Loading...
Endpoint security covers the tools that defend the devices where your people actually work: laptops, desktops, servers, mobile phones, and the browsers running on all of them. It is the layer that has absorbed the most change in the last decade, moving from signature-based antivirus to behavioral EDR, then stretching to cover cloud server workloads, mobile fleets, and the browser as a control point. The category spans prevention (endpoint protection platforms, workload protection), detection and response (EDR, file integrity monitoring), mobile (device management, threat defense, data protection), and the browser frontier (secure enterprise browsers, remote browser isolation). If you own the endpoint, you own the place attackers land first, which is why this is usually where security programs spend real money and where consolidation decisions hurt the most.
We cover 371 Endpoint Security tools, 57 free and 314 commercial.
Accuracy and depth improve over time. Last reviewed Jul 2026. Is something off? Reach out.
Browser security for the AI era.
A bash-based anti-forensic script that monitors USB ports and triggers system shutdown when unauthorized devices are detected.
A Windows security hardening tool that disables potentially dangerous features in Windows 10/11 and common applications to reduce attack surface for individual users.
A security checklist app for your Mac that helps you with basic security hygiene and prevents 80% of problems.
A script that validates Group Policy Object audit settings required for proper Microsoft Defender for Endpoint functionality.
A repository containing scripts and configuration files to help administrators implement Microsoft AppLocker for application whitelisting based on NSA security guidelines.
Firejail is a Linux sandbox program that isolates untrusted applications using kernel namespaces, seccomp-bpf, and capabilities to reduce security breach risks.
A cross-platform software library for interacting with iOS devices without jailbreaking.
An Android-based self-defense application against forensic imaging tools like Cellebrite UFED.
An anti-forensic kill-switch tool for USB ports to shut down the computer immediately in case of unauthorized access.
A daemon for blocking USB keystroke injection devices on Linux systems
Santa is a macOS binary and file access authorization system that monitors executions and makes allow/block decisions based on local database rules.
Fleet is an open-source endpoint management platform that provides device management, vulnerability reporting, and security monitoring capabilities for IT and security teams managing large computer environments.
Falco is a CNCF graduated runtime security tool that monitors Linux kernel events and syscalls to detect abnormal behavior and security threats in cloud native environments.
MIDAS (Mac Intrusion Detection Analysis System) - archived and no longer supported.
Firewall, Blackhole, and Privatizing Proxy for macOS with comprehensive security features.
DocBleach is a Content Disarm and Reconstruction software that sanitizes Office documents by removing potentially malicious dynamic content to prevent security threats.
A laser tripwire device that automatically hides windows, locks computers, or executes custom scripts when motion is detected within 120cm range.
Real-time, eBPF-based Security Observability and Runtime Enforcement component
Stronghold is the easiest way to securely configure your Mac.
Enhances Windows OS security through system modifications and settings adjustments.
AMDH is a Python3 Android security tool that automates mobile device hardening through malware detection, privacy protection, CIS benchmark compliance, and application security analysis.
An anti-forensic Linux Kernel Module kill-switch for USB ports.
OSSEC is a versatile HIDS known for its powerful log analysis and intrusion detection capabilities.
OpenEDR is an open-source platform enhancing cybersecurity through real-time detection and analysis of cyber threats.
371 tools across 9 specializations · 57 free, 314 commercial
Endpoint Protection Platform
Endpoint Protection Platforms (EPP) that prevent threats on user endpoints such as laptops and desktops, combining antivirus, NGAV, anti-malware, and firewall.
Workload Protection
Host-agent runtime protection and hardening of servers and workloads (Windows/Linux, on-prem or hosting) — server security, runtime integrity, OS hardening.
FIM
File Integrity Monitoring (FIM) tools that detect unauthorized changes to critical files, system configurations, and registries on hosts — change detection + compliance (e.
Tool roundups, buying guides, and strategic analysis from the CybersecTools resource library.
Common questions about Endpoint Security tools, selection guides, pricing, and comparisons.
Endpoint security is the discipline of protecting individual devices that connect to your network: laptops, desktops, servers, mobile devices, and the browsers on them. It combines prevention (blocking malware before it runs), detection and response (catching attacker behavior that slips past), and control over what data leaves a device. Modern endpoint security has expanded well beyond traditional antivirus into telemetry, threat hunting, and isolation.
An endpoint protection platform (EPP) is preventive: it tries to stop malware, exploits, and known-bad behavior before they execute. Endpoint detection and response (EDR) assumes some attacks get through, so it records endpoint activity, flags suspicious behavior, and gives analysts the telemetry to investigate and contain. EPP is the gate; EDR is the camera and the incident workflow behind it. Most serious programs run both, often from one vendor.
Often yes. Many endpoint platforms treat managed laptops and servers as the priority and handle mobile and browser thinly. If your workforce leans heavily on phones, BYOD, or contractors on unmanaged devices, dedicated mobile threat defense, mobile device management, or secure enterprise browser tools fill the gaps the core platform leaves open. Map your real device and access patterns before assuming one agent covers everything.
Open-source EDR agents and host-based monitoring can cover real ground, especially for telemetry collection and file integrity monitoring, and they suit tight budgets or technical teams. The gap is usually operational: managed detection, tuned prevention, response automation, and support. If you lack staff to hunt and triage around the clock, a commercial platform or a managed service typically buys back time you do not have.
Remote browser isolation runs web sessions away from the device, in a remote environment, then streams a safe rendering back to the user. Secure enterprise browsers take a different route, hardening a managed browser with policy, data controls, and visibility. Both treat the browser as the endpoint, which makes sense given how much work, and how many attacks, now live there. They complement device-level agents rather than replacing them.
Ranked by real community upvotes and saves — never for sale. Featured placement is always labeled.