SecOps-Arsenal is a curated collection of 20+ hands-on cybersecurity tools, scripts, and services designed for education, research, defensive engineering, and authorized security testing. Each tool is a standalone project that teaches essential security concepts through real, runnable implementations.
Getting Started Β· Tool Catalog Β· Contributing Β· Security Policy
- Overview
- Repository Scope
- Tool Catalog
- Quick Start
- Installation
- Architecture
- Technologies
- Supported Platforms
- Security Notice
- Contributing
- Roadmap
- FAQ
- License
- Maintainers
- Acknowledgements
SecOps-Arsenal provides practical, code-driven cybersecurity education organized in a progressive learning path from Beginner to Expert. Unlike theoretical resources, every tool in this repository is a working implementation that you can run, modify, extend, and integrate into your own security lab.
- π§ Learn by building β each tool implements a real cybersecurity concept
- π§ Understand internals β see how detection engines, SOAR platforms, and offensive tools actually work
- π» Portfolio-ready projects β polished, documented tools you can showcase
- π Progressive difficulty β structured path from DNS lookups to SOAR orchestration
- π‘οΈ Defensive-first mindset β offensive tools exist to improve your defenses
This repository is intended for:
- Cybersecurity Education β learning security concepts through implementation
- Defensive Engineering β building detection, monitoring, and response tools
- Research β experimenting with security techniques in controlled environments
- Laboratory Environments β testing tools in isolated security labs
- Authorized Security Assessments β supporting legitimate penetration testing engagements
| # | Tool | Description |
|---|---|---|
| 1 | basic-recon/ |
DNS lookup, IP geolocation, WHOIS queries, Nmap wrapper |
| 2 | credential-check/ |
Password complexity tester + Have I Been Pwned breach lookup |
| 3 | file-integrity/ |
SHA-256 file hashing + integrity monitoring (FIM) |
| 4 | url-scanner/ |
URL safety checker with regex analysis + VirusTotal API |
| # | Tool | Description |
|---|---|---|
| 5 | log-parser/ |
Apache/Nginx log parser + Streamlit visualization dashboard |
| 6 | packet-sniffer/ |
Live network capture via Scapy with protocol inspection |
| 7 | siem-ingest/ |
ELK stack ingestion scripts + Docker Compose setup |
| 8 | alerts/ |
YAML rule-based alert engine (IDS/IPS logic) |
| 9 | windows-monitor/ |
Real-time Windows Event ID monitoring (PowerShell) |
| # | Tool | Description |
|---|---|---|
| 10 | automations/ |
Security playbooks: IP blocking, account locking, email alerts |
| 11 | forensics/ |
Metadata extractor + forensic timeline builder |
| 12 | red-team/ |
SMB enumeration + phishing template generator (educational) |
| 13 | threat-intel/ |
IOC enrichment via AbuseIPDB + AlienVault OTX |
| 14 | web-scanner/ |
HTTP header audit, TLS inspection, common exposure checks |
| 15 | api-security/ |
Automated OWASP API Top 10 security tests |
| # | Tool | Description |
|---|---|---|
| 16 | blue-team/ |
Host hardening auditor for Windows & Linux baselines |
| 17 | correlation-engine/ |
Multi-source log correlation for brute-force + exfiltration detection |
| 18 | incident-response/ |
Automated live-response evidence collector + IR report generator |
| 19 | recon-framework/ |
Multi-threaded subdomain enumeration + directory brute-forcing |
| 20 | orchestration/ |
Dockerized SOAR-lite engine with YAML playbooks |
# Clone the repository
git clone https://github.com/Aakash02A/SecOps-Arsenal.git
cd SecOps-Arsenal
# Create a virtual environment
python -m venv venv
source venv/bin/activate # Linux/macOS
.\venv\Scripts\activate # Windows
# Install all dependencies
pip install -r requirements.txt
# Run a tool β for example, check a password
python credential-check/credential_checker.py "MyP@ssw0rd!"
# Or build a file integrity baseline
python file-integrity/fim.py build ./some-directory- Python 3.11+
- pip (Python package manager)
- Git
| Tool | Required For |
|---|---|
| Nmap | basic-recon/nmap_scanner.py |
| Npcap (Windows) | packet-sniffer/sniffer.py |
| Docker | orchestration/, siem-ingest/ |
pip install -r requirements.txtpip install -r requirements-dev.txt
pre-commit installEach tool's README.md lists its specific dependencies if you prefer to install only what you need.
SecOps-Arsenal/
βββ .github/ # GitHub Actions templates
β βββ workflows/ # GitHub Actions workflow folder
β βββ ISSUE_TEMPLATE/ # Bug report, feature request, tool request
β βββ PULL_REQUEST_TEMPLATE.md
β βββ FUNDING.yml
βββ tests/ # Unit tests (pytest)
βββ alerts/ # π‘ Rule-based alert engine
βββ api-security/ # π΅ API security tester
βββ automations/ # π΅ Security playbooks
βββ basic-recon/ # π’ DNS, WHOIS, IP info, Nmap
βββ blue-team/ # π΄ Host hardening auditor
βββ correlation-engine/ # π΄ Log correlation engine
βββ credential-check/ # π’ Password checker
βββ file-integrity/ # π’ File integrity monitor
βββ forensics/ # π΅ Metadata & timeline tools
βββ incident-response/ # π΄ IR evidence collector
βββ log-parser/ # π‘ Log parser & dashboard
βββ orchestration/ # π΄ SOAR-lite engine (Docker)
βββ packet-sniffer/ # π‘ Network packet sniffer
βββ recon-framework/ # π΄ Subdomain & directory enum
βββ red-team/ # π΅ SMB enum & phishing (educational)
βββ siem-ingest/ # π‘ ELK stack ingestion
βββ threat-intel/ # π΅ IOC enrichment
βββ url-scanner/ # π’ URL safety scanner
βββ web-scanner/ # π΅ Web vulnerability scanner
βββ windows-monitor/ # π‘ Windows event monitor (PS1)
βββ requirements.txt # Global Python dependencies
βββ requirements-dev.txt # Development dependencies
βββ pyproject.toml # Ruff & pytest configuration
βββ CONTRIBUTING.md
βββ CODE_OF_CONDUCT.md
βββ SECURITY.md
βββ SUPPORT.md
βββ CHANGELOG.md
βββ LICENSE # MIT License
| Category | Technologies |
|---|---|
| Languages | Python 3.11+ (primary), PowerShell, Bash |
| Core Libraries | requests, scapy, pyyaml, dnspython, python-nmap |
| Visualization | Streamlit, Plotly, Pandas |
| Infrastructure | Docker, Docker Compose, ELK Stack |
| CI/CD | GitHub Actions |
| Quality | Ruff (lint + format), pytest, pre-commit, pip-audit |
| Platform | Status | Notes |
|---|---|---|
| Windows 10/11 | β | Full support. PowerShell tools are Windows-native. |
| Ubuntu / Debian | β | Full support. Tested on Ubuntu 22.04+. |
| macOS | Most tools work. Some system-level scripts (firewall, account management) are Windows/Linux only. | |
| Docker | β | Containerized tools available for orchestration/ and siem-ingest/. |
β οΈ IMPORTANT: Responsible UseThe tools in this repository are provided for educational purposes, authorized security research, and legitimate penetration testing only. By using these tools, you agree to:
- Only use tools against systems you own or have explicit written authorization to test
- Comply with all applicable laws in your jurisdiction
- Not use these tools for unauthorized access, data theft, or any malicious purpose
- Report vulnerabilities responsibly following our Security Policy
The maintainers are not responsible for misuse of any tool in this repository.
For security vulnerability reports, see SECURITY.md.
We welcome contributions! Whether you're fixing a bug, adding a new tool, or improving documentation, your help is appreciated.
- Read the Contributing Guidelines
- Review the Code of Conduct
- Check open issues for tasks labeled
good first issue - Fork, branch, code, test, and submit a PR
See CONTRIBUTING.md for full development environment setup and coding standards.
- Expand test coverage to all 20 tools
- Add Malware Analysis toolkit (static analysis, YARA rules)
- Add Cloud Security module (AWS/GCP misconfiguration scanner)
- Add Network Security module (port knocking, ARP spoofing detection)
- Interactive web dashboard consolidating all tools
- Plugin architecture for community tool extensions
- Integration with MITRE ATT&CK framework
- Pre-built Docker lab environments with intentionally vulnerable targets
- AI-assisted threat detection module
- Full CTF challenge platform using the tools
- Certification-aligned learning paths (Security+, CEH, OSCP)
Is this repository safe to use?
Yes. All tools are designed for educational use and authorized testing. Offensive tools include prominent disclaimers. No tool contains malware, backdoors, or destructive payloads.
Do I need all the dependencies?
No. Each tool's README.md lists its specific requirements. The root requirements.txt installs everything for convenience, but you can install selectively.
Can I use these tools in production?
These tools are educational and not hardened for production use. They are excellent for learning, prototyping, and lab environments, but production security infrastructure should use battle-tested solutions.
What Python version do I need?
Python 3.11 or higher is recommended. The CI pipeline tests against Python 3.11 and 3.12.
How do I report a security vulnerability?
Do NOT open a public issue. Follow our Security Policy for responsible disclosure.
This project is licensed under the MIT License β see the LICENSE file for details.
| Aakash |
- OWASP β API Security Top 10 and web security standards
- Have I Been Pwned β Breached password API
- AbuseIPDB & AlienVault OTX β Threat intelligence APIs
- VirusTotal β URL reputation API
- Elastic β ELK Stack
- Contributor Covenant β Code of Conduct
- The open-source cybersecurity community
Built with β€οΈ for the cybersecurity community