Free cybersecurity stack
Build your own SOC at home.
A curated, opinionated catalogue of free tools the Cyentrix team uses to run a home security operations centre. Every entry has hardware sizing, install notes, suggested configuration, and a short verdict — so you can pick the right tool fast.
- 38 tools covered
- 12 categories SIEM to cloud
- Install + config guidance per tool
- 100% free or free tier
📊 SIEM & log management
Centralise logs, detect anomalies, respond.
Elastic Security
Elastic License v2 / SSPLSIEM and EDR built on the Elastic Stack with strong free-tier rules.
Graylog
SSPL (Open) / CommercialPolished open-source log management with strong search and dashboarding.
Security Onion
Open source (Elastic License + various)All-in-one network security monitoring distribution: Suricata, Zeek, Wazuh, ELK and more.
Wazuh
GPLv2Open-source SIEM and XDR platform with built-in agents for endpoints and servers.
🔎 Vulnerability scanners
Find unpatched and misconfigured assets before attackers.
Nessus Essentials
Proprietary (free tier)Tenable's industry-standard vulnerability scanner, free for up to 16 IPs.
Nuclei
MITFast, template-based vulnerability scanner from ProjectDiscovery.
OpenVAS / Greenbone Community
GPLv2Free, full-featured network vulnerability scanner with 100k+ NVTs.
Trivy
Apache 2.0Container, filesystem, and IaC vulnerability scanner from Aqua Security.
🛰️ Network detection (NIDS/NDR)
Watch traffic for malicious behaviour at the wire.
💻 Endpoint detection (EDR)
Visibility and response on every host.
🗺️ Network scanning & recon
Map what you have. You can't protect what you can't see.
🧠 Threat intelligence
Aggregate, share, and operationalise IoCs.
Cortex
AGPLv3Observable analyser engine that powers TheHive's enrichments.
MISP
AGPLv3Threat intelligence platform for sharing IoCs and structured intel.
OpenCTI
Apache 2.0STIX 2.1-native threat intelligence platform with a polished modern UI.
TheHive
AGPLv3Open-source security incident response platform — case management for SOC teams.
🍯 Honeypots & deception
Detect attackers by what they touch.
🌐 Web application security
Scan, fuzz, and audit your own web apps.
Burp Suite Community
Proprietary (free Community Edition)The industry-standard intercept proxy — free for manual testing.
Nikto
GPLv2Classic web server scanner — fast checks for known issues and misconfigurations.
OWASP ZAP
Apache 2.0Free, full-featured web application security scanner from OWASP.
🔬 DFIR & forensics
Investigate when something goes wrong.
Autopsy
Apache 2.0GUI digital forensics platform built on The Sleuth Kit.
The Sleuth Kit
Common Public License + IBM Public LicenseCommand-line digital forensics library and tools — the engine behind Autopsy.
Volatility 3
Volatility Software License (BSD-style)Industry-standard memory forensics framework.
🛡️ Network & identity defence
DNS filtering, IPS, and zero-trust connectivity.
🎣 Phishing & awareness
Run your own phishing simulations.
☁️ Cloud & container security
Harden Kubernetes, containers, and cloud accounts.