2FAuth
A self-hosted two-factor authentication token manager that stores and generates TOTP and HOTP codes through a web interface.
Secrets management, identity, VPN gateways and CIS-benchmarked hardened base images. Browse all 82 products in this category from WIEWAVE's published marketplace catalog — each one a hardened, maintained image you can deploy from your own cloud account.
Search the full catalogSelect any image for its supported distributions, marketplace availability and common questions.
A self-hosted two-factor authentication token manager that stores and generates TOTP and HOTP codes through a web interface.
A tool that automates ACME protocol challenges to obtain and renew Let's Encrypt SSL/TLS certificates.
A Windows Server domain controller that provides centralised identity, authentication, and Group Policy management.
A self-hosted email alias and forwarding service, formerly AnonAddy, that lets users create anonymous addresses to protect their real inbox.
Identity provider and access management server supporting OIDC, SAML, LDAP and MFA, deployed with its PostgreSQL database, Redis cache and web interface.
Open-source authentication server offering passwordless login, social sign-in, MFA and user management through OIDC-compatible APIs and a hosted admin portal.
Static analysis tool that scans Python source for common security issues such as hardcoded credentials, unsafe subprocess calls and weak cryptography.
Low-code honeypot framework written in Go that emulates SSH, HTTP and TCP services, optionally using an LLM to fake convincing shell responses.
HashiCorp's identity-based access proxy brokering just-in-time sessions to SSH, RDP and database targets without distributing network credentials to end users.
Web application firewall and reverse proxy built on NGINX, applying ModSecurity rules, bot detection, rate limiting and automatic Let's Encrypt certificates.
Helper controller from the cert-manager project that injects CA certificate bundles into Kubernetes webhook configurations, API services and custom resource definitions.
Incident response and security orchestration platform providing alert ticketing, automation playbooks and artifact enrichment for SOC analysts working through investigations.
Admission webhook component for cert-manager that validates and mutates certificate resources and enables DNS-01 solvers when issuing ACME certificates in Kubernetes.
RHEL hardened to the CIS Level 1 server profile with SELinux enforcing and an OpenSCAP scan result shipped alongside.
Ubuntu built against the CIS Benchmark Level 1 profile, with auditd, the remediation scripts and a compliance report included.
Open-source antivirus engine with the clamd daemon, freshclam signature updater and command-line scanner suited to mail gateways and file servers.
Antivirus scanning appliance built on ClamAV, preconfigured with scheduled filesystem scans, automatic signature updates and quarantine handling for Linux servers.
OpenLDAP-based directory server providing centralised user and group authentication over LDAP and LDAPS, with a web administration interface for entry management.
Sigstore tool for signing and verifying container images and artifacts, supporting keyless signing, attestations, OCI registries and transparency log lookups.
Capture-the-flag platform for running security competitions, providing challenge management, scoreboards, team registration and a plugin and theme system.
Image intended for encrypting data at rest and in transit and managing keys; the specific components depend on the publisher's build.
OpenID Connect identity provider that federates authentication to LDAP, SAML and upstream OAuth providers, commonly used in front of Kubernetes clusters.
Command-line web content scanner that brute-forces directories and files on HTTP servers using wordlists, packaged with its default dictionary set.
Windows Server image promoted to Active Directory Domain Services, providing Kerberos authentication, LDAP directory services, DNS and Group Policy for a domain.
EveBox is a web-based viewer for browsing and triaging Suricata EVE JSON alert and event logs from network intrusion detection systems.
Fail2ban is an intrusion prevention tool that scans log files and automatically bans IP addresses showing signs of malicious activity such as repeated failed logins.
Falco is a CNCF runtime security tool that detects anomalous behaviour in containers, Kubernetes and hosts using kernel-level system call monitoring.
ffuf is a fast, Go-based command-line web fuzzer used for discovering hidden directories, files and parameters during penetration testing.
Open-source RADIUS server handling authentication, authorization and accounting for network access, with EAP methods and LDAP or SQL back ends.
Pairs the FreeRADIUS AAA server with daloRADIUS, a PHP web console for managing users, hotspots, NAS devices and accounting records in MySQL.
Django application used by offensive security teams to track engagements, clients, infrastructure and findings, and to generate consistent penetration test reports.
Phishing simulation framework for security awareness programmes, providing campaign templates, landing pages, SMTP sending profiles and per-recipient click and credential tracking.
Authentication server for passwordless login, implementing passkeys and WebAuthn alongside email one-time codes, with drop-in UI components and a Postgres backend.
Adapter service connecting the Trivy vulnerability scanner to Harbor's pluggable scan API so container images in a Harbor registry are scanned on push.
Vault with a durable storage backend, TLS listeners and auto-unseal against the host cloud's KMS.
Access gateway that proxies developer connections to databases, servers and Kubernetes with authentication, approval workflows, session recording and data masking.
Threat intelligence platform that enriches files, domains, IP addresses and hashes by fanning requests out to many analysers and connectors behind one API.
Linux kernel packet filtering administration utility, preinstalled with rule persistence so the VM can act as a stateful firewall or NAT gateway.
Command-line tool for encoding, decoding and verifying JSON Web Tokens, useful for inspecting claims and signing test tokens during development.
Offline password manager storing credentials in an encrypted KDBX database, with key file support, plugins and auto-type for desktop sessions.
Keycloak in production mode behind a reverse proxy, with PostgreSQL storage and hostname configuration already correct.
Command-line utility that imports realm, client and role definitions into Keycloak from version-controlled JSON or YAML, enabling configuration as code.
Sidecar that authenticates incoming requests and authorises them against Kubernetes RBAC before forwarding to an otherwise unprotected upstream such as a metrics endpoint.
Scans clusters, manifests and images against NSA, MITRE and CIS controls, reporting misconfigurations and vulnerabilities from CI or the command line.
ModSecurity version 3 library with connectors for Nginx and Apache, delivering web application firewall rule processing and OWASP Core Rule Set support.
IPsec VPN implementation for Linux supporting IKEv1 and IKEv2, packaged with the pluto daemon and configuration templates for site-to-site tunnels.
Image geared toward sensitive-data discovery and classification across cloud object storage, including the client tooling used to configure and run scans.
Mobile Security Framework performs static and dynamic analysis of Android and iOS applications, inspecting APK and IPA files through a web interface.
Tenable's vulnerability scanner runs credentialed and network assessments against hosts, producing prioritised findings and reports in a local web console.
A network scanning and security auditing tool used to discover hosts, open ports and running services on a network.
A generic Python library implementing the OAuth1 and OAuth2 authorization protocol specifications for building secure authentication flows.
An open-source implementation of the IKEv2 key exchange protocol used to establish and manage IPsec VPN tunnels.
An open-source implementation of the Lightweight Directory Access Protocol for centralised authentication and directory services.
OpenVPN with a working PKI, IP forwarding and firewall rules in place — the parts that usually take an afternoon.
Host-based intrusion detection agent forwarding log analysis, file integrity monitoring and rootkit check results to a central OSSEC or Wazuh manager.
Shadowsocks-based VPN server from Jigsaw's Outline project, administered through generated access keys so users can create censorship-resistant proxy connections.
Self-hosted application for sharing passwords and secrets via links that expire after a set number of views or days, with audit logging.
Pi-hole as a network-wide DNS sinkhole, with upstream resolvers over DNS-over-HTTPS and the admin UI locked down.
Command-line client for Pinniped, which federates external identity providers into Kubernetes clusters and generates short-lived kubeconfig credentials for cluster login.
Microsoft Presidio detects and anonymises personally identifiable information in text and images, combining NLP recognisers with configurable redaction and masking services.
VPN server with a web administration console managing OpenVPN and WireGuard profiles, users and organisations, storing configuration in MongoDB.
Kubernetes controller and kubeseal CLI that encrypt Secrets into SealedSecret resources safe to commit to Git, decrypted only inside the target cluster.
Email alias service that hides a real mailbox behind disposable addresses, supporting forwarding, replies, custom domains and an OIDC login provider.
Network intrusion detection and prevention engine that inspects packets against rule sets, offering logging, alerting and inline blocking modes.
Multi-protocol VPN server supporting its own SSL-VPN protocol plus OpenVPN, L2TP/IPsec and SSTP, with virtual hubs and a management console.
Secrets editor that encrypts values inside YAML, JSON and env files using KMS, age or PGP keys while keeping file structure readable in Git.
OSINT automation tool querying hundreds of data sources to map domains, IP ranges, e-mail addresses and exposed assets, driven from a web UI.
Penetration testing tool automating detection and exploitation of SQL injection flaws, supporting many database backends and out-of-band data retrieval.
Network intrusion detection and prevention engine performing multi-threaded deep packet inspection, with EVE JSON logging and support for Emerging Threats rulesets.
eBPF-based runtime security tool from the Cilium project that records process, file and network events and enforces policy directly in kernel space.
Vaultwarden as a lightweight Bitwarden-compatible password server, behind TLS with backups scheduled.
Preconfigured virtual private network server providing encrypted remote access tunnels, certificate or key based authentication and downloadable client configuration files.
Agentless vulnerability scanner for Linux and FreeBSD servers that matches installed packages against CVE databases and reports findings via terminal or web UI.
Open-source security platform combining host intrusion detection, log analysis, file integrity monitoring and vulnerability detection with an indexer and dashboard.
Python web application fuzzer that brute-forces directories, parameters and credentials by substituting payloads into HTTP requests and filtering the responses.
WireGuard with key generation, peer templates and kernel module verification handled at build time.
Java-based certificate authority and OCSP responder implementing RFC 5280 PKI, with HSM support and a relational database backend for issued certificates.
Pattern-matching engine used by malware researchers to write and run rules against files, memory and processes, with CLI scanner and Python bindings.
OWASP Zed Attack Proxy, an intercepting proxy and dynamic scanner for web application vulnerabilities, with an automation API and headless daemon mode.
Distribution of the OWASP ZAP security testing proxy, including the desktop interface, active and passive scan rules, and the add-on marketplace.
Network security monitor that turns traffic into structured connection, DNS and HTTP logs, with a scripting language for detection; formerly named Bro.
Identity and access management server offering OIDC, OAuth2 and SAML single sign-on, multi-tenancy and passwordless login, backed by PostgreSQL.
Name the product and the distribution — we'll build, harden, certify and publish it on Azure, AWS or Google Cloud Marketplace.