Preconfigured machine images with 24/7 support by cloudimg
Security tooling images for AWS and Azure: scanners, secrets management, certificate authorities and access control platforms, deployed hardened with unique credentials per instance.
2FAuth, a self hosted vault for your two factor authentication accounts that stores the secrets and generates the one ti
acme-dns, a limited scope DNS server with a REST API, purpose built to answer ACME DNS-01 challenges without exposing yo
addy.io, an open source self hosted email aliasing service, secured on first boot.
AliasVault, an open source end to end encrypted password manager and private email alias service, secured on first boot.
Apache Directory Server, an extensible LDAP and Kerberos directory, ready to authenticate on first boot.
Apache SpamAssassin, the open source mail spam filter whose spamd daemon and rules engine score every message so your ma
Apache Syncope, open source identity management, ready to govern users, groups and accounts on first boot.
Authentik, an open source identity provider, ready to manage sign on and identity on first boot.
Authgear, an open source authentication server and identity provider that adds sign in, passkeys, multi factor authentic
Beelzebub, a low code honeypot and deception framework that stands up decoy services to lure, log and alert on attacker
BloodHound Community Edition, attack path analysis, ready to map privilege relationships on first boot.
BunkerWeb, the open source Web Application Firewall and reverse proxy built on nginx, that puts your websites and APIs b
Casdoor, a UI first identity and access management and single sign on platform that speaks OIDC, OAuth2, SAML, CAS and L
Catalyst, the open source security orchestration and incident response platform that turns alerts into tickets, runs you
Certimate, a self hosted tool that automates the full lifecycle of your SSL and TLS certificates, issuing, deploying, re
Checkov, the open source policy as code scanner that reads your infrastructure as code and reports where it breaks secur
Clair, an open source container image vulnerability scanner, indexing image layers and reporting known CVEs through a si
ClamAV, the open source malware scanning engine, ready to scan your files the moment it boots, with signatures fetched f
Cowrie, the open source SSH and Telnet honeypot, lures attackers into a fully emulated shell and records every login, co
CrowdSec, collaborative intrusion detection and response, defending from the moment it boots.
Cryptgeon, the open source service for sharing a secret once, where the note is encrypted in the sender's browser and se
CTFd, the open source Capture The Flag platform: a challenge board, live scoreboard, teams and a full admin panel for ru
CyberChef, the cyber swiss army knife, a purely client side toolkit for encoding, encryption and data analysis, served t
Databunker, a secure vault for personal data, keeps customer records encrypted and reachable through a simple API.
DefectDojo, application vulnerability management, ready to track findings on first boot.
run your ISO 27001 information security management system in one place: controls, security measures, risks, action plans
Dependency-Track, continuous software supply chain component analysis, ready to ingest an SBOM on first boot.
DFIR-IRIS, the open source collaborative platform where incident response and digital forensics teams run an investigati
self hosted DMARC and SMTP TLS report viewer: fetches reports from an IMAP inbox, parses them and renders an analytics d
collaboration and reporting for security assessment and penetration testing teams.
Enclosed, a self hosted app for sending private end to end encrypted notes and secrets that only the sender and the reci
EveBox, the web console that turns a Suricata alert stream into a searchable, triageable inbox.
Falco, the CNCF runtime security engine, watching every syscall on the machine and alerting the moment a process behaves
Fides, an open source privacy engineering platform for data mapping, consent management and automated fulfilment of data
Fleet, the open source osquery platform for device and endpoint management, ready to enroll hosts, run live queries and
FreeRADIUS, the most widely deployed RADIUS server, provides authentication, authorisation and accounting for network ac
Ghostwriter, the open source engagement and project management platform that gives offensive security teams one home for
Gitleaks, the open source secret scanner that finds hardcoded API keys, tokens and private keys across git history and y
GLAuth, a lightweight LDAP authentication server that serves a simple directory for downstream services from a single co
open source OAuth2 and OpenID Connect identity provider, self hosted and ready to issue tokens
Grype, the fast open source vulnerability scanner for container images, filesystems and SBOMs, ready to find known CVEs
Hanko, an open source authentication server for passkeys, passwordless and passwords, so you add modern sign in to your
open source mobile device management for android fleets
Hockeypuck is an OpenPGP public keyserver that stores and serves PGP public keys over the HKP protocol.
Hoop, an open source access gateway that brokers, records and audits privileged access to your databases, servers and in
Infisical, an open source secrets management platform, a self hosted alternative to HashiCorp Vault and Doppler, secured
JumpServer, an open source privileged access management bastion that brokers, vaults and records every session, with per
Keycloak identity provider with an OpenLDAP directory behind it, federation pre-wired and proven, so LDAP users sign in
KICS, the open source scanner that keeps infrastructure as code secure by flagging misconfigurations and compliance issu
LDAP Account Manager, a browsable web interface for an OpenLDAP directory, ready to sign in the moment it boots.
LLDAP, a lightweight, self hosted authentication server with an LDAP interface and a friendly web admin UI.
Lookyloo captures a web page with a real browser and unfolds everything it did: every redirect, resource, cookie and scr
Self Service Password, the LDAP Tool Box password self service portal, ready on first boot with a directory server inclu
MaxKey, an enterprise grade identity and access management server that gives your people one secure sign in to every app
map your whole information system in one place: applications, servers, networks, data and risks, rendered as cartography
MISP, an open source threat intelligence and sharing platform for collecting, correlating and sharing indicators of comp
run repeatable, authorised adversary emulation with cloudimg
MobSF, the open source Mobile Security Framework: automated static analysis of Android and iOS applications with a web d
mosparo, a privacy friendly, self hosted spam protection service that shields your web forms by checking what was actual
multiOTP, an OATH certified open source strong authentication server for TOTP and HOTP one time passwords, with a per in
Onetime Secret, a self hosted service for sharing sensitive information through one time links that reveal a secret exac
OPAL, the Open Policy Administration Layer, keeping authorization policy in sync across your services in real time.
OpenCanary, the open source honeypot daemon, stands up decoy network services and raises a high signal alert the moment
OpenLDAP, the standards based slapd directory server, ready on first boot as a private LDAP and LDAPS identity source fo
OpenLDAP directory server with the phpLDAPadmin web console in front of it, ready to browse and administer your director
OpenRelik, an open source platform for collaborative digital forensics and incident response, where analysts share cases
OpenSCAP, the reference open source compliance scanner, paired with current SCAP Security Guide content so it can audit
OSV-Scanner, Google's frontend to the OSV.dev vulnerability database: it reads your projects' lockfiles and reports the
OTS, a self hosted one time secret service that encrypts in the browser and destroys the secret on first read.
OWASP Amass, the open source attack surface mapping and external asset discovery tool, ready to enumerate the subdomains
OWASP Dependency-Check, the open source software composition analysis scanner that finds publicly disclosed vulnerabilit
OWASP Threat Dragon, the open source threat modelling tool that turns a data flow diagram of your system into a document
OWASP ZAP on Ubuntu 24.04 LTS, the web application security scanner ready to test your sites.
Password Pusher, share passwords, text, files and links over one time URLs that self destruct after a set number of view
PatchMon, a self hosted patch management platform that shows which of your Linux hosts are behind on updates and lets yo
phpLDAPadmin, a schema aware web interface for browsing and editing an OpenLDAP directory, ready to sign in the moment i
pomerium, an open source identity aware access proxy, serving TLS with unique secrets generated on first boot.
privacyIDEA, an open source multi factor authentication server that adds one time password and FIDO2 second factors to t
PrivateBin, a minimalist zero knowledge pastebin where the server only ever holds ciphertext, ready to run the moment it
multi cloud security assessment from cloudimg, ready to scan your accounts on first boot
Pwndoc, the open source penetration test reporting platform that turns findings into a finished, client ready Word repor
Rauthy, a self hosted OpenID Connect provider and identity server that runs from a single binary with no external databa
SafeLine, a self hosted web application firewall and reverse proxy with a semantic detection engine, so your web apps ar
Samba, the standard open source implementation of Active Directory, packaged as an appliance whose domain is minted on y
a lightweight, self hosted web application firewall with a web admin console for protecting your sites, blocking attacks
SecObserve, open source vulnerability management for software development teams, secured on first boot.
SignServer, an open source server that signs documents, code and data and issues trusted timestamps, keeping your signin
SimpleLogin, an open source self hosted email aliasing service, secured on first boot.
Open source governance, risk and compliance for managing your organisation's risk register.
Sirius Scan, an open source general purpose vulnerability scanner that discovers hosts and services on a network, matche
SnapPass shares a password or key by a link that works exactly once and is destroyed the moment it is read.
SpiderFoot, an OSINT automation platform that maps the attack surface of a target from public sources and correlates wha
step-ca on Ubuntu 24.04, a private certificate authority that issues and automates TLS certificates.
Strelka, Target's real-time file scanning and analysis system that recursively decomposes archives and documents and ret
Subfinder, a fast passive subdomain discovery tool that maps a domain's attack surface by reading public sources without
Suricata, the open source IDS, IPS and network security monitoring engine, with current threat intelligence fetched on f
TeamPass, the open source collaborative password manager, giving your team one encrypted shared vault with per folder ac
An open source data pipeline engine for security teams, collecting, transforming, storing and querying telemetry with a
Cilium Tetragon, the eBPF based runtime security observability and enforcement engine, running standalone as a systemd s
Timesketch, a collaborative forensic timeline analysis platform where an investigation team works one shared timeline in
Tinyauth, the lightweight open source authentication gateway: add a login screen and single sign on in front of the apps
edge reverse proxy that puts single sign-on in front of any service
edge reverse proxy with a collaborative intrusion prevention engine built in
Trivy on Ubuntu 24.04, a scanner for vulnerabilities and misconfigurations across containers and code.
Vaultwarden on Ubuntu 24.04, a lightweight self hosted password manager compatible with Bitwarden clients.
run digital forensics and incident response hunts across your endpoints from one web console
VulnerableCode, an open source, self hosted database of software package vulnerabilities with a REST API, ready to serve
Wallarm API Firewall, a fast API security proxy that validates every request and every response against your OpenAPI spe
walt.id Identity, an open source platform to issue, hold and verify verifiable credentials, packaged and secured by clou
Wapiti, the open source web vulnerability scanner that crawls a running application you own and actively probes it for i
Wazuh on Ubuntu 24.04, an open source security platform for threat detection and monitoring.
Web Check, a self hosted OSINT dashboard that reports what is publicly observable about any website.
XiPKI on Ubuntu 24.04, a high performance certificate authority for issuing and managing X.509 certificates.
Yopass, a self hosted service for sharing secrets that self destruct after a single view.
a cloud native identity and access management platform: single sign on with OIDC, OAuth2 and SAML, passwordless and mult