Directory

Cybersecurity Tools

35 tools across 7 categories

SIEM & Log Management Paid

Splunk

Industry-leading SIEM platform used by thousands of organizations for security monitoring, log management, and threat detection. Ingests and correlates massive volumes of machine data to surface threats in real time.

SIEMLog ManagementEnterprise
SIEM & Log Management Paid

IBM QRadar

Enterprise SIEM solution that uses AI and advanced analytics to detect threats and prioritize incidents. Delivers full visibility across on-premises and cloud environments with strong compliance reporting.

SIEMAIEnterprise
SIEM & Log Management Paid

Microsoft Sentinel

Cloud-native SIEM and SOAR solution built on Azure. Uses AI to detect and respond to threats across the entire enterprise with seamless Microsoft ecosystem integration and built-in SOAR capabilities.

SIEMSOARCloud
SIEM & Log Management Open Source

Elastic Security

Combines SIEM, endpoint protection, and threat hunting on the Elastic Stack. Offers a powerful open-source foundation with enterprise support options for scaling detection and response across hybrid environments.

SIEMOpen SourceElastic Stack
SIEM & Log Management Open Source

Wazuh

Free, open-source security platform that unifies XDR and SIEM capabilities. Provides threat detection, integrity monitoring, incident response, and compliance across cloud, hybrid, and on-premises environments.

SIEMXDROpen Source
EDR & Endpoint Paid

CrowdStrike Falcon

AI-native endpoint security platform with real-time threat detection and response. Cloud-delivered architecture enables lightweight agents with powerful protection across all endpoints and workloads.

EDRAICloud
EDR & Endpoint Paid

SentinelOne

Delivers autonomous endpoint protection with AI-powered prevention, detection, and response. The Singularity platform extends XDR across endpoints, cloud, and identity with fully automated threat remediation.

EDRXDRAI
EDR & Endpoint Paid

Microsoft Defender for Endpoint

Enterprise endpoint security platform offering preventative protection, post-breach detection, and automated response. Integrates deeply with the Microsoft 365 security ecosystem for unified visibility.

EDRMicrosoftEnterprise
EDR & Endpoint Paid

VMware Carbon Black

Next-generation endpoint and workload security with behavioral analytics. Cloud-native platform delivers continuous endpoint visibility and advanced threat detection for modern enterprise environments.

EDRBehavioral AnalyticsCloud
EDR & Endpoint Paid

Malwarebytes for Teams

Endpoint detection and response for businesses of all sizes. Combines advanced malware detection with EDR capabilities, making enterprise-grade security accessible to smaller teams without heavy infrastructure.

EDRSMBMalware Detection
Vulnerability Management Freemium

Tenable Nessus

World's most widely deployed vulnerability scanner. Identifies software vulnerabilities, misconfigurations, and malware across physical, virtual, cloud, and OT environments with 100,000+ plugins.

Vulnerability ScannerComplianceNetwork Security
Vulnerability Management Paid

Qualys VMDR

Cloud-based vulnerability management, detection, and response platform. Provides continuous visibility into the risk posture and automates the remediation lifecycle across hybrid IT environments.

Vulnerability ManagementCloudEnterprise
Vulnerability Management Paid

Rapid7 InsightVM

Live vulnerability management with real-time risk assessment. Integrates with remediation workflows and offers attacker analytics to prioritize the vulnerabilities that pose the greatest business risk.

Vulnerability ManagementReal-timeRisk Assessment
Vulnerability Management Open Source

OpenVAS

Full-featured open-source vulnerability scanner and manager. Part of the Greenbone Vulnerability Management framework, it runs over 100,000 vulnerability tests and is widely used in security labs and enterprises.

Vulnerability ScannerOpen SourceFree
Vulnerability Management Freemium

Burp Suite

Leading web application security testing platform used by security professionals worldwide. Provides a comprehensive toolkit for manual and automated web app vulnerability testing and penetration testing.

Web App SecurityPenetration TestingManual Testing
Identity & Access (IAM/PAM) Paid

Okta

Leading identity and access management platform providing secure SSO, MFA, and lifecycle management. Connects workforce to apps and devices with zero trust principles across cloud and on-premises environments.

IAMSSOMFA
Identity & Access (IAM/PAM) Paid

CyberArk

Global leader in privileged access management, protecting organizations against attacks that leverage privileged credentials. Platform secures both human and machine identities across the enterprise.

PAMPrivileged AccessEnterprise
Identity & Access (IAM/PAM) Paid

BeyondTrust

Comprehensive privileged access security with solutions for PAM, endpoint privilege management, and secure remote access. Minimizes the attack surface from insider threats and external attackers.

PAMPrivileged AccessRemote Access
Identity & Access (IAM/PAM) Open Source

HashiCorp Vault

Tool for securely accessing secrets — API keys, passwords, certificates, and encryption keys. Provides a unified interface for dynamic secret generation, data encryption, and identity-based access.

Secrets ManagementDevSecOpsOpen Source
Identity & Access (IAM/PAM) Paid

Ping Identity

Enterprise identity security with intelligent SSO, MFA, and API security. Supports complex hybrid environments and delivers frictionless user experiences at enterprise scale.

IAMSSOMFA
Cloud Security (CSPM) Paid

Prisma Cloud

Palo Alto Networks' comprehensive cloud-native security platform offering CSPM, workload protection, and application security across AWS, Azure, GCP, and hybrid environments.

CSPMCloud SecurityCWPP
Cloud Security (CSPM) Paid

Wiz

Cloud security platform providing full-stack visibility and risk assessment without agents. Connects via API to cloud environments and surfaces critical risks across misconfigurations, vulnerabilities, and data exposure.

CSPMAgentlessCloud Security
Cloud Security (CSPM) Paid

Lacework

AI-driven cloud security platform providing CSPM, CWPP, and cloud detection and response. Polygraph technology builds behavioral baselines to detect anomalous activity across cloud environments.

CSPMCWPPAI
Cloud Security (CSPM) Paid

Aqua Security

Platform for securing cloud-native applications across containers, Kubernetes, VMs, and serverless. Provides vulnerability scanning, runtime protection, and supply chain security for modern cloud workloads.

Container SecurityKubernetesCloud-Native
Cloud Security (CSPM) Paid

Orca Security

Agentless cloud security platform that detects risks across your entire cloud estate without blind spots. SideScanning technology reads cloud workload runtime blocks directly from the cloud provider.

CSPMAgentlessCloud Security
AppSec Testing (SAST/DAST/SCA) Paid

Checkmarx

Leading application security platform offering SAST, DAST, SCA, and API security testing. Integrates into CI/CD pipelines to shift security left and deliver secure software at enterprise scale.

SASTDASTSCA
AppSec Testing (SAST/DAST/SCA) Paid

Veracode

Intelligent software security platform providing SAST, DAST, SCA, and penetration testing. Uses machine learning to surface exploitable vulnerabilities and guide developers through remediation.

SASTDASTSCA
AppSec Testing (SAST/DAST/SCA) Freemium

Snyk

Developer-first security platform that finds and fixes vulnerabilities in open source dependencies, container images, infrastructure as code, and application code. Integrates directly into developer workflows.

SCADeveloper SecurityOpen Source
AppSec Testing (SAST/DAST/SCA) Open Source

SonarQube

Leading platform for continuous inspection of code quality and security. Performs static analysis to detect bugs, code smells, and security vulnerabilities across 30+ programming languages.

SASTCode QualityOpen Source
AppSec Testing (SAST/DAST/SCA) Open Source

OWASP ZAP

World's most widely used open-source web application security scanner. Ideal for developers and security engineers to find vulnerabilities in web apps during active development and CI/CD pipelines.

DASTOpen SourceFree
Threat Intelligence Paid

Recorded Future

World's largest threat intelligence company providing real-time intelligence powered by machine learning. Aggregates data from open web, dark web, and technical sources to surface actionable, contextualized intelligence.

Threat IntelligenceDark WebMachine Learning
Threat Intelligence Paid

ThreatConnect

Threat intelligence platform that enables security teams to aggregate, analyze, act on, and share intelligence. Supports both tactical and strategic operations with built-in SOAR capabilities.

Threat IntelligenceTIPSOAR
Threat Intelligence Paid

Anomali

Threat intelligence platform enabling security teams to identify threats and automate detection. Matches IOCs against historical and real-time telemetry to pinpoint active compromises at enterprise scale.

Threat IntelligenceIOCTIP
Threat Intelligence Freemium

VirusTotal

Free online service that analyzes files, URLs, domains, and IP addresses for malware and malicious content using 70+ antivirus scanners and domain blocklists. Owned by Google, trusted by security teams worldwide.

Malware AnalysisFreeIOC
Threat Intelligence Paid

Mandiant Advantage

SaaS threat intelligence platform backed by Mandiant's elite incident response experience. Provides validated, frontline intelligence to accelerate detection and response for enterprise security teams.

Threat IntelligenceSaaSEnterprise

Security Matchmaking

Not sure who to hire for your security work?

We act as your liaison. Tell us your scope, budget, location, and expertise requirements — we find the best-fit vendor or consultant and handle the introduction. This service is completely free for you. We charge the company side only, on a successful match.

No commitment. We scope it together, then find your match.