Open-source AI models for cybersecurity

Security models help analyze logs and incidents, find vulnerabilities in code and explain detected threats. In this field it is especially important that the model runs inside your perimeter and data stays in-house. Look at the model's specialization, hardware requirements and license terms.

9 open model families in this collection.Updated 22 Sep 2026Open the full catalog with filters
Cybersecurity2025–2026

Foundation-Sec

Cisco (Foundation AI) · USA

Cisco models for information security based on Llama 3.1 8B: analysis of vulnerabilities, threats and incidents. Can be deployed inside your own perimeter.

  • Analyzing vulnerability and threat reports
  • Helping SOC analysts during incidents
  • Mapping threats to MITRE ATT&CK
Sizes
8B
Hardware
from: Laptop
Commercial use with conditionsDetails
Moderation and safety2025

AprielGuard

ServiceNow · USA

A guard model that catches both harmful content and attacks on AI (prompt injection, jailbreaks), including when agents use tools.

  • Screening chatbot requests for attacks and jailbreaks
  • Filtering harmful model answers
  • Monitoring the actions of AI agents that use tools
Sizes
8B
Hardware
from: Laptop
Commercial use allowedDetails
CybersecurityGGUF2023–2025

SecGPT

Clouditera · China

A Chinese open family for cybersecurity: reviewing vulnerabilities, analysing logs and traffic, explaining commands and scripts.

  • Reviewing vulnerabilities and drafting fix recommendations
  • Analysing logs and reconstructing an attack chain
  • Explaining suspicious commands and scripts
Sizes
1.5B – 14B
Hardware
from: Laptop
Commercial use allowedDetails
CybersecurityGGUF2025

Trendyol Cybersecurity LLM

Trendyol · Turkey

Security models from a large Turkish marketplace, published in GGUF format: reviewing alerts and incidents, English and Turkish.

  • Reviewing alerts and first-pass incident assessment
  • Explaining suspicious activity in reports
  • Helping the on-duty shift of a monitoring centre
Sizes
32B и 70B
Hardware
from: 1 GPU
Commercial use allowedDetails
CybersecurityGGUF2023–2025

WhiteRabbitNeo / DeepHat

Kindo · USA

One of the best-known open families for security and DevSecOps work: reviewing code for weaknesses, test scenarios, explaining attacks.

  • Finding weak spots in code and configurations
  • Reviewing incidents and explaining attack techniques
  • Drafting scripts and procedures for the security team
Sizes
7B – 70B
Hardware
from: Laptop
Commercial use with conditionsDetails
Cybersecurity2025

Llama-Primus

Trend Micro · Japan

Trend Micro cybersecurity models based on Llama 3.1 8B, fine-tuned on a corpus of security texts. A reasoning version is available.

  • Answering questions about threats and vulnerabilities
  • Analyzing cyberattack reports
  • A base for fine-tuning for SOC tasks
Sizes
8B
Hardware
from: Laptop
Commercial use with conditionsDetails
Cybersecurity2024

Phishing Email Detection DistilBERT

cybersectony · not disclosed

A very light classifier for emails and links showing signs of phishing. It errs in both directions, so borderline emails are still reviewed by a person.

  • Flagging suspicious incoming emails
  • Checking links from correspondence before opening them
  • A first-level filter in a mail gateway
Sizes
about 66M
Hardware
from: Laptop
Commercial use allowedDetails
CybersecurityGGUFNot maintained2023–2024

ZySec

ZySec AI · India

A small open assistant for security professionals: questions about standards, reviewing threats and vulnerabilities, drafting internal documents.

  • Answering questions about security policies and standards
  • First-pass review of threat reports
  • Drafting internal protection guidelines
Sizes
2.8B и 7B
Hardware
from: Laptop
Commercial use allowedDetails
CybersecurityNot maintained2022–2023

SecureBERT

Ehsan Aghaei and co-authors · USA

A compact language encoder trained on cybersecurity texts: tagging threat reports, finding entities and classification.

  • Tagging threat reports and vulnerability bulletins
  • Extracting entities from security texts
  • Classifying and searching an internal incident base
Sizes
около 125M
Hardware
from: Laptop
Commercial use with conditionsDetails

Collections

Need a model for your task?

An open model can run on your own server: data stays in-house, there is no per-request fee, and the model can be fine-tuned on your documents.

  1. SelectThe model and size for your task and hardware budget
  2. DeployOn your server or in a closed network, with an API
  3. Fine-tuneOn your data, or connect a knowledge base
  4. IntegrateInto your CRM, ERP, bot, website or team chat
Discuss deployment