Every tool I reach for, area by area, favorite first. Most of them are open source and link straight to their source on GitHub. The few commercial ones are marked as such.
Reading code for bugs before it ships.
Testing running applications from the outside.
The standard intercepting proxy for manual web and API testing.
OWASP's open-source proxy and scanner, easy to automate against staging.
Template-based scanner for known misconfigurations and CVEs at scale.
Finding credentials before attackers do.
Finds secrets across git history and checks whether they are still live.
Lightweight scanner that fits neatly into pre-commit hooks and CI.
Baseline-driven scanning that keeps old noise out of existing repositories.
Keeping other people's code in check.
OWASP's scanner that maps project dependencies to known CVEs.
Checks lockfiles against the open OSV vulnerability database.
Automated pull requests that keep vulnerable dependencies up to date.
From image to running pod.
Guardrails that hold while teams move fast.
Security and compliance checks for AWS, Azure, Google Cloud and Kubernetes.
Policy-as-code scanning for Terraform, CloudFormation and Kubernetes manifests.
Detects risky configurations across cloud accounts.
New attack surface, same discipline.
Controls that stand up to auditors and attackers.
The ones I would take to a desert island.
[Why it is a favorite.]
[Why it is a favorite.]
[Why it is a favorite.]
Security know-how packaged for agents.
Agent skills for web, API, cloud, AI and offensive security testing.
Security auditing skills for Claude Code from the Trail of Bits team.
GitHub Action that runs an AI security review on every pull request.
Community standards and tools I lean on.
Application Security Verification Standard, the backbone of my design reviews.
Web Security Testing Guide, the checklist behind manual tests.
Deliberately insecure app for training sessions and internal CTFs.
Threat modelling diagrams that live next to the code.
Vulnerability management that collects and de-duplicates findings from every scanner.
Generic WAF rules for ModSecurity and Coraza.
Thinking like the adversary, with permission.
Small, focused tests mapped to MITRE ATT&CK techniques.
Automated adversary emulation for testing detections end to end.
Open-source command and control framework for authorised engagements.
Maps attack paths through Active Directory and Entra ID.
Finding the signal in the noise.
When something has already gone wrong.
Endpoint collection and hunting across thousands of machines.
Memory forensics for finding what never touched the disk.
Builds super timelines from many artefact sources.
Collaborative case management for incident responders.