SecPod

Open-Source
Security Tools

SecPod Labs develops and maintains free command-line open-source tools for vulnerability and exposure management

View on GitHub
$ vex-studio --package lodash@4.17.21
Generating SBOM…
scanning CVEs… SBOM generated, CVE-2021-23337 found
status: not_affected
OpenVEX saved: vex-output.json
$ patchadvisor --cve CVE-2024-3094
CVSS 10.0 CRITICAL — XZ Utils backdoor (liblzma)
fix: apt-get install --only-upgrade xz-utils
$ dnsarmor --domain example.com
DNSSEC ✓ SPF ✓ DMARC ✓
DKIM selector missing
$ _

Open-Source Tools Built by Secpod Labs

01

Vex Studio

A guided VEX authoring tool for open-source maintainers. It generates SBOMs, scans packages for known CVEs, and walks maintainers through CWE-guided exploitability questions to determine whether a flagged vulnerability is exploitable in context. Answers map to standard VEX status values and justification codes, producing an auditable OpenVEX document maintainers can publish downstream reducing false-positive vulnerability alerts at the source.

02

Patch Advisor

A CVE remediation lookup for Linux platforms. Give it a CVE ID and PatchAdvisor pulls confirmed fix data from authoritative sources, then returns the exact apt, yum, or apk command for your distribution — no cross-referencing advisories by hand.

03

DNA Armor

A complete DNS security audit in one run. Checks DNSSEC, SPF, DKIM, and DMARC configuration, zone transfer exposure, subdomain takeover risk, and wildcard records — giving a full picture of a domain's DNS attack surface instantly.

SecPod's Commitment

Our contributions raise the bar for tools the entire industry runs. Open-source tools are meant to solve specific problems teams face today.

OpenVAS

Vulnerability Scanning

A widely deployed open-source vulnerability scanning framework. SecPod contributes detection improvements and expands coverage for newly disclosed threats, strengthening scan accuracy for teams that rely on it for continuous assessment.

Snort

IDS/IPS

One of the most widely deployed open-source intrusion detection and prevention systems. SecPod's threat research and rule development help sharpen detection of suspicious traffic and known attack patterns at the network layer.

MITRE

ATT&CK

MITRE maintains the frameworks the industry uses to reason about attacker behavior. SecPod feeds in research and threat-intelligence insight that aligns with those frameworks, helping teams map detections to real adversary tactics.

SCAP & OVAL

Compliance Automation

Security Content Automation Protocol and Open Vulnerability and Assessment Language standardize how vulnerability management and compliance checks are automated. SecPod actively contributes content that expands vulnerability definitions and configuration checks used across the ecosystem.

SecPod's contributions to
open-source security ecosystems

Our engineering and research teams contribute threat research, and vulnerability content to established open-source security projects, improving coverage for everyone who depends on them, not just SecPod customers.

Rule and detection work contributed to OpenVAS and Snort doesn't just help SecPod customers, it improves scan and detection accuracy for every organization running those tools.

Stay informed on the latest range of free tools from SecPod Labs

Subscribe Now