Specops Password Auditor
FreePlatform: Windows
Audits Active Directory passwords.

Resources
A curated list of low- and no-cost security tools for small and mid-sized businesses. Use this with your MSP or IT provider to strengthen backup, MFA, DNS filtering, email security, patching, monitoring, and more.
How to use this page
Filter by category, search by platform/purpose, then open the tool website to evaluate fit. Later, this will auto-populate “Consider Tools” inside the Risk Workspace.
Tip: keep your “primary CTA” orange. Everything else stays calm.
Browse tools
Showing 90 of 90 tools.
Search by name, purpose, or platform. Filter by canonical categories.
Showing 90 of 90 tools.
Platform: Windows
Audits Active Directory passwords.
Platform: Cloud, API
Repository of open-source ML models to explore, test, and adopt AI responsibly.
Platform: Windows, macOS, Linux
Built-in endpoint protection.
Platform: Cloud, API
Scans REST APIs from OpenAPI specs for auth issues, injection, data leakage, and misconfigurations.
Platform: Cloud
API security discovery and protection.
Platform: Cloud
API security with discovery, posture management, and runtime protection.
Platform: Cloud
API security platform with bot mitigation and API protection.
Platform: Cloud-based
Protects AI/LLM apps by monitoring prompts, generating safety rules, analyzing risks, and defending against prompt injection.
Platform: Cloud, API
Content moderation API to detect hate, harassment, violence, sexual content, and more in text or images.
Platform: Cloud
Cloud-native DLP and sensitive data detection for SaaS, LLMs, and cloud apps.
Platform: Cloud
Secures email and collaboration apps against phishing, malware, account takeover, and data loss.
Platform: Cloud
AI-powered email security platform focused on phishing detection and user reporting.
Platform: Cloud
Phishing simulation and training platform.
Platform: Cloud
Security awareness training with phishing simulations and education for employees.
Platform: Cloud
Phishing simulation and training for end users.
Platform: Linux, Web Servers
Free, automated, and open certificate authority for HTTPS/TLS.
Platform: Web-based
Analyzes SSL/TLS configuration of public web servers.
Platform: Windows
Local Administrator Password Solution for rotating local admin passwords.
Platform: Windows, macOS, Browser
Password manager with secure vault and role-based access.
Platform: Cloud, Endpoint
Managed detection and response (MDR) for CrowdStrike Falcon deployments.
Platform: Network, Cloud
Privacy-focused public DNS with built-in security filtering.
Platform: Network
Security-focused DNS service that blocks known malicious domains.
Platform: Network
DNS-based content filtering for home and small networks.
Platform: Cloud
SaaS security posture management and app discovery.
Platform: Cloud
SaaS operations and security platform for managing data and access across apps.
Platform: Cloud
SaaS security posture management for enterprise applications.
Platform: Windows
Free, reduced version of THOR for endpoint threat hunting.
Platform: Windows, Linux, macOS
Enterprise-grade endpoint scanning and threat hunting tool.
Platform: Windows, macOS, Linux
AI-powered EDR with autonomous response and ransomware rollback.
Platform: Windows, macOS, Linux, Android, iOS
Enterprise-grade EDR/XDR integrated into Microsoft 365.
Platform: Windows, macOS, Linux
Cloud-native endpoint protection with strong detection and response.
Platform: Windows
Free antivirus for Windows (regional availability may vary).
Platform: Windows, macOS
Free AV and web filtering for home and small environments.
Platform: Windows, macOS
Free antivirus with basic protection and web shield.
Platform: Web-based
Online SMB security questionnaire that generates a basic security score.
Platform: Web-based
Game-style AI prompt injection and jailbreak testing.
Platform: Cloud, API
AI security platform that protects LLM apps from prompt injection and data exfiltration.
Platform: Cloud
Blocks weak and compromised passwords using banned password lists in Azure AD.
Platform: Windows, macOS, Browser, Mobile
Business password manager with shared vaults and admin controls.
Platform: Windows, macOS, Linux, Browser, Mobile
Password manager and secrets vault for teams and businesses.
Platform: Windows, macOS, Linux, Browser, Mobile
Open-source password manager with team features.
Platform: Android, iOS
Free TOTP-based 2FA app.
Platform: Android, iOS
App-based MFA with push notifications, TOTP, and passwordless sign-in.
Platform: Cloud
Multi-factor authentication for apps, VPNs, and devices.
Platform: Cloud
Okta’s MFA service for securing identities and apps.
Platform: Cloud
Advanced security policies and authentication controls in 1Password Business.
Platform: Windows, macOS, Linux
Open-source network protocol analyzer.
Platform: Linux, macOS
Command-line packet capture tool.
Platform: Windows, macOS, Linux
Open-source network scanner for host discovery and port scanning.
Platform: Windows
Fast network scanner for Windows, useful for small networks.
Platform: Windows
IT asset management and inventory for small environments.
Platform: Linux, Web-based
Open-source IT asset management and helpdesk.
Platform: Cloud, On-Prem
Vulnerability management and risk prioritization platform.
Platform: Windows, macOS, Linux
Free vulnerability scanner for up to 16 IPs.
Platform: Linux
Full-featured network vulnerability scanner with scheduled scans and reporting.
Platform: Windows
Legacy Microsoft tool for basic Windows security configuration analysis.
Platform: Windows
Collection of Windows utilities for diagnostics and troubleshooting.
Platform: Windows
Advanced process viewer for Windows.
Platform: Windows
Built-in Windows feature for centralizing logs.
Platform: Windows, Linux
Free license of Splunk for small log volumes.
Platform: Linux
Open-source log management and analysis.
Platform: Linux
Open-source security platform for SIEM, XDR, and endpoint security.
Platform: Cloud
Managed detection and response services for SMB and mid-market.
Platform: Cloud
Managed detection and response provider for 24/7 monitoring.
Platform: Cloud
MDR and XDR services with a mobile app for SOC collaboration.
Platform: Windows
Free edition of Veeam Backup for small environments.
Platform: Windows
Enterprise backup and replication for virtual and physical workloads.
Platform: Cloud
Low-cost cloud storage used as a backup target.
Platform: Cloud
Hot cloud storage often used for backup and archives.
Platform: Web-based
Tests email deliverability, SPF, DKIM, and DMARC configuration.
Platform: Web-based
DNS, blacklist, SPF, DKIM, and DMARC diagnostic tools.
Platform: Cloud
Email analysis and phishing triage platform.
Platform: Cloud
DMARC reporting and management platform.
Platform: Cloud
Automated DMARC enforcement and reporting.
Platform: Cloud
DMARC monitoring and email security tools.
Platform: Windows, macOS, Linux, Mobile
Zero trust remote access solution to replace VPNs.
Platform: Windows, macOS, Linux, Mobile
Mesh VPN based on WireGuard for simple remote access.
Platform: Windows, macOS, Linux
Open-source VPN solution for secure remote access.
Platform: Windows, macOS, Linux, Mobile
Remote desktop support for IT admins and MSPs.
Platform: Windows, macOS, Linux, Mobile
Open-source remote desktop software with self-hosting options.
Platform: Cloud
Security awareness training platform integrated with Fortinet.
Platform: Windows, macOS
DNS-based threat prevention and filtering.
Platform: Windows, macOS
Next-gen antivirus and EDR solution.
Platform: Windows, macOS, Linux
Professional vulnerability assessment for networks and systems.
Platform: Windows, macOS
Zero trust application control and ringfencing for endpoints and servers.
Platform: Windows, macOS, Server
EDR and anti-ransomware protection for endpoints and servers.
Platform: Cloud
Email security, archiving, and backup for Microsoft 365 and other email platforms.
Platform: Cloud
Email security, continuity, and archiving service for businesses.
Platform: Appliance, Cloud
Business continuity and disaster recovery appliances and cloud services.
Platform: Cloud
SMB subscription bundle including Office apps, email, and Microsoft security capabilities like Intune and Defender.