| Port | Description |
| ADMsnmp | SNMP audit scanner |
| ROPgadget | Gadgets finder and auto-roper |
| acme.sh | pure Unix shell script implementing ACME client protocol |
| aescrypt | encrypt/decrypt using Rijndael encryption algorithm |
| age | simple, modern and secure file encryption tool |
| age-plugin-yubikey | YubiKey plugin for age clients |
| aide | Advanced Intrusion Detection Environment (file mod checker) |
| aircrack-ng | 802.11 WEP and WPA-PSK keys cracking program |
| amap | application protocol detection tool |
| angrop | ROP chain builder based off of angr |
| apg | automated password generator |
| argon2 | C implementation of Argon2 - password hashing function |
| arirang | powerful webserver security scanner for network |
| badkeys | check cryptographic keys for known weaknesses |
| bfbtester | brute force binary tester |
| boofuzz | extensible network protocol fuzzer |
| botan2 | crypto and TLS for C++11 |
| bounix | Back Orifice Unix client by the cDc |
| c2sp-testvectors | community cryptography specification project test vectors |
| ccid | USB Chip/Smart Card Interface Devices driver |
| ccrypt | encrypt and decrypt AES files and streams |
| certspotter | Certificate Transparency log monitor |
| cfssl | CloudFlare PKI/TLS command-line toolkit and HTTP API server |
| cgichk | scans webservers for vulnerable CGI programs |
| chrootuid | control chroot and su access rights by application |
| clamav | virus scanner |
| clusterssh | secure concurrent multi-server terminal control |
| corkscrew | HTTP tunneling utility for SSH |
| cracklib | sensible unix password cracker |
| crowdsec | lightweight and collaborative security engine |
| crowdsec-firewall-bouncer | CrowdSec bouncer written in golang for firewalls |
| cvechecker | local CVE checker tool |
| cyberchef | cyber swiss army knife |
| cyrus-sasl-xoauth2 | XOAUTH2 mechanism plugin for cyrus-sasl |
| cyrus-sasl2 | RFC 2222 SASL (Simple Authentication and Security Layer) |
| dante | SOCKS client and server |
| dirb | web content scanner |
| distorm3 | powerful disassembler library for x86/amd64 |
| dropbear | small SSH server and client |
| dsniff | sniffing tools for penetration testing |
| easy-rsa | small RSA key management package |
| ejabberd-dovecot-auth | authenticate ejabberd against dovecot |
| emldump | analyze MIME files |
| encfs | fuse-based cryptographic filesystem |
| exploitdb | archive of public exploits and shellcode |
| fcrackzip | ZIP password cracker |
| fierce | DNS reconnaissance tool for locating non-contiguous IP space |
| foremost | forensic data recovery program |
| fragrouter | tool for testing network IDS implementations |
| fwbuilder | firewall GUI |
| fwknop | firewall knock operator |
| ghidra | software reverse engineering (SRE) framework |
| gnupg | GNU privacy guard - a free PGP replacement |
| gnutls | GNU Transport Layer Security library |
| gobuster | tool used to brute-force stuff |
| gopass | pass compatible password manager written in go |
| gosec | security checker for Go projects |
| gpa | graphical interface for GnuPG |
| gpgme | GnuPG Made Easy |
| gpgmepp | GnuPG Made Easy C++ bindings |
| gringotts | GTK+2 secure notes manager |
| hashdeep | tools to compute hashes recursively |
| hashid | Identify the different types of cryptographic hashes |
| hcxtools | convert pcap dumps to hashcat or John the Ripper input |
| heimdal | Kerberos 5 implementation |
| hydra | parallelized network logon cracker |
| integrit | file integrity checker |
| ipguard | protect LAN IP address space by ARP spoofing |
| isic | IP stack integrity checker |
| john | extremely fast password cracker |
| john-jumbo | extremely fast password cracker, with community patches |
| kc | console based password storing application |
| keepassxc | management tool for passwords and sensitive data |
| keybase | client for keybase.io |
| keychain | front-end to ssh-agent and gpg-agent |
| keycloak | Identity and Access Management solution |
| keyringer | manage and share secrets using GnuPG and Git |
| knockpy | subdomain scanner |
| kpcli | cli browser for keepassx databases |
| lastpass-cli | LastPass command line interface tool |
| lego | Let's Encrypt/ACME client written in Go |
| libassuan | IPC library used by GnuPG and gpgme |
| libb2 | library providing BLAKE2b, BLAKE2s, BLAKE2bp, BLAKE2sp |
| libbde | access the BitLocker Drive Encryption encrypted volumes |
| libdigidocpp | library for creating DigiDoc signature files |
| libewf | access the Expert Witness Compression Format |
| libfprint | library for fingerprint reader devices |
| libgcrypt | crypto library based on code used in GnuPG |
| libgpg-error | error codes for GnuPG related software |
| libgringotts | encryption backend |
| libgsasl | GNU implementation of the SASL framework |
| libident | library to interface the ident protocol server (rfc1413) |
| libksba | X.509 library |
| libmcrypt | interface to access block/stream encryption algorithms |
| libmodsecurity | intrusion detection and prevention engine |
| libnettle | cryptographic library |
| libotr | portable OTR messaging library and toolkit |
| libpwquality | library to generate, and check strengh of passwords |
| libscrypt | shared library that implements scrypt() functionality |
| libsodium | library for network communications and cryptography |
| libsrtp | secure RTP library |
| libssh | C library implementing server and client side SSH |
| libssh2 | library implementing the SSH2 protocol |
| libtasn1 | Abstract Syntax Notation One structure parser library |
| logsentry | logfile auditing tool |
| luasec | lua binding to OpenSSL to provide TLS/SSL communication |
| lynis | security auditing tool |
| mbedtls | TLS library with an intuitive API and readable source code |
| mcrypt | extendable encryption program that supports many ciphers |
| mhash | strong hash library |
| minisign | dead simple tool to sign files and verify digital signatures |
| mitmproxy | interactive intercepting HTTP proxy |
| netpgp | BSD-licensed PGP implementation |
| nfsshell | NFS auditing tool |
| nikto | web and CGI vulnerability scanner with SSL support |
| nss | libraries to support development of security-enabled apps |
| nuclei | fast and customizable vulnerability scanner |
| oath-toolkit | toolkit for OATH/HOTP and TOTP |
| ogvt | simple tool for verifying gpg signatures |
| oledump | analyze OLE files |
| oletools | python tools to analyze OLE files |
| onesixtyone | efficient SNMP scanner |
| opendnssec | open-source turn-key solution for DNSSEC |
| openpam | Pluggable Authentication Module |
| opensc | set of libraries and utilities to access smart cards |
| openssl-ruby-tests | sources of the Ruby OpenSSL gem for regression testing |
| ophcrack | password cracker based on rainbow tables |
| opm | minimalistic password manager written in shell |
| opmsg | a replacement for gpg which can encrypt/sign/verify |
| ossec-hids | host-based intrusion detection system |
| osv-scanner | scan your project's dependencies for vulnerabilities |
| otpcalc | OTP and S/Key calculator for X |
| outguess | universal steganography tool |
| p0f | passive OS fingerprinting tool |
| p0f3 | passive OS fingerprinting tool |
| p11-kit | library for loading and enumerating PKCS\#11 modules |
| p5-Alt-Crypt-RSA-BigInt | RSA public-key cryptosystem, using Math::BigInt |
| p5-Auth-Yubikey_Decrypter | decrypt one-time-password for a YubiKey |
| p5-Authen-Htpasswd | read and modify Apache .htpasswd files |
| p5-Authen-NTLM | perl interface to the NTLM authentication mechanism |
| p5-Authen-OATH | OATH One Time Passwords |
| p5-Authen-Radius | Perl module to authenticate against a RADIUS server |
| p5-Authen-SASL | perl interface to the SASL auth framework |
| p5-Authen-SASL-Authd | client authentication via Cyrus or Dovecot |
| p5-Authen-WebAuthn | library to add Web Authentication support to server |
| p5-Catalyst-Authentication-Store-DBI | storage class for Catalyst Authentication using DBI |
| p5-Catalyst-Authentication-Store-DBIx-Class | storage class for Catalyst Authentication using DBIx::Class |
| p5-Catalyst-Plugin-Authentication | Catalyst authentication framework |
| p5-Catalyst-Plugin-Authentication-Store-DBIC | CDBI Authentication for Catalyst |
| p5-Catalyst-Plugin-Authentication-Store-Htpasswd | catalyst authentication via .htpasswd |
| p5-Catalyst-Plugin-Authorization-ACL | ACL support for Catalyst applications |
| p5-Catalyst-Plugin-Authorization-Roles | role based authorization for Catalyst |
| p5-Chipcard-PCSC | perl interface to PC/SC smartcards |
| p5-Crypt-Argon2 | interface to the Argon2 key derivation functions |
| p5-Crypt-Blowfish | interface to the Blowfish encryption algorithm |
| p5-Crypt-Blowfish_PP | Blowfish encryption implemented pure Perl |
| p5-Crypt-CAST5_PP | CAST5 block cipher in pure Perl |
| p5-Crypt-CBC | cryptographic cipher block chaining mode |
| p5-Crypt-CipherSaber | cryptographic CipherSaber encryption |
| p5-Crypt-Curve25519 | generate shared secret using ECDH function |
| p5-Crypt-DES | interface to the DES encryption algorithm |
| p5-Crypt-DES-EDE3 | Triple-DES EDE encryption/decryption |
| p5-Crypt-DSA | DSA signatures and key generation |
| p5-Crypt-Ed25519 | bare-bones Ed25519 public key signing/verification system |
| p5-Crypt-Eksblowfish | the Eksblowfish block cipher |
| p5-Crypt-IDEA | Perl interface to IDEA block cipher |
| p5-Crypt-LE | Let's Encrypt API interfacing module and client |
| p5-Crypt-OpenPGP | Pure-Perl OpenPGP implementation |
| p5-Crypt-OpenSSL-Bignum | OpenSSL's multiprecision integer arithmetic#' |
| p5-Crypt-OpenSSL-DSA | implements DSA using OpenSSL |
| p5-Crypt-OpenSSL-EC | EC using OpenSSL |
| p5-Crypt-OpenSSL-ECDSA | ECDSA encoding and decoding using OpenSSL |
| p5-Crypt-OpenSSL-Guess | guess OpenSSL include path |
| p5-Crypt-OpenSSL-PKCS10 | perl extension to OpenSSL PKCS10 API |
| p5-Crypt-OpenSSL-RSA | RSA encoding and decoding using OpenSSL |
| p5-Crypt-OpenSSL-Random | routines for accessing the OpenSSL prng |
| p5-Crypt-OpenSSL-X509 | access OpenSSL X509 API from Perl |
| p5-Crypt-PBKDF2 | PBKDF2 password hash algorithm |
| p5-Crypt-PKCS10 | Perl extension to parse PKCS \#10 certificate requests |
| p5-Crypt-PasswdMD5 | md5-based passwords in perl |
| p5-Crypt-RC4 | implementation of the RC4 encryption algorithm |
| p5-Crypt-RC5 | implementation of the RC5 encryption algorithm |
| p5-Crypt-RIPEMD160 | Perl extension for the RIPEMD-160 Hash function |
| p5-Crypt-Rijndael | interface to the rijndael encryption algorithm aka AES |
| p5-Crypt-SSLeay | library to provide LWP https support via OpenSSL |
| p5-Crypt-SaltedHash | object oriented interface to create salted hashes |
| p5-Crypt-SmbHash | Perl module implementing lanman and nt md4 hash functions |
| p5-Crypt-SysRandom | perl interface to system randomness |
| p5-Crypt-TripleDES | implementation of 3DES encryption on ECB mode |
| p5-Crypt-Twofish | module to implement the Twofish cipher |
| p5-Crypt-URandom | provide non blocking randomness |
| p5-Crypt-X509 | parse an X.509 certificate |
| p5-CryptX | cryptographic toolkit for Perl |
| p5-Digest-BubbleBabble | module to bubble-babble fingerprints |
| p5-Digest-HMAC | keyed-hashing for message authentication |
| p5-Digest-MD2 | perl interface to the MD2 Algorithm |
| p5-Digest-MD4 | interface to md4 message-digest algorithm |
| p5-Digest-MD5-M4p | perl interface to a variant of the MD5 algorithm |
| p5-Digest-Nilsimsa | module to calculate Nilsimsa digests |
| p5-Digest-Perl-MD5 | perl implementation of Ron Rivests MD5 Algorithm |
| p5-Digest-SHA1 | module to calculate SHA1 digests |
| p5-Digest-SHA3 | Perl extension for SHA-3 |
| p5-Digest-Skein | interface to the Skein digest algorithm |
| p5-Digest-ssdeep | Pure Perl ssdeep (CTPH) fuzzy hashing |
| p5-File-Scan-ClamAV | client class for the ClamAV clamd virus scanner daemon |
| p5-GPG | perl5 interface to GnuPG using scalars |
| p5-GnuPG | perl5 interface to GnuPG |
| p5-GnuPG-Interface | perl5 interface to GnuPG |
| p5-IO-Socket-SSL | Perl SSL sockets with IO::Socket interface |
| p5-MD5 | interface to md5 message-digest algorithm |
| p5-Module-Signature | module signature file manipulation |
| p5-Mojolicious-Plugin-Authentication | authentication plugin for the Mojolicious Perl framework |
| p5-Mozilla-CA-Fake | access system SSL certificate bundle from Perl |
| p5-Net-SSL-ExpireDate | obtain expiration date of SSL certificate |
| p5-Net-SSLGlue | add/extend SSL support for common perl modules |
| p5-Net-SSLeay | Perl bindings for OpenSSL and LibreSSL |
| p5-PGP-Sign | perl module to create/verify PGP signatures |
| p5-POE-Component-SSLify | make use of SSL with POE |
| p5-Text-Password-Pronounceable | generate pronounceable passwords |
| p5-Tie-EncryptedHash | hashes with encrypting fields |
| p5-Unix-OpenBSD-Random | interface to arc4random(3) on OpenBSD |
| paperkey | OpenPGP private key backup utility suitable for printing |
| pass-import | importer for pass (passwordstore) |
| pass-otp | OTP extension for password-store |
| passphraseme | passphrase generator using EFF's wordlists |
| passwdqc | complexity checker for passwd(1) and password generator |
| password-gorilla | cross-platform password manager |
| password-store | simple password store |
| pcsc-cyberjack | REINER SCT cyberJack chipcard reader driver |
| pcsc-lite | resource manager for PC/SC |
| pcsc-tools | tools for use with PC/SC drivers, cards, readers |
| pdf-parser | parse a PDF document |
| pdfcrack | password recovery tool for PDF-files |
| pdfid | tool to test a PDF file |
| pebble | small test server for RFC 8555 (ACME) |
| pecl-mcrypt | PHP bindings for the libmcrypt library |
| pgp5 | Pretty Good Privacy 5.0i (world wide use) |
| pgpdump | PGP packet visualizer |
| pidgin-otr | allows deniable private conversations using Pidgin |
| pinentry | PIN or passphrase entry dialog (ncurses interface) |
| pinentry-dmenu | pinentry for tiling window manager |
| pivy | tools for using PIV tokens as an SSH agent, encryption, etc. |
| pixiewps | offline bruteforce of WPS pins |
| pizauth | OAuth2 authentication daemon |
| pkcs11-helper | library with PKCS\#11 providers for end-user applications |
| plaso | engine and tools to automate creation of super timeline |
| plass | manage passwords |
| portscanner | simple and easy to use TCP port scanner |
| portsentry | port scan detection and active defense |
| ppgen | secure passphrase generator |
| pwgen | simple password generator |
| pwsafe | program that manages encrypted password databases |
| py-M2Crypto | crypto and TLS toolkit for Python |
| py-PyNaCl | Python binding to the NaCl library |
| py-aes | pure-Python implementation of AES block-cipher |
| py-argon2-cffi | argon2 password hashing for Python |
| py-argon2-cffi-bindings | argon2 password hashing for Python |
| py-artifacts | ForensicArtifacts.com Artifact Repository |
| py-asn1crypto | fast ASN.1 parser and serializer |
| py-asyncssh | SSHv2 library built on asyncio |
| py-axolotl | Python port of libaxolotl |
| py-axolotl-curve25519 | Python curve25519 library with ed25519 signatures |
| py-bcrypt | bcrypt blowfish password hashing for Python |
| py-cryptodome | self-contained cryptographic library for Python |
| py-cryptodome-test-vectors | test vectors for pycryptodome |
| py-cryptodomex | self-contained cryptographic library for Python |
| py-cryptography | cryptographic recipes and primitives for Python |
| py-cryptography_vectors | test vectors for py-cryptography |
| py-dfdatetime | Digital Forensics date and time |
| py-dfvfs | Digital Forensics Virtual File System (dfVFS) |
| py-dfwinreg | Digital Forensics Windows Registry (dfWinReg) |
| py-duo_client | Python library for interacting with Duo APIs |
| py-duo_universal | Duo Python two-factor authentication |
| py-ecdsa | Python implementation of ECDSA cryptography |
| py-fastecdsa | fast elliptic curve digital signatures |
| py-fickling | analyze Python pickle object serializations |
| py-fido2 | Python module to communicate with USB FIDO devices |
| py-gnupg | Python module for GnuPG interface |
| py-google-auth | Google authentication library |
| py-gssapi | Python bindings to GSSAPI C libraries |
| py-hkdf | HMAC-based Extract-and-Expand Key Derivation Function (HKDF) |
| py-hvac | Python client library for Hashicorp Vault |
| py-in-toto | framework to protect supply chain integrity |
| py-josepy | Javascript Object Signing and Encryption (JOSE) |
| py-keyring | store and access your passwords safely |
| py-krb5 | krb5 API interface |
| py-kyber | pure Python ML-KEM / CRYSTALS-Kyber implementation |
| py-libnacl | Python bindings for libsodium/tweetnacl based on ctypes |
| py-miasm | reverse engineering framework in Python |
| py-mitmproxy_rs | Rust components used in mitmproxy |
| py-oauthlib | Python library for OAuth |
| py-omemo-dr | Gajim's fork of py-axolotl |
| py-openssl | Python interface to the OpenSSL library |
| py-paramiko | low-level pure Python implementation of SSHv2 |
| py-passlib | Python module providing a password hashing framework |
| py-pbkdf2 | Python implementation of PBKDF2 |
| py-pefile | Python module to read and work with PE files |
| py-pgpdump | PGP packet parser library for Python |
| py-potr | pure Python Off-The-Record encryption |
| py-pykeepass | interact with keepass databases from Python |
| py-pyotp | Python library for one-time passwords |
| py-pyscard | smartcard package for Python |
| py-pyu2f | library for interacting with a U2F device over USB |
| py-requests-aws4auth | AWS v4 authentication for py-requests |
| py-ropper | ROP gadget finder and binary information tool |
| py-rsa | Python RSA implementation |
| py-scp | scp module for Paramiko |
| py-scrypt | support for the scrypt key derivation function |
| py-secretstorage | secure storing of passwords using the SecretService DBus API |
| py-securesystemslib | library providing cryptographic and general-purpose routines |
| py-service_identity | service identity verification for pyOpenSSL/py-cryptography |
| py-spake2 | SPAKE2 password-authenticated key exchange (pure Python) |
| py-spnego | SPNEGO authentication library |
| py-ssh2-python | Python bindings for libssh2 |
| py-tlsfuzzer | fuzzer and test suite for TLS implementations. |
| py-trustme | quality TLS certs while you wait, for the discerning |
| py-yaswfp | Yet Another SWF Parser |
| py-zxcvbn | realistic password strength estimator |
| qca-qt5 | Qt Cryptographic Architecture |
| qca-qt6 | Qt Cryptographic Architecture |
| qdigidoc4 | DigiDoc4 GUI client for signing and encrypting documents |
| qgpgme | GnuPG Made Easy Qt bindings |
| qtkeychain | Qt API to store passwords and other secret data |
| qtpass | multi-platform GUI for password-store |
| radiusniff | radius sniffer |
| rarcrack | rar, 7zip and zip password bruteforcer |
| rbw | command line BitWarden client |
| reaver | online brute force WPS PINs |
| recon-ng | web reconnaissance framework |
| regripper | Windows Registry data extraction tool |
| reop | create and verify cryptographic signatures |
| rhash | utility and library for computing hash sums |
| rnp | high performance C++ OpenPGP library and tools |
| routersploit | The Router Exploitation Framework |
| rp++ | fast ROP gadget finder for multiple targets |
| ruby-argon2 | Ruby binding for the argon2 password hashing algorithm |
| ruby-bcrypt | Ruby binding for the bcrypt() password hashing algorithm |
| ruby-cms_scanner | framework to implement CMS scanners |
| ruby-ed25519 | ruby binding Ed25519 EC public-key signature system |
| ruby-gpgme | Ruby language binding for gpgme |
| ruby-pledge | ruby wrapper for pledge(2) and unveil(2) |
| ruby-rbnacl | Ruby binding for libsodium/NaCl |
| ruby-rotp | Ruby library for generating and verifying one time passwords |
| rust-openssl-tests | source of the rust-openssl crate for regression testing |
| rust-ring | ring crate source patched for x-only assembly |
| scanlogd | TCP port scan detection tool |
| scanssh | SSH remote version scanner |
| scrypt | command-line encryption using scrypt key derivation function |
| sequoia-sq | Sequoia-PGP command line tool |
| shash | generates or checks digests or mac |
| smtpscan | Remote SMTP Server Detection |
| smurflog | logs smurf attacks |
| sn0int | semi-automatic OSINT framework and package manager |
| snort2pf | block "nasty" hosts with pf(4) based on Snort's rules |
| softhsm2 | software PKCS\#11 cryptographic token |
| sops | tool for managing secrets |
| spiped | utility for creating secure pipes between socket addresses |
| sqlmap | penetration testing tool to detect/exploit SQL injection |
| squealer | filesystem secrets scanner |
| ssdeep | fuzzy hashing program and library |
| ssh-askpass-fullscreen | good-looking ssh-agent pass-phrase dialog |
| ssh-audit | ssh configuration security auditing tool |
| ssh-ldap-helper | fetch ssh AuthorizedKeys from LDAP |
| sshguard | protect against brute force attacks on sshd and others |
| sshlockout | protect against brute force attacks on sshd(8) |
| sslscan | SSL/TLS scanner (identify version, ciphers, etc) |
| sslsplit | transparent and scalable SSL/TLS interception |
| ssss | split secrets using Shamir's Secret Sharing Scheme |
| stegdetect | steganography detection tool (unmaintained) |
| steghide | software able to hide data in various kind of files |
| stegseek | lightning fast steghide cracker |
| step-ca | private certificate authority and ACME server |
| step-cli | swiss army knife for working with X509, OAuth, JWT, OATH OTP |
| strobe | fast scatter/gather TCP port scanner |
| stunnel | SSL encryption wrapper for standard network daemons |
| sudo | execute a command as another user |
| suricata | high performance network IDS, IPS and security monitoring |
| swatch | simple log monitoring program |
| tclgpg | Tcl interface to GNU Privacy Guard |
| tcltls | OpenSSL Tcl extension |
| tfsec | static analyzer for Terraform |
| theharvester | information gathering suite |
| tinyssh | minimal SSH server implementation, run from inetd |
| towitoko | library and utilities for towitoko card readers |
| uacme | lightweight C ACMEv2 client, uses external authenticators |
| vault | secure secret storage |
| vaultwarden | unofficial bitwarden compatible server |
| veracrypt | free open source disk encryption software |
| volatility3 | volatile memory extraction framework |
| wapiti | web-application vulnerability scanner |
| web-eid-app | native messaging host for Web eID browser extension |
| wesng | Windows Exploit Suggester - Next Generation |
| wfuzz | web fuzzer |
| wpa_supplicant | IEEE 802.1X supplicant |
| wpscan | WordPress security scanner |
| wycheproof | test vectors from C2SP's Project Wycheproof |
| xca | create and manage certificates, CSRs, keys, etc |
| xmlsec | XML security library |
| yubiserve | standalone Yubikey validation server |
| zaproxy | web application security tool |
| zkt | DNSsec Zone Key Tool |