.
Clamav
6.4KClamav handles antivirus engine for detecting malicious threats as a self-hosted solution.
Permify
5.8KPermify is a self-hosted cybersecurity tools tool that provides authorization service for implementing fine-grained access controls. Centralized.
Cosmos
5.8KCosmos is a JavaScript-based application that provides complete self-hosting solution.
Passbolt
5.8KPassbolt is a self-hosted authentication & SSO replacement for 1Password, Authy, and more.
BleachBit
4.5KBleachBit lets you run frees disk space & protects privacy by deleting cache entirely on your own server.
Cerbos
4.3KCerbos is a self-hosted authentication & SSO replacement for AWS Cognito, Auth0, and more.
Tracecat
3.5KReleased under AGPL-3.0, Tracecat provides scalable, self-hostable platform for automating security workflows and playbooks without limits on self-hosted...
Password Pusher
2.9KReleased under Apache-2.0, Password Pusher provides dead-simple application to communicate passwords (or text) over the web. Passwords automatically on...
Defguard
2.7KFor authentication & SSO, Defguard is a self-hosted solution that provides enterprise-grade VPN solution combining WireGuard.
Peergos
2.4KReleased under AGPL-3.0, Peergos provides secure and private space online where you can store on self-hosted infrastructure.
Comp AI
1.4KFor cybersecurity tools, Comp AI offers a self-hosted way to get SOC 2, ISO 27001 or HIPAA compliant in 4 weeks. Transparent, automated, and cost-effective.
Tailcall
1.4KTailcall is a self-hosted cybersecurity tools tool with support for security, GRAPHQL, cloud native.
tirreno
1.2KTirreno lets you run security framework for threat detection entirely on your own server.
Phase
838Phase handles platform for engineering teams to manage secrets and environment variables from development as a self-hosted solution.
Keyshade
747Keyshade is a TypeScript-based application that provides secure secret management platform.
GoAway
692GoAway handles lightweight DNS sinkhole for blocking unwanted domains as a self-hosted solution.
Double Take
687Released under MIT, Double Take provides unified UI and API for processing and training images for facial recognition on self-hosted infrastructure.
Cert Warden
497For proxy servers, Cert Warden is a self-hosted solution that provides centralized certificate management for secure infrastructure.
Shelve
390Shelve lets you run comprehensive project management tool designed to streamline workflows and enhance collaboration entirely on your own server.
VaulTLS
330VaulTLS handles mTLS certificate manager as a self-hosted solution.
Fail2Ban-Report
306For log management, Fail2Ban-Report is a self-hosted solution that provides web-based dashboard for Fail2Ban logging.
Procaptcha
299Procaptcha lets you run blockchain-based CAPTCHA solution offering improved security entirely on your own server.
Secrover
246Released under GPL-3.0, Secrover provides security reports on self-hosted infrastructure.
Openlane
225Self-hosted cybersecurity tools tool that provides comprehensive platform for automating compliance workflows.
mkcert Web UI
206For cybersecurity tools, mkcert Web UI is a self-hosted solution that provides modern web interface for mkcert.
Ackify
197Released under AGPL-3.0, Ackify provides proof of read platform for internal documents on self-hosted infrastructure.
PortChecker
182PortChecker lets you run port status queries for provided hostnames or IP addresses entirely on your own server.
Aikido Intel
179For cybersecurity tools, Aikido Intel is a self-hosted solution that provides comprehensive threat intelligence platform.
Werbot
169Werbot lets you run centralized platform for managing SSH access entirely on your own server.
Private Captcha
157Private Captcha is a Go-based application that provides privacy-first CAPTCHA service.
PWgen
85PWgen handles secure password generator with customizable options as a self-hosted solution.
Why Self-Host Your Cybersecurity Tools?
Commercial security platforms like Splunk, DataDog Security, and CrowdStrike cost thousands monthly and require sending your security telemetry — logs, vulnerability scans, network traffic analysis — to external servers. This creates an ironic situation: the tools meant to protect your infrastructure require you to expose sensitive operational data to a third party. Self-hosted security tools analyze threats on your own infrastructure.
Fail2ban and CrowdSec form the first line of defense, automatically blocking IP addresses that show malicious behavior like brute-force attacks or vulnerability scanning. BunkerWeb provides a web application firewall (WAF) with bot detection and rate limiting. Nuclei runs vulnerability scans against your infrastructure using community-maintained detection templates. ClamAV provides antivirus scanning for files and email attachments. For network security, Firezone and OpenVPN create encrypted tunnels, while GoAway detects and blocks malicious bots and scrapers.
Password and secrets management is a critical security layer. KeePassXC provides offline password management, while Passbolt enables team password sharing with fine-grained access controls. Infisical Community Edition manages application secrets and environment variables across deployments. For identity security, Authentik and Defguard handle authentication and access control. Tracecat provides security incident response automation, CrowdSec shares threat intelligence across installations, and Comp-AI helps with compliance documentation. The breadth of this category — from ClamAV virus scanning to Cert-Warden TLS certificate management — means you can build a complete security stack without relying on commercial vendors who charge per endpoint, per GB, or per user.