Cybersecurity Arsenal

65 tools and 16 labs, free and with no signup. The ones handling your data —emails, logs, passwords— do it entirely in your browser: nothing is uploaded anywhere.

✨ New

🛡️ Defense & SOC

15
📧 Email Triage (.eml) FEATURED Phishing verdict on a message: real route, SPF/DKIM/DMARC alignment, IOCs and a plain-language AI explanation. 🩺 SPF/DMARC/DKIM Auditor Live-checks a domain's SPF, DMARC and DKIM, audits them (grade and fixes) and lays out the phased plan to DMARC p=reject without breaking legit mail. 🔏 SPF/DMARC/DKIM Generator Build email authentication records (SPF, DMARC and DKIM with a key pair) with warnings and explanations. 🧬 YARA rule generator FEATURED Build a valid YARA rule from strings (text, hex or regex), their modifiers and a condition. File-based malware detection. ⚒️ Sigma Forge FEATURED From a real log to the Sigma rule, then to KQL, SPL, Lucene, EQL and Wazuh. 🔎 Detection Linter FEATURED Grades a Sigma or YARA rule (A–F) and flags its anti-patterns: missing fields, fragile condition, generic strings. 🔩 PowerShell Decoder FEATURED Recover the script from a "powershell -enc": decodes UTF-16LE Base64, flags obfuscation (IEX, download cradle, AMSI) and extracts IOCs. 🌉 CVE to Detection FEATURED From a CVE to a detection starting point: ports, event IDs, ATT&CK tactics and a Sigma rule skeleton. 🔑 Secret Scanner FEATURED Finds leaked keys and tokens (AWS, GitHub, Slack, private keys, JWT…) in code or .env, in your browser. 🛡️ SOC Arsenal (KQL) KQL queries and scripts ready to paste into Sentinel and Defender. 📊 Log Analyzer Spots attack patterns in Apache and Nginx logs. ☣️ Sandbox-X Malware Malware analysis simulator in a controlled environment. Live Threat Map Real-time threat map. 🧷 IOC Defanger Defangs and refangs indicators (hxxp, [.]) to share them safely, and extracts IOCs from text. 🛰️ Posture Radar FEATURED Scan a domain for an A–F security grade with prioritized fixes: SPF/DMARC, TLS, headers, DNS and exposure. Passive and non-intrusive.

🩹 Vulnerability management

18
🩹 What do I patch first? FEATURED Ranks your CVEs by real exploitation using CVSS, EPSS and the KEV catalog. 🎯 Am I affected? FEATURED Paste your dependencies and find out which to update this week, and to which version. 🐛 CVE & Exploit Finder Search vulnerabilities by product, year or severity, plus public exploits. 🧮 CVSS Calculator Compute CVSS v3.1 (base, temporal, environmental) and v4.0: build the vector and get the score and severity, with every metric explained. 🎯 Perimeter Scanner X-ray of a domain exposed surface. 📋 HTTP Header Analyzer Audits security headers: CSP, HSTS, X-Frame-Options. 🧱 CSP Builder Build a Content-Security-Policy by directive, with warnings on weak choices and strict presets. 🧯 CSP Evaluator FEATURED Paste a Content-Security-Policy and get an A–F grade with its bypasses: unsafe-inline, data:, wildcards and missing hardening. 🐳 Dockerfile / IaC Linter FEATURED A–F security grade for a Dockerfile, docker-compose or K8s manifest: root, :latest, privileged, hostPath, plaintext secrets. 🔒 TLS/SSL Analyzer Inspects a host certificate and TLS: expiry, chain, protocol, cipher and an A–F grade. 🔒 TLS Config Generator FEATURED Hardened TLS config (protocols, ciphers, HSTS, OCSP) for nginx, Apache or HAProxy: Mozilla modern and intermediate profiles. 🧰 Config Auditor FEATURED Paste your sshd_config, .htaccess or wp-config.php and get an A–F grade with the issues and the corrected line: SSH root, weak ciphers, directory listing, WP_DEBUG, default keys… In your browser. 🔌 WP plugin vulnerabilities FEATURED Paste your WordPress plugin list (or the output of "wp plugin list") and find which have known vulnerabilities, their severity and which version to update to. No install. Data from Wordfence Intelligence. 📜 Certificate Decoder Paste a PEM certificate and read it inside: subject, issuer, validity, serial, signature, key and SANs. In your browser. 🛡️ OS Bastioning Hardening guide for Linux and Windows with ready-to-run commands. 🧰 System Prompt Auditor FEATURED Paste your LLM app system prompt and find weaknesses (secrets, blind trust, instruction leakage, no boundaries) with a grade and fix. 👁️ Visual Code Auditor Finds insecure patterns in pasted source code. 🔑 SSH Analyzer Assesses SSH key strength and configuration.

🏴‍☠️ Offensive & pentesting

10

🔍 OSINT & recon

7

🔐 Crypto & data

14
🔬 File signature identifier (magic bytes) FEATURED Identify a file's real format by its signature (magic bytes), ignoring the extension. Paste hex or drop the file. Forensics and CTF. #️⃣ Hash Generator MD5, SHA-1, SHA-256 and SHA-512 instantly. 🔄 Base64 Encodes and decodes Base64 in the browser. 🔄 Multi Decoder (CTF) Chains Base64, Hex, ROT13 and more until the text appears. 🔓 JWT: decode & audit Opens a JWT's header and payload and audits it: alg=none, HS/RS confusion, jku/x5u, expiration (expired or none), injectable kid, sensitive data and authorization claims. Explains each claim and translates the dates. 🔗 URL: encode, decode & X-ray Encode/decode URLs and X-ray them for deception: a phishing verdict (@ trick, brand-imitating subdomains, Punycode, risky TLDs, shorteners, open redirects, tracking). 🌍 CIDR Calculator Subnets, ranges and masks for IPv4 and IPv6. 🐧 Chmod Calculator Translates Linux permissions between octal and symbolic. Cron Parser Translates cron to plain language, computes next runs and audits the command. 🕐 Timestamp Converter Converts Unix epoch (s/ms) to date and back, in UTC and your timezone, with relative time. 🧩 Regex Generator Builds regular expressions to validate passwords and formats. 🧩 Regex Explainer FEATURED Paste a regex and understand it: token-by-token breakdown, ReDoS warning and a live tester that highlights matches. 🔑 Password Generator Strong passwords and passphrases without leaving the browser. 🛡️ Password Strength Estimates how long your password would hold against a real attack.

🧪 Labs & simulators

16
🗂️ Local investigation case FEATURED Connect synthetic email, indicators, notes and a timeline. Keep source references and reopen your case from a local JSON file. 🔎 Microsoft 365 Identity Lab FEATURED Investigate synthetic sign-ins and mailbox changes. Cite evidence, compare hypotheses and justify decisions. 🛡️ Sigma Detection Lab FEATURED Test detections against synthetic events, compare A/B versions and download a report of hits, noise and limits. 🧱 WAF Bypass Lab FEATURED Evade a WAF level by level: XSS without <script>, encoded path traversal, spaceless SQLi and double encoding. 💉 SQL Injection Lab FEATURED SQL injection level by level: boolean login bypass, commenting out the query, UNION exfiltration and time-based blind. 🤖 Prompt Injection Lab FEATURED Jailbreak a guardian chatbot level by level: direct request, filter evasion, instruction override and context injection. 📊 Threat Hunting Lab Hunt the attacker inside an event stream. 🚨 SOC Simulator A SOC shift: triage alerts and decide what to escalate. 🧠 Threat Intelligence Live threat intelligence dashboard. 🛡️ Sentinel D&R Lab Detection and response with Microsoft Sentinel. 🎣 Phishing Analysis Step-by-step phishing email analysis simulator. 🚨 Tabletop: Ransomware Crisis exercise: you make the calls during a ransomware incident. 🗺️ MITRE ATT&CK Mapper Maps attack techniques onto the MITRE matrix. 📡 Threat Radar FEATURED Daily ranking of the most dangerous CVEs combining active exploitation (KEV), exploit probability (EPSS) and severity (CVSS). 🏗️ Arch Designer Design a security architecture and check its gaps. 📄 C-Level Reports Turns technical findings into a board-level report.