Hey, I'm Tarik ๐Ÿ‘‹ โ† Back to portfolio
Favorite toys ยท Full list

The whole toy box

Every tool I reach for, area by area, favorite first. Most of them are open source and link straight to their source on GitHub. The few commercial ones are marked as such.

Security engineering

01 โ€“ 08
01

SAST

Reading code for bugs before it ships.

  1. 01
    Claude Code FavoriteCommercial

    Agentic coding assistant I use for security code review, and for fixing findings in place.

  2. 02

    OpenAI's open-source coding agent, a second pair of eyes on the same diff.

  3. 03
    Semgrep Open source

    Fast, rule-based static analysis, with custom rules for the team's own frameworks.

02

DAST

Testing running applications from the outside.

  1. 01
    Burp Suite FavoriteCommercial

    The standard intercepting proxy for manual web and API testing.

  2. 02

    OWASP's open-source proxy and scanner, easy to automate against staging.

  3. 03
    Nuclei Open source

    Template-based scanner for known misconfigurations and CVEs at scale.

03

Secret Scanning

Finding credentials before attackers do.

  1. 01
    TruffleHog FavoriteOpen source

    Finds secrets across git history and checks whether they are still live.

  2. 02
    Gitleaks Open source

    Lightweight scanner that fits neatly into pre-commit hooks and CI.

  3. 03

    Baseline-driven scanning that keeps old noise out of existing repositories.

04

Dependency Management

Keeping other people's code in check.

  1. 01
    Dependency-Check FavoriteOpen source

    OWASP's scanner that maps project dependencies to known CVEs.

  2. 02

    Checks lockfiles against the open OSV vulnerability database.

  3. 03

    Automated pull requests that keep vulnerable dependencies up to date.

05

Container Security

From image to running pod.

  1. 01
    Trivy FavoriteOpen source

    One scanner for images, filesystems, infrastructure as code and Kubernetes.

  2. 02
    Grype Open source

    Fast vulnerability scanner for container images and SBOMs.

  3. 03
    Cosign Open source

    Signs and verifies container images with Sigstore.

06

Cloud Security

Guardrails that hold while teams move fast.

  1. 01
    Prowler FavoriteOpen source

    Security and compliance checks for AWS, Azure, Google Cloud and Kubernetes.

  2. 02
    Checkov Open source

    Policy-as-code scanning for Terraform, CloudFormation and Kubernetes manifests.

  3. 03

    Detects risky configurations across cloud accounts.

07

AI Security

New attack surface, same discipline.

  1. 01
    garak FavoriteOpen source

    LLM vulnerability scanner that probes for jailbreaks, leakage and prompt injection.

  2. 02

    Red teaming and evaluation for prompts, agents and RAG pipelines.

  3. 03
    DeepTeam Open source

    Framework for red teaming LLM applications against known attack types.

08

Compliance & Regulation

Controls that stand up to auditors and attackers.

  1. 01
    Open Policy Agent FavoriteOpen source

    General-purpose policy engine for writing guardrails as code.

  2. 02
    OpenCRE Open source

    OWASP's map that links security standards and requirements to each other.

  3. 03
    Drata Commercial

    Continuous compliance automation for SOC 2 and ISO 27001 evidence.

And beyond

09 โ€“ 14
09

Favorite

The ones I would take to a desert island.

  1. 01
    [Tool name]

    [Why it is a favorite.]

  2. 02
    [Tool name]

    [Why it is a favorite.]

  3. 03
    [Tool name]

    [Why it is a favorite.]

10

AI Security Skills

Security know-how packaged for agents.

  1. 01
    HackSkills FavoriteOpen source

    Agent skills for web, API, cloud, AI and offensive security testing.

  2. 02

    Security auditing skills for Claude Code from the Trail of Bits team.

  3. 03

    GitHub Action that runs an AI security review on every pull request.

11

OWASP Projects

Community standards and tools I lean on.

  1. 01
    ASVS FavoriteOpen source

    Application Security Verification Standard, the backbone of my design reviews.

  2. 02
    WSTG Open source

    Web Security Testing Guide, the checklist behind manual tests.

  3. 03

    Deliberately insecure app for training sessions and internal CTFs.

  4. 04

    Threat modelling diagrams that live next to the code.

  5. 05

    Vulnerability management that collects and de-duplicates findings from every scanner.

  6. 06

    Generic WAF rules for ModSecurity and Coraza.

12

Red Teaming

Thinking like the adversary, with permission.

  1. 01
    Atomic Red Team FavoriteOpen source

    Small, focused tests mapped to MITRE ATT&CK techniques.

  2. 02
    Caldera Open source

    Automated adversary emulation for testing detections end to end.

  3. 03
    Sliver Open source

    Open-source command and control framework for authorised engagements.

  4. 04

    Maps attack paths through Active Directory and Entra ID.

13

Log Analysis

Finding the signal in the noise.

  1. 01
    Sigma FavoriteOpen source

    Generic detection rules that translate to any SIEM.

  2. 02
    Hayabusa Open source

    Fast Windows event log timelines and threat hunting.

  3. 03
    Chainsaw Open source

    Searches event logs quickly using Sigma rules.

  4. 04
    Zeek Open source

    Turns network traffic into rich, searchable logs.

14

Incident Response

When something has already gone wrong.

  1. 01
    Velociraptor FavoriteOpen source

    Endpoint collection and hunting across thousands of machines.

  2. 02

    Memory forensics for finding what never touched the disk.

  3. 03
    Plaso Open source

    Builds super timelines from many artefact sources.

  4. 04

    Collaborative case management for incident responders.