// ARSENAL
Cybersecurity Arsenal
65 tools and 16 labs, free and with no signup. The ones handling your data —emails, logs, passwords— do it entirely in your browser: nothing is uploaded anywhere.
✨ New
★ Favourites
🕘 Recent
🛡️ Defense & SOC
15
☆
📧
Email Triage (.eml)
FEATURED
Phishing verdict on a message: real route, SPF/DKIM/DMARC alignment, IOCs and a plain-language AI explanation.
☆
🩺
SPF/DMARC/DKIM Auditor
Live-checks a domain's SPF, DMARC and DKIM, audits them (grade and fixes) and lays out the phased plan to DMARC p=reject without breaking legit mail.
☆
🔏
SPF/DMARC/DKIM Generator
Build email authentication records (SPF, DMARC and DKIM with a key pair) with warnings and explanations.
☆
🧬
YARA rule generator
FEATURED
Build a valid YARA rule from strings (text, hex or regex), their modifiers and a condition. File-based malware detection.
☆
⚒️
Sigma Forge
FEATURED
From a real log to the Sigma rule, then to KQL, SPL, Lucene, EQL and Wazuh.
☆
🔎
Detection Linter
FEATURED
Grades a Sigma or YARA rule (A–F) and flags its anti-patterns: missing fields, fragile condition, generic strings.
☆
🔩
PowerShell Decoder
FEATURED
Recover the script from a "powershell -enc": decodes UTF-16LE Base64, flags obfuscation (IEX, download cradle, AMSI) and extracts IOCs.
☆
🌉
CVE to Detection
FEATURED
From a CVE to a detection starting point: ports, event IDs, ATT&CK tactics and a Sigma rule skeleton.
☆
🔑
Secret Scanner
FEATURED
Finds leaked keys and tokens (AWS, GitHub, Slack, private keys, JWT…) in code or .env, in your browser.
☆
🛡️
SOC Arsenal (KQL)
KQL queries and scripts ready to paste into Sentinel and Defender.
☆
📊
Log Analyzer
Spots attack patterns in Apache and Nginx logs.
☆
☣️
Sandbox-X Malware
Malware analysis simulator in a controlled environment.
☆
⚡
Live Threat Map
Real-time threat map.
☆
🧷
IOC Defanger
Defangs and refangs indicators (hxxp, [.]) to share them safely, and extracts IOCs from text.
☆
🛰️
Posture Radar
FEATURED
Scan a domain for an A–F security grade with prioritized fixes: SPF/DMARC, TLS, headers, DNS and exposure. Passive and non-intrusive.
🩹 Vulnerability management
18
☆
🩹
What do I patch first?
FEATURED
Ranks your CVEs by real exploitation using CVSS, EPSS and the KEV catalog.
☆
🎯
Am I affected?
FEATURED
Paste your dependencies and find out which to update this week, and to which version.
☆
🐛
CVE & Exploit Finder
Search vulnerabilities by product, year or severity, plus public exploits.
☆
🧮
CVSS Calculator
Compute CVSS v3.1 (base, temporal, environmental) and v4.0: build the vector and get the score and severity, with every metric explained.
☆
🎯
Perimeter Scanner
X-ray of a domain exposed surface.
☆
📋
HTTP Header Analyzer
Audits security headers: CSP, HSTS, X-Frame-Options.
☆
🧱
CSP Builder
Build a Content-Security-Policy by directive, with warnings on weak choices and strict presets.
☆
🧯
CSP Evaluator
FEATURED
Paste a Content-Security-Policy and get an A–F grade with its bypasses: unsafe-inline, data:, wildcards and missing hardening.
☆
🐳
Dockerfile / IaC Linter
FEATURED
A–F security grade for a Dockerfile, docker-compose or K8s manifest: root, :latest, privileged, hostPath, plaintext secrets.
☆
🔒
TLS/SSL Analyzer
Inspects a host certificate and TLS: expiry, chain, protocol, cipher and an A–F grade.
☆
🔒
TLS Config Generator
FEATURED
Hardened TLS config (protocols, ciphers, HSTS, OCSP) for nginx, Apache or HAProxy: Mozilla modern and intermediate profiles.
☆
🧰
Config Auditor
FEATURED
Paste your sshd_config, .htaccess or wp-config.php and get an A–F grade with the issues and the corrected line: SSH root, weak ciphers, directory listing, WP_DEBUG, default keys… In your browser.
☆
🔌
WP plugin vulnerabilities
FEATURED
Paste your WordPress plugin list (or the output of "wp plugin list") and find which have known vulnerabilities, their severity and which version to update to. No install. Data from Wordfence Intelligence.
☆
📜
Certificate Decoder
Paste a PEM certificate and read it inside: subject, issuer, validity, serial, signature, key and SANs. In your browser.
☆
🛡️
OS Bastioning
Hardening guide for Linux and Windows with ready-to-run commands.
☆
🧰
System Prompt Auditor
FEATURED
Paste your LLM app system prompt and find weaknesses (secrets, blind trust, instruction leakage, no boundaries) with a grade and fix.
☆
👁️
Visual Code Auditor
Finds insecure patterns in pasted source code.
☆
🔑
SSH Analyzer
Assesses SSH key strength and configuration.
🏴☠️ Offensive & pentesting
10
☆
🐚
Reverse Shell Generator
Reverse, bind and msfvenom in 30+ languages, with encoding and TTY upgrade.
☆
🛡️
WAF Bypass Payloads
Mutator that generates evasion variants of any payload, plus a 158-payload library.
☆
📝
Wordlist Generator
Tailored dictionaries: leet, affixes, combining and policy filtering.
☆
📡
HTTP Builder
Builds custom HTTP requests and their curl equivalent.
☆
🔓
Hash Analyzer
Identifies a hash algorithm and suggests how to attack it.
☆
💻
C2 Web Simulator
Command-and-control panel simulator to understand its traffic.
☆
🐕
BloodHound AD
Simulates escalation paths in Active Directory.
☆
🏴☠️
Subdomain Takeover
Detects subdomains pointing at abandoned services.
☆
🛰️
Nmap command builder
FEATURED
Assemble your Nmap scan by options (type, ports, timing, version/OS, NSE, output) and understand each flag. With recipes.
☆
📋
Port Reference
TCP/UDP port cheatsheet with service and risk.
🔍 OSINT & recon
7
☆
🔍
OSINT Quick Recon
Fast reconnaissance of a domain from open sources.
☆
📄
OSINT Report
Generates a presentable OSINT report in PDF.
☆
🔍
DNS Lookup
Queries DNS records and tests zone transfer.
☆
🤖
robots.txt / security.txt Analyzer
Analyzes a robots.txt (sensitive paths it reveals) or a security.txt (RFC 9116: fields, expiry). In your browser.
☆
☁️
Cloud Enum
Enumeration commands for AWS, Azure and GCP.
☆
🌐
What is my IP?
Your public IP, geolocation and VPN detection.
☆
🏷️
MAC Vendor Lookup
Identifies the vendor behind a MAC address (OUI).
🔐 Crypto & data
14
☆
🔬
File signature identifier (magic bytes)
FEATURED
Identify a file's real format by its signature (magic bytes), ignoring the extension. Paste hex or drop the file. Forensics and CTF.
☆
#️⃣
Hash Generator
MD5, SHA-1, SHA-256 and SHA-512 instantly.
☆
🔄
Base64
Encodes and decodes Base64 in the browser.
☆
🔄
Multi Decoder (CTF)
Chains Base64, Hex, ROT13 and more until the text appears.
☆
🔓
JWT: decode & audit
Opens a JWT's header and payload and audits it: alg=none, HS/RS confusion, jku/x5u, expiration (expired or none), injectable kid, sensitive data and authorization claims. Explains each claim and translates the dates.
☆
🔗
URL: encode, decode & X-ray
Encode/decode URLs and X-ray them for deception: a phishing verdict (@ trick, brand-imitating subdomains, Punycode, risky TLDs, shorteners, open redirects, tracking).
☆
🌍
CIDR Calculator
Subnets, ranges and masks for IPv4 and IPv6.
☆
🐧
Chmod Calculator
Translates Linux permissions between octal and symbolic.
☆
⏱
Cron Parser
Translates cron to plain language, computes next runs and audits the command.
☆
🕐
Timestamp Converter
Converts Unix epoch (s/ms) to date and back, in UTC and your timezone, with relative time.
☆
🧩
Regex Generator
Builds regular expressions to validate passwords and formats.
☆
🧩
Regex Explainer
FEATURED
Paste a regex and understand it: token-by-token breakdown, ReDoS warning and a live tester that highlights matches.
☆
🔑
Password Generator
Strong passwords and passphrases without leaving the browser.
☆
🛡️
Password Strength
Estimates how long your password would hold against a real attack.
🧪 Labs & simulators
16
☆
🗂️
Local investigation case
FEATURED
Connect synthetic email, indicators, notes and a timeline. Keep source references and reopen your case from a local JSON file.
☆
🔎
Microsoft 365 Identity Lab
FEATURED
Investigate synthetic sign-ins and mailbox changes. Cite evidence, compare hypotheses and justify decisions.
☆
🛡️
Sigma Detection Lab
FEATURED
Test detections against synthetic events, compare A/B versions and download a report of hits, noise and limits.
☆
🧱
WAF Bypass Lab
FEATURED
Evade a WAF level by level: XSS without <script>, encoded path traversal, spaceless SQLi and double encoding.
☆
💉
SQL Injection Lab
FEATURED
SQL injection level by level: boolean login bypass, commenting out the query, UNION exfiltration and time-based blind.
☆
🤖
Prompt Injection Lab
FEATURED
Jailbreak a guardian chatbot level by level: direct request, filter evasion, instruction override and context injection.
☆
📊
Threat Hunting Lab
Hunt the attacker inside an event stream.
☆
🚨
SOC Simulator
A SOC shift: triage alerts and decide what to escalate.
☆
🧠
Threat Intelligence
Live threat intelligence dashboard.
☆
🛡️
Sentinel D&R Lab
Detection and response with Microsoft Sentinel.
☆
🎣
Phishing Analysis
Step-by-step phishing email analysis simulator.
☆
🚨
Tabletop: Ransomware
Crisis exercise: you make the calls during a ransomware incident.
☆
🗺️
MITRE ATT&CK Mapper
Maps attack techniques onto the MITRE matrix.
☆
📡
Threat Radar
FEATURED
Daily ranking of the most dangerous CVEs combining active exploitation (KEV), exploit probability (EPSS) and severity (CVSS).
☆
🏗️
Arch Designer
Design a security architecture and check its gaps.
☆
📄
C-Level Reports
Turns technical findings into a board-level report.
Nothing matches that search. Try another word.