EXAMPLE — mirror installer (replace me)
free DirectSelf-hosted mirror. Drop the real file in apps/dev/public/dl/ and update this entry. This is where Joe keeps installers in case upstream removes them.
Tools worth keeping. Some I host directly here as mirrors so they survive if the source disappears — those are tagged Direct. The rest link out to the vendor, tagged Link. Cost is always labeled: Free or Paid. No affiliate, ever.
Kept on the server in case upstream takes them down — direct download, no redirect.
Self-hosted mirror. Drop the real file in apps/dev/public/dl/ and update this entry. This is where Joe keeps installers in case upstream removes them.
GPU-accelerated, native, fast. The terminal i actually open.
Lua-configurable cross-platform terminal. Fallback when Ghostty isn't available.
Terminal multiplexer. Surviving SSH disconnects since forever.
Cross-shell prompt. Fast, configurable, looks good out of the box.
Command-line fuzzy finder. Ctrl-R will never feel slow again.
grep replacement. Faster than you'd believe.
cat with syntax highlighting and git integration.
Modern ls. Colors, git status, tree mode.
Modal editing the way it should be. LSP, treesitter, the lot.
The big tent editor. Extensions ecosystem nobody can match.
VSCode fork with AI baked in. Tab autocomplete that actually understands context.
Rust-native editor from the Atom alumni. Insanely fast.
The intercepting proxy. Pro tier unlocks the scanner and extensions you actually want.
Modern web proxy. Lighter than Burp. Workflows are first-class.
Template-based vulnerability scanner. Community templates ship daily.
subfinder, httpx, naabu, katana — the recon backbone.
NSA-built reverse engineering platform. Free IDA Pro competitor.
Network protocol analyzer. The ground truth when nothing else makes sense.
All-in-one honeypot platform. The basis for Joe's honeypots.
The scanner. Host discovery, port states, service/version, NSE scripts.
Internet-scale port scanner. Whole /0 in minutes if your link can take it.
Attack-surface mapping and subdomain enumeration done right.
Fast web fuzzer. Content discovery, vhosts, parameters.
Directory, DNS and vhost brute-forcer in Go.
Automatic SQL injection and database takeover.
Free web app proxy/scanner. The open alternative when Burp Pro isn't around.
Search engine for exposed devices and services.
Link-analysis and OSINT graphing. Community edition is free.
Emails, subdomains, hosts and names from public sources.
The distro. Hundreds of tools, preconfigured, maintained.
The exploitation framework. Modules, payloads, post-ex.
Open-source cross-platform C2. The serious free Cobalt Strike alternative.
Modern malleable C2 framework with a clean operator UI.
Plugin-based C2 with a browser UI. Bring your own agent.
The commercial red-team standard. Beacon, malleable C2.
Active Directory attack-path mapping. Community Edition.
Network swiss-army knife (the maintained CrackMapExec successor).
Python classes for network protocols. secretsdump, psexec, ntlmrelayx.
LLMNR/NBT-NS/MDNS poisoner and rogue auth server.
Windows credential extraction. The reason you rotate krbtgt.
World's fastest password recovery. GPU-accelerated.
The other cracker. Jumbo build covers everything.
Wi-Fi security auditing suite. Capture, crack, replay.
Automated adversary emulation mapped to ATT&CK.
Small, portable ATT&CK technique tests. Validate detections.
Full compromise-assessment scanner. Thousands of hand-crafted YARA/Sigma rules.
Free IOC and YARA scanner with the open signature base.
Lightweight Sigma-based endpoint agent. Real-time detection, your rules.
Free Aurora agent on the open Sigma rule set.
Schedule, configure and manage scans across the whole fleet.
Curated high-quality YARA/Sigma rule feed. Thousands, hand-made.
Free simple IOC and YARA scanner. The original from Florian Roth.
Pattern-matching for malware researchers. Write rules, hunt files.
Generic detection rule format. Write once, convert to any SIEM.
Endpoint visibility and DFIR at scale. VQL hunts across the fleet.
Memory forensics framework. Pull secrets and rootkits out of RAM.
High-performance IDS/IPS and network security monitoring.
Network analysis framework. Rich connection logs, not just alerts.
Full-packet capture, indexing and search at scale.
The cyber swiss-army knife. Decode, deobfuscate, transform, in the browser.
Procmon, Autoruns, Procexp and friends. Windows internals, exposed.
The DFIR artifact toolkit — MFTECmd, KAPE, Registry Explorer.
Open-source digital forensics platform on top of Sleuth Kit.
Open-source XDR/SIEM. Agents, detections, compliance.
Free Linux distro for IDS, NSM and log management.
Threat-intelligence sharing platform. IOCs with context.
Docker Desktop replacement. Faster, lighter, also runs linux VMs.
Infra as code. The default for multi-cloud.
Terraform's open-source fork. License-resilient.
Kubernetes TUI. Navigate clusters without kubectl carpal tunnel.
Kubernetes IDE. When you need a UI, this is it.
Spotlight replacement on creatine. Extensions for everything.
Window management with keyboard shortcuts. Free alternative to Magnet.
Password manager. Worth every cent for SSH key delegation alone.
Open-source password manager. Self-hostable.
Notepad calculator. 'how many days until friday' just works.
Collaborative design tool. The default for UI/UX.
Hand-drawn diagrams. The whiteboard tool.
One-time purchase Photoshop/Illustrator. No subscription.
Pro video editing for free (Studio is paid). Color, audio, fusion.
(See cloud) — the fast docker replacement on mac.
Polyglot tool version manager. Replaces asdf + nvm + pyenv + rbenv.
10–100x faster Python package manager from Astral. Replaces pip + venv + pipx.
Fast all-in-one JS runtime, bundler, package manager.
GitHub from the terminal. PRs, issues, releases, gists.
Terminal git UI. Stage hunks, rebase, resolve conflicts without leaving your terminal.
The missing package manager for macOS. Or Linux.
Menubar system monitor. CPU, GPU, network, disk, fans.
Battery charging limit for Mac laptops. Extends battery lifespan.
Screenshot tool that fixes every macOS screenshot pain point.
Menubar system monitor — the paid alternative to Stats.
www.nextron-systems.com ↗ — Florian Roth's shop behind THOR and the largest commercial YARA/Sigma rule base.
Enterprise APT / compromise scanner — 30,000+ YARA and 4,000+ Sigma rules from Valhalla.
Free multi-platform IOC + YARA scanner on the open signature base.
ETW-based endpoint agent applying Sigma rules + IOCs to live Windows events.
Free community edition of the Aurora ETW agent (open Sigma rules).
22,000+ curated YARA + 4,000+ Sigma rules as a subscription feed.
trustedsec.com ↗ — Dave Kennedy's offensive-security shop, keeping a stack of widely-used open-source pentest tools.
The de facto social-engineering pentest framework — phishing, payloads, harvesting.
PowerShell downgrade attack that injects shellcode into memory; CS + Metasploit.
Automates Hashcat cracking methodologies end to end.
Pentest, red team, IR, and security program advisory.
www.huntress.com ↗ — Managed security for SMBs and MSPs — a 24/7 human SOC on top of EDR + identity telemetry.
EDR backed by a 24/7 SOC that triages and remediates real threats.
Identity threat detection for M365 — credential theft, session hijack, BEC.
Full-featured 21-day trial with live SOC coverage, no feature gating.
Free CTFs, labs, and tradecraft writeups from Huntress research.
www.binarydefense.com ↗ — Ohio MDR shop (TrustedSec sister company) running a human-driven SOC + several blue-team tools.
Human-driven MDR with a 24/7 SOC over endpoint, network, and logs.
Open-source honeypot + file/SSH monitoring + alerting for Linux/Windows.
Modular Sysmon config mapped to MITRE ATT&CK.
PowerShell tool to scan live process memory with YARA.
Honeypot for detecting Log4Shell (CVE-2021-44228) scanning.