Resources

Security Tool Directory

A curated list of low- and no-cost security tools for small and mid-sized businesses. Use this with your MSP or IT provider to strengthen backup, MFA, DNS filtering, email security, patching, monitoring, and more.

How to use this page

Filter by category, search by platform/purpose, then open the tool website to evaluate fit. Later, this will auto-populate “Consider Tools” inside the Risk Workspace.

Tip: keep your “primary CTA” orange. Everything else stays calm.

Browse tools

Showing 90 of 90 tools.

Search by name, purpose, or platform. Filter by canonical categories.

Showing 90 of 90 tools.

Specops Password Auditor

Free

Platform: Windows

Audits Active Directory passwords.

Identity, MFA & Passwords
Official site availableVisit website →

Hugging Face Model Hub

Free

Platform: Cloud, API

Repository of open-source ML models to explore, test, and adopt AI responsibly.

AI & LLM Security
Official site availableVisit website →

Microsoft Defender

Free

Platform: Windows, macOS, Linux

Built-in endpoint protection.

Endpoint Security & EDR
Official site availableVisit website →

OpenAPI.Security

Free

Platform: Cloud, API

Scans REST APIs from OpenAPI specs for auth issues, injection, data leakage, and misconfigurations.

API Security
Official site availableVisit website →

Noname API Security

Paid

Platform: Cloud

API security discovery and protection.

API Security
Official site availableVisit website →

Salt Security

Paid

Platform: Cloud

API security with discovery, posture management, and runtime protection.

API Security
Official site availableVisit website →

Cequence Security

Paid

Platform: Cloud

API security platform with bot mitigation and API protection.

API Security
Official site availableVisit website →

PromptShield

Free

Platform: Cloud-based

Protects AI/LLM apps by monitoring prompts, generating safety rules, analyzing risks, and defending against prompt injection.

AI & LLM Security
Official site availableVisit website →

OpenAI Moderation

Free Tier

Platform: Cloud, API

Content moderation API to detect hate, harassment, violence, sexual content, and more in text or images.

AI & LLM Security
Official site availableVisit website →

Nightfall AI

Paid

Platform: Cloud

Cloud-native DLP and sensitive data detection for SaaS, LLMs, and cloud apps.

AI & LLM Security
Official site availableVisit website →

Check Point Harmony Email & Collaboration

Paid

Platform: Cloud

Secures email and collaboration apps against phishing, malware, account takeover, and data loss.

Email Security
Official site availableVisit website →

IRONSCALES

Paid

Platform: Cloud

AI-powered email security platform focused on phishing detection and user reporting.

Email Security
Official site availableVisit website →

Cofense PhishMe

Paid

Platform: Cloud

Phishing simulation and training platform.

Security Awareness & Phishing Training
Official site availableVisit website →

KnowBe4 Security Awareness Training

Paid

Platform: Cloud

Security awareness training with phishing simulations and education for employees.

Security Awareness & Phishing Training
Official site availableVisit website →

PhishingBox

Paid

Platform: Cloud

Phishing simulation and training for end users.

Security Awareness & Phishing Training
Official site availableVisit website →

Let’s Encrypt

Free

Platform: Linux, Web Servers

Free, automated, and open certificate authority for HTTPS/TLS.

Certificates & TLS
Official site availableVisit website →

SSL Labs Server Test

Free

Platform: Web-based

Analyzes SSL/TLS configuration of public web servers.

Certificates & TLS
Official site availableVisit website →

Microsoft LAPS

Free

Platform: Windows

Local Administrator Password Solution for rotating local admin passwords.

Identity, MFA & Passwords
Official site availableVisit website →

Netwrix Password Secure

Paid

Platform: Windows, macOS, Browser

Password manager with secure vault and role-based access.

Identity, MFA & Passwords
Official site availableVisit website →

CrowdStrike Falcon Complete

Paid

Platform: Cloud, Endpoint

Managed detection and response (MDR) for CrowdStrike Falcon deployments.

SOC & MDR Services
Official site availableVisit website →

Cloudflare DNS

Free

Platform: Network, Cloud

Privacy-focused public DNS with built-in security filtering.

DNS & Web Filtering
Official site availableVisit website →

Quad9 DNS

Free

Platform: Network

Security-focused DNS service that blocks known malicious domains.

DNS & Web Filtering
Official site availableVisit website →

OpenDNS Home (Cisco)

Free

Platform: Network

DNS-based content filtering for home and small networks.

DNS & Web Filtering
Official site availableVisit website →

Microsoft Defender for Cloud Apps

Paid

Platform: Cloud

SaaS security posture management and app discovery.

Cloud & SaaS Security
Official site availableVisit website →

BetterCloud

Paid

Platform: Cloud

SaaS operations and security platform for managing data and access across apps.

Cloud & SaaS Security
Official site availableVisit website →

AppOmni

Paid

Platform: Cloud

SaaS security posture management for enterprise applications.

Cloud & SaaS Security
Official site availableVisit website →

THOR Home Free

Free

Platform: Windows

Free, reduced version of THOR for endpoint threat hunting.

Endpoint Security & EDR
Official site availableVisit website →

Nextron THOR

Paid

Platform: Windows, Linux, macOS

Enterprise-grade endpoint scanning and threat hunting tool.

Endpoint Security & EDR
Official site availableVisit website →

SentinelOne Singularity

Paid

Platform: Windows, macOS, Linux

AI-powered EDR with autonomous response and ransomware rollback.

Endpoint Security & EDR
Official site availableVisit website →

Microsoft Defender for Endpoint Plan 2

Paid

Platform: Windows, macOS, Linux, Android, iOS

Enterprise-grade EDR/XDR integrated into Microsoft 365.

Endpoint Security & EDR
Official site availableVisit website →

CrowdStrike Falcon

Paid

Platform: Windows, macOS, Linux

Cloud-native endpoint protection with strong detection and response.

Endpoint Security & EDR
Official site availableVisit website →

Kaspersky Free

Free

Platform: Windows

Free antivirus for Windows (regional availability may vary).

Endpoint Security & EDR
Official site availableVisit website →

Sophos Home Free

Free

Platform: Windows, macOS

Free AV and web filtering for home and small environments.

Endpoint Security & EDR
Official site availableVisit website →

Avast Free Antivirus

Free

Platform: Windows, macOS

Free antivirus with basic protection and web shield.

Endpoint Security & EDR
Official site availableVisit website →

Maisie SMB Security Evaluator

Free

Platform: Web-based

Online SMB security questionnaire that generates a basic security score.

Assessments & Utilities
Official site availableVisit website →

Gandalf AI

Free

Platform: Web-based

Game-style AI prompt injection and jailbreak testing.

AI & LLM Security
Official site availableVisit website →

Lakera Guard

Paid

Platform: Cloud, API

AI security platform that protects LLM apps from prompt injection and data exfiltration.

AI & LLM Security
Official site availableVisit website →

Azure AD Password Protection

Paid

Platform: Cloud

Blocks weak and compromised passwords using banned password lists in Azure AD.

Identity, MFA & Passwords
Official site availableVisit website →

LastPass Teams

Paid

Platform: Windows, macOS, Browser, Mobile

Business password manager with shared vaults and admin controls.

Identity, MFA & Passwords
Official site availableVisit website →

1Password Business

Paid

Platform: Windows, macOS, Linux, Browser, Mobile

Password manager and secrets vault for teams and businesses.

Identity, MFA & Passwords
Official site availableVisit website →

Bitwarden Teams

Freemium

Platform: Windows, macOS, Linux, Browser, Mobile

Open-source password manager with team features.

Identity, MFA & Passwords
Official site availableVisit website →

Google Authenticator

Free

Platform: Android, iOS

Free TOTP-based 2FA app.

Identity, MFA & Passwords
Official site availableVisit website →

Microsoft Authenticator

Free

Platform: Android, iOS

App-based MFA with push notifications, TOTP, and passwordless sign-in.

Identity, MFA & Passwords
Official site availableVisit website →

Duo MFA

Paid

Platform: Cloud

Multi-factor authentication for apps, VPNs, and devices.

Identity, MFA & Passwords
Official site availableVisit website →

Okta MFA

Paid

Platform: Cloud

Okta’s MFA service for securing identities and apps.

Identity, MFA & Passwords
Official site availableVisit website →

1Password Advanced Protection

Paid

Platform: Cloud

Advanced security policies and authentication controls in 1Password Business.

Identity, MFA & Passwords
Official site availableVisit website →

Wireshark

Free

Platform: Windows, macOS, Linux

Open-source network protocol analyzer.

Network & Remote Access
Official site availableVisit website →

tcpdump

Free

Platform: Linux, macOS

Command-line packet capture tool.

Network & Remote Access
Official site availableVisit website →

Nmap

Free

Platform: Windows, macOS, Linux

Open-source network scanner for host discovery and port scanning.

Network & Remote Access
Official site availableVisit website →

Advanced IP Scanner

Free

Platform: Windows

Fast network scanner for Windows, useful for small networks.

Network & Remote Access
Official site availableVisit website →

Spiceworks Inventory

Free

Platform: Windows

IT asset management and inventory for small environments.

Asset Inventory & CMDB
Official site availableVisit website →

GLPI IT Asset Management

Free, Open Source

Platform: Linux, Web-based

Open-source IT asset management and helpdesk.

Asset Inventory & CMDB
Official site availableVisit website →

Rapid7 InsightVM

Paid

Platform: Cloud, On-Prem

Vulnerability management and risk prioritization platform.

Vulnerability Scanning
Official site availableVisit website →

Tenable Nessus Essentials

Free (limited)

Platform: Windows, macOS, Linux

Free vulnerability scanner for up to 16 IPs.

Vulnerability Scanning
Official site availableVisit website →

OpenVAS

Free & Open Source

Platform: Linux

Full-featured network vulnerability scanner with scheduled scans and reporting.

Vulnerability Scanning
Official site availableVisit website →

Microsoft Baseline Security Analyzer (Legacy)

Free

Platform: Windows

Legacy Microsoft tool for basic Windows security configuration analysis.

Vulnerability Scanning
Official site availableVisit website →

Sysinternals Suite

Free

Platform: Windows

Collection of Windows utilities for diagnostics and troubleshooting.

Windows & Admin Tools
Official site availableVisit website →

Process Explorer

Free

Platform: Windows

Advanced process viewer for Windows.

Windows & Admin Tools
Official site availableVisit website →

Windows Event Forwarding

Free

Platform: Windows

Built-in Windows feature for centralizing logs.

SIEM & Log Management
Official site availableVisit website →

Splunk Free

Free (limited)

Platform: Windows, Linux

Free license of Splunk for small log volumes.

SIEM & Log Management
Official site availableVisit website →

Graylog Open

Free & Open Source

Platform: Linux

Open-source log management and analysis.

SIEM & Log Management
Official site availableVisit website →

Wazuh

Free & Open Source

Platform: Linux

Open-source security platform for SIEM, XDR, and endpoint security.

SIEM & Log Management
Official site availableVisit website →

Arctic Wolf MDR

Paid

Platform: Cloud

Managed detection and response services for SMB and mid-market.

SOC & MDR Services
Official site availableVisit website →

Binary Defense MDR

Paid

Platform: Cloud

Managed detection and response provider for 24/7 monitoring.

SOC & MDR Services
Official site availableVisit website →

Critical Start MDR

Paid

Platform: Cloud

MDR and XDR services with a mobile app for SOC collaboration.

SOC & MDR Services
Official site availableVisit website →

Veeam Backup Community Edition

Free (limited)

Platform: Windows

Free edition of Veeam Backup for small environments.

Backup & Disaster Recovery
Official site availableVisit website →

Veeam Backup & Replication

Paid

Platform: Windows

Enterprise backup and replication for virtual and physical workloads.

Backup & Disaster Recovery
Official site availableVisit website →

Backblaze B2

Paid (low-cost)

Platform: Cloud

Low-cost cloud storage used as a backup target.

Backup & Disaster Recovery
Official site availableVisit website →

Wasabi Hot Cloud Storage

Paid (flat-rate)

Platform: Cloud

Hot cloud storage often used for backup and archives.

Backup & Disaster Recovery
Official site availableVisit website →

Mail-Tester

Free

Platform: Web-based

Tests email deliverability, SPF, DKIM, and DMARC configuration.

Email Security
Official site availableVisit website →

MXToolbox

Free (with paid tiers)

Platform: Web-based

DNS, blacklist, SPF, DKIM, and DMARC diagnostic tools.

Email Security
Official site availableVisit website →

PhishTool

Freemium

Platform: Cloud

Email analysis and phishing triage platform.

Email Security
Official site availableVisit website →

dmarcian

Paid

Platform: Cloud

DMARC reporting and management platform.

Email Security
Official site availableVisit website →

Valimail

Paid

Platform: Cloud

Automated DMARC enforcement and reporting.

Email Security
Official site availableVisit website →

EasyDMARC

Paid (with free tier)

Platform: Cloud

DMARC monitoring and email security tools.

Email Security
Official site availableVisit website →

Twingate

Freemium

Platform: Windows, macOS, Linux, Mobile

Zero trust remote access solution to replace VPNs.

Network & Remote Access
Official site availableVisit website →

Tailscale

Freemium

Platform: Windows, macOS, Linux, Mobile

Mesh VPN based on WireGuard for simple remote access.

Network & Remote Access
Official site availableVisit website →

OpenVPN (Community Edition)

Free & Open Source

Platform: Windows, macOS, Linux

Open-source VPN solution for secure remote access.

Network & Remote Access
Official site availableVisit website →

AnyDesk

Freemium

Platform: Windows, macOS, Linux, Mobile

Remote desktop support for IT admins and MSPs.

Remote Support
Official site availableVisit website →

RustDesk

Free & Open Source

Platform: Windows, macOS, Linux, Mobile

Open-source remote desktop software with self-hosting options.

Remote Support
Official site availableVisit website →

Fortinet Security Awareness and Training Service

Paid

Platform: Cloud

Security awareness training platform integrated with Fortinet.

Security Awareness & Phishing Training
Official site availableVisit website →

Heimdal Threat Prevention - DNS

Paid

Platform: Windows, macOS

DNS-based threat prevention and filtering.

DNS & Web Filtering
Official site availableVisit website →

Heimdal NGAV & EDR

Paid

Platform: Windows, macOS

Next-gen antivirus and EDR solution.

Endpoint Security & EDR
Official site availableVisit website →

Nessus Professional

Paid

Platform: Windows, macOS, Linux

Professional vulnerability assessment for networks and systems.

Vulnerability Scanning
Official site availableVisit website →

ThreatLocker

Paid

Platform: Windows, macOS

Zero trust application control and ringfencing for endpoints and servers.

Endpoint Security & EDR
Official site availableVisit website →

Sophos Intercept X Advanced

Paid

Platform: Windows, macOS, Server

EDR and anti-ransomware protection for endpoints and servers.

Endpoint Security & EDR
Official site availableVisit website →

Barracuda Essentials

Paid

Platform: Cloud

Email security, archiving, and backup for Microsoft 365 and other email platforms.

Email Security
Official site availableVisit website →

Mimecast Email Security

Paid

Platform: Cloud

Email security, continuity, and archiving service for businesses.

Email Security
Official site availableVisit website →

Datto SIRIS/Datto BCDR

Paid

Platform: Appliance, Cloud

Business continuity and disaster recovery appliances and cloud services.

Backup & Disaster Recovery
Official site availableVisit website →

Microsoft 365 Business Premium

Paid (per user)

Platform: Cloud

SMB subscription bundle including Office apps, email, and Microsoft security capabilities like Intune and Defender.

Productivity & Security Bundles
Official site availableVisit website →