🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
4 free to run · no account needed

Tools we build and use ourselves

Start with the four below — templates, the GRC starter kit, the audit trial and the scenario bank all run right now, free, without an account. Under those sit the AI-security and supply-chain scanners and the security-architect studios — interactive canvases with an AI copilot for threat modeling, architecture design, design review, org design and a unified risk register. Those come with any subscription, and the source stays private.

Free cyber-artefact templatesfree · no signup

25 editable starting points — artefacts, policies, processes and audit packs. Generated in your browser.

GRC Starter Kit — full bank edition80 documents

Audit-ready policies, procedures, standards and internal-audit templates written for one fully worked fictional global bank. Download by document or as one ZIP.

Audit Trial — find the gapsNew15 documents · scored

A fictional client submits real-looking policies, firewall rule sets and vendor assessments with planted gaps. Flag every issue, get scored, and see the answer key.

Scenario Bank — pick your answer, beat the pollNew100 scenarios

Realistic interview scenarios across cyber and AI engineering. Pick a response, see how it compares to a simulated peer poll, and read the reasoning behind the strongest move.

Identity Risk

·Identity Risk Calculatorlive

Score a human, service or AI identity 0–100.

Scores any identity — human user, service account or AI agent — across blast radius, authentication strength, exposure, governance and monitoring, and bands it Low to Critical.

Open

SOC Triage Trainer

·SOC Log Triage Trainerlive

Practice spotting the bad logs in a stream of 1,000.

An inbox of 1,000 synthetic logs from across the stack — identity, EDR, firewall, email, DNS, cloud.

Open

Find the Bad Friend

·Find the Bad Friendlive

Friend-request scam simulator — accept the real, reject the fakes.

A simulation game: incoming friend / follow / connection requests pop up one at a time — accept the genuine people, reject the fakes and say why.

Open

Would You Pick Up?

·Would You Pick Up?live

Scam-call simulator — answer or decline five incoming calls.

Five calls come in over a Microsoft Teams-style screen — family, colleagues and scammers.

Open

NIST CSF 2.0 Toolkit

·NIST CSF 2.0 Visual & Audio Toolkitlive

Maturity wheel, roadmap, crosswalk, audio flashcards & tabletop.

Score your NIST CSF 2.0 maturity as a visual wheel and heat-map, build a tier roadmap, cross-walk to CIS / ISO 27001 / SOC 2 / PCI, and drill the framework with browser-audio flashcards and a spoken ransomware tabletop.

Open

NPM Scanner

·Automated Supply Chain Risk Scannerlive

Daily scanning of npm packages — download the same tool for your own repos.

PlayCISO scans the top npm packages daily against 50 risk policies (install scripts, ownership changes, typosquats, obfuscation).

Open

Prompt Scan

·Prompt Injection Scannerbeta

Catches "ignore prior instructions" before your agent does.

Enforces the one rule that actually stops prompt injection: forwarded content is data to read, never instructions to obey.

Open

Prompt Injection Library

·Prompt Injection & Jailbreak Librarynew

200+ examples across every technique — study them, then score your own.

100+ defanged real-world prompt-injection and jailbreak attacks across every technique (DAN, ignore-previous, system-prompt extraction, indirect injection, exfiltration) plus 100 healthy prompts to contrast — filterable, highlighted, and paired with a 25-rule browser-side scorer for your own prompts.

Open

MCP Guard

·MCP Config Auditorbeta

A static audit of your MCP server config.

Paste your MCP config; it flags plaintext secrets, unpinned installs, shell pipes, and over-broad filesystem roots.

Open

MCP Scan

·Public MCP Server Hygiene Scannernew

Browse the public leaderboard free; scan your own server with Pro.

One standard MCP handshake (no exploitation, ever) scored against 27 deterministic rules — auth, dangerous capability exposure, prompt injection, input validation, transport hygiene, and description-change detection across scans.

Open

Model Audit

·Model Behavioural Auditbeta

Red-team a model endpoint you control — part of PlayCISO Pro.

Runs an adversarial suite — jailbreak, injection, secret-leak — against your own model endpoint and hands you the replies.

Open

Extension Scanner

·Chrome Extension Risk Scannerbeta

Score a Chrome extension by what it can actually do — part of PlayCISO Pro.

Give it an extension ID; it pulls the live Web Store manifest and scores the permission combinations nobody reads.

Open

AI BOM

·AI Bill of Materialsbeta

A bill of materials for your AI stack — part of PlayCISO Pro.

Turns a package.json or models/datasets manifest into a CycloneDX-style inventory with a license-risk read per component.

Open

Resume Review

·AI Resume Critiquebeta

A resume critique tuned to security roles and your market.

Grades your resume for a specific role and market, rewrites the flat bullets, and finds the ATS keywords you’re missing.

Open

AI SVS

·AI Security Verification Standardalpha

A verification standard for AI systems — in development.

An ASVS-style verification standard for AI systems, still being written — the one thing here you can't run yet.

Open

AI Cert Prep

·AI Cert Practice Drillsbeta

Gamified practice for CSA, IAPP, ISACA, and ISO/IEC 42001.

600+ questions across four AI security/governance certifications — CSA AI Security, IAPP AIGP, ISACA AAIA, and ISO/IEC 42001 Lead Auditor.

Open

The Cut

·Competitive Budget Siegelive

Survive a 10% budget cut, get a CISO Score, challenge a colleague.

One shared board per week, a server-graded CISO Score out of 1000, a live leaderboard, and challenge links that make a colleague play your exact scenario.

Open

M&A Cyber Assessment

·M&A Cyber Due Diligencebeta

Six-phase acquisition scenario with ransomware incident, dual roles, and NPC advisors.

6 phases · 2 roles · ~3h · cyber incident · 7 NPC advisors

Open

Cinematic Video

·Cinematic Introduction Videobeta

Upload your resume, get a 60-second cinematic video with AI voiceover.

Extracts your career story, writes a narrative script, records motion graphics with professional AI voiceover, and delivers a shareable MP4.

Open

AI Cost Optimizer

·AI Cost & Savings Optimizernew

Estimate your AI spend and get a ranked list of ways to cut it.

Upload a usage CSV, scan a website for the AI it runs, or paste your provider usage.

Open

MCP Server Risk

·MCP Server Governance & Risk Checknew

Should this MCP server be allowed in your environment, and under what controls?

Applies the OWASP MCP Governance & Risk framework: four non-negotiable gates (owner, logging, scope, review), a Tier 0-4 classification, and an eight-factor risk score, returning an approve / conditional / block verdict with the controls to add.

Open

Abliterated Model Risk

·Abliterated Model Risk Calculatornew

Score a refusal-removed ("uncensored") LLM before it enters your environment.

Nine questions about a refusal-removed model — type, provenance, custom code, deployment, data access, users, agent tools, governance, authorisation — return a banded 0–100 risk score and the controls that bring it down.

Open

LiteLLM Checker

·LiteLLM / TeamPCP Exposure Checkernew

Check a host for IOCs from the March 2026 LiteLLM supply chain attack.

A free, local, single-file Python script — no network calls, no telemetry.

Open

Reputation Checker

·File/URL/Domain/IP Reputation Lookupnew

Check VirusTotal’s existing scan results — no API key, no signup.

Look up an existing malware/reputation verdict for a file hash, URL, domain or IP, powered by VirusTotal’s free VTAI API.

Open

Agent Governance Plane

·AI Agent Governance & Security Architecturenew

Interactive reference architecture — identity, guardrails, observability.

Click through all 9 components of a production agent-governance architecture — zero standing privilege, policy enforcement, quarantine, audit trail — and self-score your own environment’s maturity live on the diagram.

Open

Cyber Insurance Calculator

·Cyber Insurance Premium & Cost Calculatornew

Real, cited market data — no invented premium formula.

Average incident cost by revenue band (NetDiligence), U.S. market-wide premium trends and loss ratios (Aon/NAIC/Marsh), and the top 10 carriers by market share — every figure sourced and linked, with no fabricated per-control discount.

Open

APT & Threat-Intel Feed

·APT & Threat-Intel Feednew

Curated threat research, filterable 10+ ways.

Real APT, ransomware, malware and supply-chain research from major vendors, filterable by category, source, threat actor, origin, target sector, target region, confidence and date.

Open

APT Knowledge Graph

·APT Knowledge Graphnew

Interactive graph of actors, origins, and targets.

The same curated threat-intel dataset visualized as a force-directed graph — threat actors connected to suspected origins, target sectors and target regions, sourced entirely from vendor research.

Open

APT Naming Rosetta Stone

·APT Naming Rosetta Stonenew

Translate threat actor names across Microsoft, CrowdStrike, Mandiant & more.

172 threat actors from Microsoft’s official naming taxonomy, cross-referenced with aliases from CrowdStrike, Mandiant, ESET, Kaspersky and community names.

Open

AI Threat Model Builder

·Agentic AI Threat Model Buildernew

Toggle components, get a STRIDE register mapped to 6 frameworks, explore it as a knowledge graph, export a PDF.

Pick one of 10 industry profiles, switch 13 architectural assets on or off, and get a threat register for every resulting trust boundary — 62 threats mapped to the OWASP Agentic AI, LLM, MCP and AppSec Top 10s, MITRE ATLAS and the NIST AI RMF, with controls, likelihood × impact scoring, a heatmap, a knowledge-graph view and a real-world incident overlay.

Open

Compress PDF

·Free PDF Compressornew

Shrink a PDF by recompressing its images — text stays sharp.

Recompresses the embedded images inside a PDF, which is almost always what makes a scanned or exported PDF huge.

Open

Compress MP4

·Free MP4 Compressornew

Re-encode a video down to something you can actually send.

Re-encodes an MP4 with H.264 at a lower bitrate and resolution.

Open

Scan to PDF

·Camera Document Scannernew

Photograph a document, get a perspective-corrected scanned PDF.

Drag the four corners onto a photographed document’s edges and it’s perspective-corrected, enhanced (color, grayscale or high-contrast black & white) and assembled into a high-resolution multi-page PDF.

Open

Security Ops Maturity Model

·SOC-CMM-Inspired Maturity Assessmentnew

Pick a persona for an instant benchmark, or build your own.

A condensed, SOC-CMM-inspired maturity model across Business, People, Process, Technology and Services.

Open

Vendor Risk Ranking

·CVSS 10.0 Vendor Risk Rankingnew

Rank 15 enterprise vendors by CVSS 10.0 vulnerability count.

Free interactive tool ranking 15 enterprise vendors by CVSS 10.0 vulnerability count, confirmed exploitation rate, and computed fragility score.

Open

Secure Paste

·Encrypted Notepad & Pastebinnew

Share text via a link the server can’t read — encrypted before it leaves your browser.

AES-256-GCM encryption happens client-side; the decryption key lives only in the share link, never on PlayCISO’s servers.

Open

AI Risk Register

·AI Risk Register — 30 Real-World Risksnew

30 incident-grounded AI risks with severity scoring — free CSV download.

30 AI-specific risks grounded in documented incidents (Samsung data leak, $25M deepfake fraud, prompt injection, EU AI Act deadlines), each with likelihood × impact scoring, recommended controls and links to PlayCISO tools. Download the full register as CSV.

Open

AI Adoption Hub

·AI Adoption & Migration Hubnew

Adopt, migrate, or offload AI — checklists, readiness scores, project plans.

Interactive checklists for adopting Claude, ChatGPT, Gemini, or DeepSeek across your engineering org. Migration planner between platforms. Offloading guide for going back to manual. Readiness assessment, 20-week project plan, CSV exports.

Open

Security-architect studios

new

Three independent, interactive canvases. You stay in control — the AI proposes, you dispose: edit, accept, dispute or dismiss everything, then export. Nothing is versioned; your work autosaves locally and exports whenever you want.

Share

Threat Model Studio

·STRIDE Threat Modeling Canvasstudio

Draw the system, let an AI copilot map the threats.

Sketch a data-flow diagram — or describe your system and have it drawn for you — then get STRIDE threats suggested per element, with likelihood, impact and control mappings you accept, edit or dismiss.

Open the studio

Architecture Studio

·Security Architecture Canvasstudio

Blueprint a reference architecture with live compliance coverage.

A component palette plus a blueprint wizard: pick a pattern, cloud, compliance regime and data classification, and the AI seeds a labelled architecture you keep editing.

Open the studio

Design Review Workbench

·RFC / Design Security Reviewstudio

Paste an RFC, triage the findings, sign it off.

Drop in a design doc and get a severity-ranked findings board you can accept, dispute (and challenge the AI back), defer or assign — beside an annotation whiteboard and an OWASP ASVS checklist.

Open the studio

Attack Path Simulator

·Animated Kill-Chain Simulatorstudio

Watch a breach move through your enterprise, live.

Pick an industry + threat actor; it generates a multi-tier enterprise (DMZ, identity, internal, Kubernetes, cloud, OT, data) and plays the intrusion like a movie — hop by hop to the crown jewels and back out on exfil, each step mapped to ATT&CK.

Open the studio

Org Designer

·Greenfield Security-Org Builderstudio

Design the team before you hire it.

Five facts about the company in — a defensible org out: functions, headcount model, budget split, KPIs per role, a first-year hiring roadmap, and job descriptions you can download and edit.

Open the studio

Cyber PMO

·10 Security Project Packsstudio

The ten projects every program runs — fully packed.

Business case, phased plan with exit criteria, governance, baselined KPIs, status-report skeleton and a pre-seeded RAID log — for MFA, EDR, PAM, SIEM/SOC, vuln management, IR, Zero Trust, DLP, vendor risk and awareness.

Open the studio

Risk Register

·Unified Cross-Tool Risk Registerstudio

Every risk from all three studios, board-ready.

Aggregates threats, architecture control gaps and design-review findings into one register with owners, status and residual risk — then exports a board report plus SARIF, Open Threat Model, Threat Dragon, OSCAL and CSV.

Open the studio

Community tools — vote them up

Open-source security tools worth a look, ranked by the community. Signed-in members upvote or downvote.

0
#1Darknet MCP Server TypeScript 405

66-tool MCP server that brings dark-web and threat intelligence to AI agents — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search and stealer logs across 16 sources.

mcposintdarknetthreat-intelai-agents badchars
0
#2reburp Kotlin 45

A Burp Suite extension that re-exposes the full Montoya API over a local OpenAPI REST API (with Swagger UI), bridging everything a Burp extension can do — active scan, intruder/turbo intruder, sitemap iteration, WebSockets, CSRF PoC, other extensions like Autorize, custom Bambda rules — to your AI agents.

burp-suitepentestingai-agentsopenapimontoya-api forefy
0
#3BugScanner Python 58

Automated web-security reconnaissance & vulnerability assessment for bug-bounty hunters — discover attack surfaces, fingerprint technologies, detect common web vulnerabilities and generate actionable reports.

bug-bountyreconweb-securityvulnerability-scanner eldarshiraliyev
0
#4OpenHunterAI TypeScript/Go 82

Local-first AI red-team engine for web, API and LLM application security. Assesses a scoped target through externally observable behaviour (browser inspection, recon, ZAP and Nuclei adapters) with explicit scope verification and human approval gates, and produces evidence-backed findings with remediation guidance. Also ships as a portable skill for coding agents (Codex, Claude Code, Gemini CLI, Grok).

red-teampenetration-testingweb-securityai-agentslocal-first LumosLab Innovation
0
#5PentAGI Go 24300

Autonomous AI agent system for penetration testing — researches an authorized target, plans the assessment, runs 20+ real tools (Nmap, SQLMap, Metasploit) in isolated Docker containers, and reports findings. Works with cloud LLMs or fully local/self-hosted models via Ollama and vLLM.

ai-agentspenetration-testingred-teamautomationself-hosted vxcontrol

Loading votes…

These are third-party open-source projects, credited to their authors and linked to source. Listing is not an endorsement — review any tool before you run it.

All tools require a Pro plan.

Free users see landing pages and can preview docs. Run buttons and the architect studios require a paid subscription. See pricing.

Security Tools & Architect Studios · PlayCISO