Tools we build and use ourselves
Start with the four below — templates, the GRC starter kit, the audit trial and the scenario bank all run right now, free, without an account. Under those sit the AI-security and supply-chain scanners and the security-architect studios — interactive canvases with an AI copilot for threat modeling, architecture design, design review, org design and a unified risk register. Those come with any subscription, and the source stays private.
25 editable starting points — artefacts, policies, processes and audit packs. Generated in your browser.
Audit-ready policies, procedures, standards and internal-audit templates written for one fully worked fictional global bank. Download by document or as one ZIP.
A fictional client submits real-looking policies, firewall rule sets and vendor assessments with planted gaps. Flag every issue, get scored, and see the answer key.
Realistic interview scenarios across cyber and AI engineering. Pick a response, see how it compares to a simulated peer poll, and read the reasoning behind the strongest move.
Identity Risk
·Identity Risk CalculatorliveScore a human, service or AI identity 0–100.
Scores any identity — human user, service account or AI agent — across blast radius, authentication strength, exposure, governance and monitoring, and bands it Low to Critical.
SOC Triage Trainer
·SOC Log Triage TrainerlivePractice spotting the bad logs in a stream of 1,000.
An inbox of 1,000 synthetic logs from across the stack — identity, EDR, firewall, email, DNS, cloud.
Find the Bad Friend
·Find the Bad FriendliveFriend-request scam simulator — accept the real, reject the fakes.
A simulation game: incoming friend / follow / connection requests pop up one at a time — accept the genuine people, reject the fakes and say why.
Would You Pick Up?
·Would You Pick Up?liveScam-call simulator — answer or decline five incoming calls.
Five calls come in over a Microsoft Teams-style screen — family, colleagues and scammers.
NIST CSF 2.0 Toolkit
·NIST CSF 2.0 Visual & Audio ToolkitliveMaturity wheel, roadmap, crosswalk, audio flashcards & tabletop.
Score your NIST CSF 2.0 maturity as a visual wheel and heat-map, build a tier roadmap, cross-walk to CIS / ISO 27001 / SOC 2 / PCI, and drill the framework with browser-audio flashcards and a spoken ransomware tabletop.
NPM Scanner
·Automated Supply Chain Risk ScannerliveDaily scanning of npm packages — download the same tool for your own repos.
PlayCISO scans the top npm packages daily against 50 risk policies (install scripts, ownership changes, typosquats, obfuscation).
Prompt Scan
·Prompt Injection ScannerbetaCatches "ignore prior instructions" before your agent does.
Enforces the one rule that actually stops prompt injection: forwarded content is data to read, never instructions to obey.
Prompt Injection Library
·Prompt Injection & Jailbreak Librarynew200+ examples across every technique — study them, then score your own.
100+ defanged real-world prompt-injection and jailbreak attacks across every technique (DAN, ignore-previous, system-prompt extraction, indirect injection, exfiltration) plus 100 healthy prompts to contrast — filterable, highlighted, and paired with a 25-rule browser-side scorer for your own prompts.
MCP Guard
·MCP Config AuditorbetaA static audit of your MCP server config.
Paste your MCP config; it flags plaintext secrets, unpinned installs, shell pipes, and over-broad filesystem roots.
MCP Scan
·Public MCP Server Hygiene ScannernewBrowse the public leaderboard free; scan your own server with Pro.
One standard MCP handshake (no exploitation, ever) scored against 27 deterministic rules — auth, dangerous capability exposure, prompt injection, input validation, transport hygiene, and description-change detection across scans.
Model Audit
·Model Behavioural AuditbetaRed-team a model endpoint you control — part of PlayCISO Pro.
Runs an adversarial suite — jailbreak, injection, secret-leak — against your own model endpoint and hands you the replies.
Extension Scanner
·Chrome Extension Risk ScannerbetaScore a Chrome extension by what it can actually do — part of PlayCISO Pro.
Give it an extension ID; it pulls the live Web Store manifest and scores the permission combinations nobody reads.
AI BOM
·AI Bill of MaterialsbetaA bill of materials for your AI stack — part of PlayCISO Pro.
Turns a package.json or models/datasets manifest into a CycloneDX-style inventory with a license-risk read per component.
Resume Review
·AI Resume CritiquebetaA resume critique tuned to security roles and your market.
Grades your resume for a specific role and market, rewrites the flat bullets, and finds the ATS keywords you’re missing.
AI SVS
·AI Security Verification StandardalphaA verification standard for AI systems — in development.
An ASVS-style verification standard for AI systems, still being written — the one thing here you can't run yet.
AI Cert Prep
·AI Cert Practice DrillsbetaGamified practice for CSA, IAPP, ISACA, and ISO/IEC 42001.
600+ questions across four AI security/governance certifications — CSA AI Security, IAPP AIGP, ISACA AAIA, and ISO/IEC 42001 Lead Auditor.
The Cut
·Competitive Budget SiegeliveSurvive a 10% budget cut, get a CISO Score, challenge a colleague.
One shared board per week, a server-graded CISO Score out of 1000, a live leaderboard, and challenge links that make a colleague play your exact scenario.
M&A Cyber Assessment
·M&A Cyber Due DiligencebetaSix-phase acquisition scenario with ransomware incident, dual roles, and NPC advisors.
6 phases · 2 roles · ~3h · cyber incident · 7 NPC advisors
Cinematic Video
·Cinematic Introduction VideobetaUpload your resume, get a 60-second cinematic video with AI voiceover.
Extracts your career story, writes a narrative script, records motion graphics with professional AI voiceover, and delivers a shareable MP4.
AI Cost Optimizer
·AI Cost & Savings OptimizernewEstimate your AI spend and get a ranked list of ways to cut it.
Upload a usage CSV, scan a website for the AI it runs, or paste your provider usage.
MCP Server Risk
·MCP Server Governance & Risk ChecknewShould this MCP server be allowed in your environment, and under what controls?
Applies the OWASP MCP Governance & Risk framework: four non-negotiable gates (owner, logging, scope, review), a Tier 0-4 classification, and an eight-factor risk score, returning an approve / conditional / block verdict with the controls to add.
Abliterated Model Risk
·Abliterated Model Risk CalculatornewScore a refusal-removed ("uncensored") LLM before it enters your environment.
Nine questions about a refusal-removed model — type, provenance, custom code, deployment, data access, users, agent tools, governance, authorisation — return a banded 0–100 risk score and the controls that bring it down.
LiteLLM Checker
·LiteLLM / TeamPCP Exposure CheckernewCheck a host for IOCs from the March 2026 LiteLLM supply chain attack.
A free, local, single-file Python script — no network calls, no telemetry.
Reputation Checker
·File/URL/Domain/IP Reputation LookupnewCheck VirusTotal’s existing scan results — no API key, no signup.
Look up an existing malware/reputation verdict for a file hash, URL, domain or IP, powered by VirusTotal’s free VTAI API.
Agent Governance Plane
·AI Agent Governance & Security ArchitecturenewInteractive reference architecture — identity, guardrails, observability.
Click through all 9 components of a production agent-governance architecture — zero standing privilege, policy enforcement, quarantine, audit trail — and self-score your own environment’s maturity live on the diagram.
Cyber Insurance Calculator
·Cyber Insurance Premium & Cost CalculatornewReal, cited market data — no invented premium formula.
Average incident cost by revenue band (NetDiligence), U.S. market-wide premium trends and loss ratios (Aon/NAIC/Marsh), and the top 10 carriers by market share — every figure sourced and linked, with no fabricated per-control discount.
APT & Threat-Intel Feed
·APT & Threat-Intel FeednewCurated threat research, filterable 10+ ways.
Real APT, ransomware, malware and supply-chain research from major vendors, filterable by category, source, threat actor, origin, target sector, target region, confidence and date.
APT Knowledge Graph
·APT Knowledge GraphnewInteractive graph of actors, origins, and targets.
The same curated threat-intel dataset visualized as a force-directed graph — threat actors connected to suspected origins, target sectors and target regions, sourced entirely from vendor research.
APT Naming Rosetta Stone
·APT Naming Rosetta StonenewTranslate threat actor names across Microsoft, CrowdStrike, Mandiant & more.
172 threat actors from Microsoft’s official naming taxonomy, cross-referenced with aliases from CrowdStrike, Mandiant, ESET, Kaspersky and community names.
AI Threat Model Builder
·Agentic AI Threat Model BuildernewToggle components, get a STRIDE register mapped to 6 frameworks, explore it as a knowledge graph, export a PDF.
Pick one of 10 industry profiles, switch 13 architectural assets on or off, and get a threat register for every resulting trust boundary — 62 threats mapped to the OWASP Agentic AI, LLM, MCP and AppSec Top 10s, MITRE ATLAS and the NIST AI RMF, with controls, likelihood × impact scoring, a heatmap, a knowledge-graph view and a real-world incident overlay.
Compress PDF
·Free PDF CompressornewShrink a PDF by recompressing its images — text stays sharp.
Recompresses the embedded images inside a PDF, which is almost always what makes a scanned or exported PDF huge.
Compress MP4
·Free MP4 CompressornewRe-encode a video down to something you can actually send.
Re-encodes an MP4 with H.264 at a lower bitrate and resolution.
Scan to PDF
·Camera Document ScannernewPhotograph a document, get a perspective-corrected scanned PDF.
Drag the four corners onto a photographed document’s edges and it’s perspective-corrected, enhanced (color, grayscale or high-contrast black & white) and assembled into a high-resolution multi-page PDF.
Security Ops Maturity Model
·SOC-CMM-Inspired Maturity AssessmentnewPick a persona for an instant benchmark, or build your own.
A condensed, SOC-CMM-inspired maturity model across Business, People, Process, Technology and Services.
Vendor Risk Ranking
·CVSS 10.0 Vendor Risk RankingnewRank 15 enterprise vendors by CVSS 10.0 vulnerability count.
Free interactive tool ranking 15 enterprise vendors by CVSS 10.0 vulnerability count, confirmed exploitation rate, and computed fragility score.
Secure Paste
·Encrypted Notepad & PastebinnewShare text via a link the server can’t read — encrypted before it leaves your browser.
AES-256-GCM encryption happens client-side; the decryption key lives only in the share link, never on PlayCISO’s servers.
AI Risk Register
·AI Risk Register — 30 Real-World Risksnew30 incident-grounded AI risks with severity scoring — free CSV download.
30 AI-specific risks grounded in documented incidents (Samsung data leak, $25M deepfake fraud, prompt injection, EU AI Act deadlines), each with likelihood × impact scoring, recommended controls and links to PlayCISO tools. Download the full register as CSV.
AI Adoption Hub
·AI Adoption & Migration HubnewAdopt, migrate, or offload AI — checklists, readiness scores, project plans.
Interactive checklists for adopting Claude, ChatGPT, Gemini, or DeepSeek across your engineering org. Migration planner between platforms. Offloading guide for going back to manual. Readiness assessment, 20-week project plan, CSV exports.
Security-architect studios
newThree independent, interactive canvases. You stay in control — the AI proposes, you dispose: edit, accept, dispute or dismiss everything, then export. Nothing is versioned; your work autosaves locally and exports whenever you want.
Threat Model Studio
·STRIDE Threat Modeling CanvasstudioDraw the system, let an AI copilot map the threats.
Sketch a data-flow diagram — or describe your system and have it drawn for you — then get STRIDE threats suggested per element, with likelihood, impact and control mappings you accept, edit or dismiss.
Architecture Studio
·Security Architecture CanvasstudioBlueprint a reference architecture with live compliance coverage.
A component palette plus a blueprint wizard: pick a pattern, cloud, compliance regime and data classification, and the AI seeds a labelled architecture you keep editing.
Design Review Workbench
·RFC / Design Security ReviewstudioPaste an RFC, triage the findings, sign it off.
Drop in a design doc and get a severity-ranked findings board you can accept, dispute (and challenge the AI back), defer or assign — beside an annotation whiteboard and an OWASP ASVS checklist.
Attack Path Simulator
·Animated Kill-Chain SimulatorstudioWatch a breach move through your enterprise, live.
Pick an industry + threat actor; it generates a multi-tier enterprise (DMZ, identity, internal, Kubernetes, cloud, OT, data) and plays the intrusion like a movie — hop by hop to the crown jewels and back out on exfil, each step mapped to ATT&CK.
Org Designer
·Greenfield Security-Org BuilderstudioDesign the team before you hire it.
Five facts about the company in — a defensible org out: functions, headcount model, budget split, KPIs per role, a first-year hiring roadmap, and job descriptions you can download and edit.
Cyber PMO
·10 Security Project PacksstudioThe ten projects every program runs — fully packed.
Business case, phased plan with exit criteria, governance, baselined KPIs, status-report skeleton and a pre-seeded RAID log — for MFA, EDR, PAM, SIEM/SOC, vuln management, IR, Zero Trust, DLP, vendor risk and awareness.
Risk Register
·Unified Cross-Tool Risk RegisterstudioEvery risk from all three studios, board-ready.
Aggregates threats, architecture control gaps and design-review findings into one register with owners, status and residual risk — then exports a board report plus SARIF, Open Threat Model, Threat Dragon, OSCAL and CSV.
Community tools — vote them up
Open-source security tools worth a look, ranked by the community. Signed-in members upvote or downvote.
66-tool MCP server that brings dark-web and threat intelligence to AI agents — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit search and stealer logs across 16 sources.
A Burp Suite extension that re-exposes the full Montoya API over a local OpenAPI REST API (with Swagger UI), bridging everything a Burp extension can do — active scan, intruder/turbo intruder, sitemap iteration, WebSockets, CSRF PoC, other extensions like Autorize, custom Bambda rules — to your AI agents.
Automated web-security reconnaissance & vulnerability assessment for bug-bounty hunters — discover attack surfaces, fingerprint technologies, detect common web vulnerabilities and generate actionable reports.
Local-first AI red-team engine for web, API and LLM application security. Assesses a scoped target through externally observable behaviour (browser inspection, recon, ZAP and Nuclei adapters) with explicit scope verification and human approval gates, and produces evidence-backed findings with remediation guidance. Also ships as a portable skill for coding agents (Codex, Claude Code, Gemini CLI, Grok).
Autonomous AI agent system for penetration testing — researches an authorized target, plans the assessment, runs 20+ real tools (Nmap, SQLMap, Metasploit) in isolated Docker containers, and reports findings. Works with cloud LLMs or fully local/self-hosted models via Ollama and vLLM.
Loading votes…
These are third-party open-source projects, credited to their authors and linked to source. Listing is not an endorsement — review any tool before you run it.
Free users see landing pages and can preview docs. Run buttons and the architect studios require a paid subscription. See pricing.