Maintaining security is a never-ending business. There’s so much to worry about, from misconfigured software to phishing attacks to a rapidly expanding inventory of devices with their own vulnerabilities and update requirements. We could all use a little help to stay on top of things, as we strive to assess where issues lie, protect data effectively, and test the defenses we have put in place to see how robust they really are.
Fortunately, better security doesn’t have to break the bank. There are many excellent free security tools available that can help you take those first practical steps towards some peace of mind.
Adding to CSO’s roundup of the 24 best free security tools, here are 10 more worth your consideration. Try some out and find what works best for you.
1. AT&T Alien Labs Open Threat Exchange (OTX)
2. Sophos XG Firewall Home Edition
3. Imperva Scuba Database Vulnerability Scanner
4. LogRhythm NetMon Freemium
5. KnowBe4 Phish-prone
6. Qualys Cloud Platform Community Edition
7. Sophos Intercept X for Mobile
8. KnowBe4 RanSim
9. Have I Been Pwned?
10. Kali Linux
Powered by a global community of more than 100,000 security professionals, OTX is all about identifying cyberattacks and threats as they emerge. Information is presented that summarizes each threat and informs on how to figure out whether it’s relevant to your organization. This goes beyond which environments are at risk and what is being targeted to look at where attacks originate and the motives behind them. Collaboration through the OTX community can help you validate threats and find strategies for remediation.
With so many people forced to work from home because of COVID, the advantages of having a dedicated firewall as a first line of defense should be considered a basic need. The Sophos XG firewall provides anti-malware protection, web security and URL filtering, traffic shaping, and VPN support among other things. Free and recommended mostly for home users, it requires a spare PC to be installed on.
The Sophos XG firewall could prove valuable for managing internet bandwidth when working from home. It allows users to prioritize traffic and run multiple ISP connections for greater resiliency. And family traffic can be monitored, time limits set, and web browsing filtered. The VPN feature lets you connect securely to your home computer. Throw scanning into the mix for virus protection and you have a smart firewall for serving home office needs.
To combat vulnerabilities and configuration problems, you first have to uncover them. This simple, free scanning tool enables you to scan enterprise databases to identify any potential issues. Not only does Scuba find potential problems, it also offers recommendations on how you can mitigate any issues that were flagged.
The LogRhythm NetMon Freemium offers real-time network-based threat detection and incident response. You can use it for many things, from identifying data exfiltration hidden in normal traffic to exposing bandwidth hogs to detecting botnets. It’s capable of flagging abnormal traffic patterns and application usage. It can also analyze full packet captures.
You’ve been running regular security awareness training, but has it worked? Find out how resistant your staff is to phishing attacks with this phishing attack test. You can sign up and test up to 100 users, customize the attack, and see at a glance how your organization measures up compared to your peers via clear industry benchmarks.
Gaining a clear picture of all of your assets, whether physical devices or cloud-based web apps and containers, is a vital first step in assessing your security. Qualys Community Edition works like a map for scanning your IT infrastructure, including web applications, for the latest known vulnerabilities. Results are presented in a customizable dashboard that you can use to generate reports.
Everyone uses their smartphone for work nowadays. This useful app for Android or iOS is designed to continuously monitor phones to rapidly detect potential malware issues and alert IT administrators, so they can fix or revoke access to corporate resources before a breach occurs. Intercept X for Mobile can identify man-in-the-middle attacks, detect jailbreaking or rooting, and flag required updates.
Do you have effective protection in place to safeguard your organization against ransomware or cryptomining attacks? You may think you do, but you don’t really know until your defenses are put to the test. Rather than wait until an actual attack happens, you can use this free tool to run harmless simulations of real ransomware attacks and find out how your network copes and where the weak spots are.
Millions of accounts are compromised every year through password hacks. Cybercriminals may sell or post hacked accounts online and this can wreak havoc, enabling scammers to steal identities and run more sophisticated phishing scams that allow them to dig deeper into your organization. Plug an email address into this free tool and find out instantly if any accounts associated with that email have been compromised in a data breach.
A great place for cybersecurity professionals to start is with this free operating system that comes fully equipped with a wide range of cybersecurity tools. It serves well as a platform for security work, whether you want a comprehensive exploit database or you’re looking to engage in some penetration testing. All of the apps are open source and there are lots of training materials alongside the project to help get you up to speed.