CyberRamen security tools
Running
All tools
- Phishing CheckerSniff out suspicious URLs. Typosquatting detection included.Server-assisted
- PDF ScannerScan a suspicious PDF in a sandbox: antivirus, hidden links, scripts, embedded programs, safe preview.Server
- Email Header AnalyzerDissect headers layer by layer. SPF/DKIM/DMARC — the holy trinity.In browser
- Email Security CheckerSPF, DKIM, DMARC at a glance. Holy trinity of email security.Server
- Email Auth Record BuilderGenerate valid SPF, DKIM, and DMARC DNS records with guardrails.In browser
- DMARC Report AnalyzerTurn DMARC aggregate (RUA) XML into a readable pass/fail-by-source view.In browser
- QR Code ScannerDecode QR codes with URL defanging for SOC sharing.In browser
- HTTP Security Headers GraderGrade headers A+ to F. Missing CSP? Cold noodles.Server-assisted
- SSL Certificate CheckerTrust score, expiration alerts, legitimacy indicators.Server
- Certificate DecoderDecode SSL/TLS certs to view subject, issuer, validity, extensions.In browser
- CAA & HSTS Preload CheckerCheck CAA records and HSTS preload eligibility for any domain.Server
- Domain Security Posture ScannerOne domain → a graded report: security.txt, DMARC, SPF, MTA-STS, CAA, DNSSEC, HSTS.Server
- Subdomain Takeover CheckerFind dangling CNAMEs vulnerable to takeover — matches 20+ services + fingerprints.Server
- CSP BuilderBuild CSP headers visually with presets.In browser
- Cookie Security AnalyzerParse Set-Cookie, flag missing Secure/HttpOnly/SameSite.In browser
- SRI Hash GeneratorGenerate Subresource Integrity hashes for assets.Server-assisted
- security.txt GeneratorGenerate RFC 9116 vulnerability disclosure files.In browser
- Server Config ValidatorValidate Apache/Nginx config with best-practice checks.In browser
- .htaccess GeneratorCreate Apache .htaccess with security/caching/rewrite rules.In browser
- Mod_Rewrite TesterTest Apache mod_rewrite rules and see transformations.In browser
- Robots.txt AnalyzerParse robots.txt with URL testing and validation.In browser
- LinkedIn Exposure AuditScore LinkedIn exposure from an attacker perspective.In browser
- DNS MapperMap DNS infra with visual graphs and subdomain discovery.Server
- DNS Record LookupA, AAAA, MX, TXT, NS, CNAME, SOA records with TTL.Server
- WHOIS LookupLook up domain registration via RDAP.Server
- IP InfoAnalyze IPv4/IPv6 with binary representation, range detection.In browser
- IP Geolocation & PrivacyGeolocate IPs, detect VPN/proxy, browser fingerprint.Server
- CIDR CalculatorCalculate IP ranges, subnets, masks.In browser
- Port LookupPort info, security status, common usage.In browser
- MAC Address LookupLook up MAC vendor/manufacturer from OUI database.In browser
- Domain AvailabilityCheck domain availability across TLDs using RDAP.Server
- Firewall Rule AnalyzerFind shadowed and permissive iptables/UFW/nftables rules.In browser
- Network Flow MatrixMap authorized flows between zones and check policy.In browser
- Resource Health CheckerParse uptime/free/df/top output for CPU/RAM/disk health.In browser
- Nmap XML ParserParse Nmap -oX into a clean filterable HTML report.In browser
- MITRE ATT&CK SearchSearch the ATT&CK matrix like a menu.In browser
- Sigma Rule BuilderVisual builder with Splunk / QRadar / Sentinel export.In browser
- YARA Rule BuilderVisually build YARA rules with live preview and tester.In browser
- Sysmon Config BuilderVisually compose Sysmon rules and export valid XML.In browser
- Windows Event ID LookupOffline reference for Security / System / Sysmon event IDs.In browser
- Log Parser BuilderBuild Grok / named-capture regex against log lines.In browser
- SIEM Query Template LibraryHunting queries for Splunk, Sentinel and QRadar.In browser
- QRadar AQL AssistantBuild, validate and explain QRadar AQL queries.In browser
- SOC Alert TriageWalk an alert to a disposition with next queries.In browser
- SOC Sizing & CostSIEM sizing, storage, 3-year TCO across SIEMs.In browser
- IOC DefangerDefang malicious indicators for safe sharing.In browser
- IOC Pivoting ToolClassify an indicator and jump straight to it in VirusTotal, Shodan, AbuseIPDB, URLhaus, crt.sh, NVD and more.In browser
- STIX 2.1 FormatterConvert IOC lists into STIX 2.1 bundles.In browser
- Incident Timeline BuilderBuild incident timelines from logs with annotations.In browser
- Log RedactorAnonymize IPs, emails, tokens in logs before sharing.In browser
- Incident Report GeneratorNIS2 / DORA / GDPR incident report templates with deadlines.In browser
- Tabletop Exercise GeneratorReady-to-run IR tabletop scenarios with injects.In browser
- SecOps Response Templates100+ security email and ticket templates.In browser
- File Signature IdentifierIdentify file formats by magic numbers. 60+ signatures.In browser
- Security Feeds (RSS)Aggregated security news, CVEs, threat intel from 40+ sources.Server
- USB Hygiene HelperAnalyze USB device lists for BadUSB / unknown vendors.In browser
- CVSS v3.1 CalculatorScore vulns with the official CVSS v3.1 recipe.In browser
- CVSS v4.0 CalculatorOfficial CVSS v4.0 scoring across Base/Threat/Environmental/Supplemental.In browser
- EPSS Score LookupFIRST EPSS exploit-prediction score with CISA KEV cross-check.Server
- SSVC Decision TreeCISA SSVC to Track / Attend / Act with rationale.In browser
- Actionable CVEs DashboardWhat to patch today: fresh CISA KEV entries + highest-EPSS CVEs.Server
- Dependency ScannerScan package.json / requirements.txt / composer.json for CVEs.Server-assisted
- CVE / CPE Search BuilderCompose CPE 2.3 names and search NVD / MITRE / OSV / KEV.In browser
- Hash ToolkitGenerate, verify, identify hashes (MD5, SHA, bcrypt, more).In browser
- AES-GCM Encrypt / DecryptEncrypt/decrypt with AES-256-GCM (Web Crypto API).In browser
- HMAC GeneratorCompute/verify HMAC signatures (SHA-1/256/384/512).In browser
- JWT DecoderDecode and analyze JSON Web Tokens.In browser
- TOTP GeneratorGenerate / verify RFC 6238 TOTPs with provisioning URI.In browser
- SSH Key AnalyzerGenerate Ed25519/RSA, analyze pub keys with fingerprint.In browser
- CSR Generator & DecoderGenerate RSA/ECDSA CSRs in-browser; decode existing CSRs.In browser
- PGP Key InspectorInspect OpenPGP public keys: algos, fingerprint, UIDs.In browser
- PGP Key LookupFind PGP keys by email/fingerprint/key ID via keyservers.Server
- Password Security SuiteGenerate strong passwords with entropy analysis and bcrypt.Server-assisted
- Password Policy TesterScore policies against NIST 800-63B / NCSC / CIS.In browser
- Password Hash VerifierVerify passwords against bcrypt/Argon2, identify algo.Server
- Base ConverterConvert between bin/oct/dec/hex with arithmetic.In browser
- Encoding ToolkitEncode / decode / detect: Hex, URL, HTML, Unicode, Base64.In browser
- Kaidoku Cipher DecoderDecode 80+ classical ciphers and encodings with auto-detection, then triage the plaintext for URLs, handles, coordinates, hashes and CTF flags.In browser
- DORA Compliance CheckerDORA self-assessment with CSSF specifics, gap export.In browser
- DORA Register of InformationCompile DORA ICT third-party register, completeness checks.In browser
- NIS2 Self-AssessmentSelf-assess NIS2 scope and Article 21 measures.In browser
- Swiss FADP (nLPD) Self-AssessmentSelf-assess the Swiss data protection act, with GDPR overlap flagged.In browser
- ISO 27001 SoA BuilderBuild SoA across 93 Annex A:2022 controls.In browser
- BIA / RTO-RPO CalculatorRun a BIA, derive RTO/RPO, flag SPOFs.In browser
- Compliance Reference DatabaseSearchable database of 1200+ compliance specs, incl. GDPR ↔ Swiss FADP map.In browser
- Risk Matrix Builder3x3 or 5x5 risk heatmaps, PNG/CSV/JSON export.In browser
- Control MapperCross-reference NIST CSF 2.0 to ISO 27001 / DORA.In browser
- NIST CSF 2.0 Profile BuilderBuild CSF 2.0 Current and Target Profile across 106 subcats.In browser
- NIST CSF 2.0 Tier AssessmentSelf-assess your CSF 2.0 Implementation Tier.In browser
- Vendor Risk QuestionnaireBuild third-party security questionnaires.In browser
- Third-Party Risk RegisterTrack ICT vendors: tier, status, review dates, findings.In browser
- RACI Matrix BuilderRACI / RASCI matrix with one-Accountable validation, MD/CSV/JSON export.In browser
- Policy Document GeneratorDraft eight security policies mapped to ISO 27001, NIS2, DORA, GDPR, PCI DSS.In browser
- IAM Policy AnalyzerYour policy said *:*. That's an all-you-can-eat buffet for attackers.In browser
- Bucket Exposure CheckerPublic bucket, public shame. Exists, listable, readable, or takeover bait.Server
- Container Manifest LinterRunning as root? That's raw noodles, not ramen.In browser
- Secrets & Credential Leak ScannerFind and redact leaked API keys, tokens and private keys in pasted text.In browser
- AI / LLM VocabularyPlain-language glossary of 100+ AI / LLM terms.In browser
- LLM Pre-flight RedactorScan and redact text before pasting into LLMs.In browser
- LLM Output ScannerCheck an LLM's answer for reproduced PII, credentials and unverified citations.In browser
- LLM Token Cost EstimatorApproximate tokens and cost across LLM providers.In browser
- Context-Window Fit CheckerWill it fit in 128k or 1M? Per-model pass/warn/fail.In browser
- Local-Model VRAM CalculatorGPU memory estimates for local LLMs with quant tweaks.In browser
- LLM System-Prompt LinterLint system prompts for foot-guns and leaks.In browser
- MITRE ATLAS SearchOffline search across MITRE ATLAS for AI/ML attacks.In browser
- OWASP LLM Top 10 CheckerSelf-assess OWASP LLM Top 10 (v1.1).In browser
- Prompt Injection PlaygroundLearn prompt injection via 8 simulated scenarios.In browser
- AI/ML Threat Model BuilderWizard threat model for AI/ML systems (STRIDE+ATLAS+OWASP).In browser
- EU AI Act Readiness CheckerEU AI Act self-assessment (Reg 2024/1689).In browser
- NIST AI RMF CheckerSelf-assess NIST AI RMF (Govern/Map/Measure/Manage).In browser
- JSON / YAML / PHP FormatterValidate, format, convert between JSON / YAML / PHP.In browser
- Regex TesterTest regex with highlighting and ReDoS protection.In browser
- SQL FormatterFormat and minify SQL with syntax highlighting.In browser
- CSV ConverterParse CSV/TSV, convert to JSON/SQL/HTML/Markdown.In browser
- Diff ToolCompare texts with side-by-side and unified diff.In browser
- Markdown PreviewWrite Markdown with live preview and export.In browser
- String Case ConvertercamelCase, snake_case, kebab-case, slug.In browser
- Text Cleaner & NormalizerStrip HTML, remove diacritics, normalize whitespace.In browser
- Text StatisticsWord count, readability, keyword density.In browser
- Lorem Ipsum GeneratorPlaceholder text for design mockups.In browser
- URL ParserParse URLs, encode/decode, build URLs.In browser
- Link ExtractorExtract links from a webpage with filtering.Server
- Page Content AuditContent, links, social profiles, media, design and hidden-text detection for any page.Server-assisted
- HTTP Status CodesComplete searchable status code reference.In browser
- HTTP Request BuilderBuild requests, export cURL/fetch/Python/PHP.In browser
- User Agent ParserParse UA strings: browser, OS, device.In browser
- MIME Type LookupLook up MIME types by file extension.In browser
- Unix Permissions CalculatorCalculate Unix file permissions visually.In browser
- Timestamp ConverterConvert Unix timestamps with timezone support.In browser
- Meeting Timezone ConverterConvert meeting times across timezones with .ics export.In browser
- Cron ParserParse cron expressions, see next run times.In browser
- Color ConverterHEX, RGB, HSL, CMYK with WCAG contrast checker.In browser
- UUID GeneratorGenerate/validate UUIDs (v1, v4) with bulk support.In browser
- QR Code GeneratorGenerate QR codes for URLs, WiFi, contacts.In browser
- ASCII Banner GeneratorGenerate ASCII art text banners.In browser
- ASCII TableComplete ASCII reference: dec/hex/oct/bin.In browser
- NATO Phonetic ConverterConvert text/hex/UUIDs to NATO phonetic alphabet.In browser
- ICS Calendar GeneratorCreate .ics events for Calendar / Google / Outlook.In browser
- Favicon GeneratorFavicons from text, emojis, or solid colors.In browser
- Test Data GeneratorRealistic random test data: emails, IPs, domains.In browser
- Secret Menu — Encrypted Link SharingShare a password or token as a link that only decrypts in the browser.In browser
- EXIF AnalyzerExtract EXIF metadata from images client-side.In browser
- Metadata StripperRemove EXIF/metadata from images before sharing.In browser
- Filigrane — Document WatermarkWatermark ID cards, payslips & PDFs before sending. 100% in-browser.In browser
Workflows
All 144 toolsSecurity noodle bar サイバーラーメン
Free security tools, served fresh in your browser.
144 tools for SOC analysts, pentesters, GRC teams and developers — headers, phishing, CVSS, Sigma, DORA, DNS, hashing and more.
本日のセット Today’s set
Spice of the day 激辛
CVE-2026-104286
Fortinet · FortiMail
EPSS 0.022 · top 18% · CVSS 9.8
Chef’s pick String Case Converter
Most used this month
Recently updated
Web & Domain Security
ラーメンTLS, headers, cookies and domain hardening.
Grade a site's HTTP security headers from A+ to F.
Check a TLS certificate's chain, expiry, protocols and cipher strength.
Compose a Content-Security-Policy header with directive guidance and validation.
Scan a domain's DNS, email, TLS and headers for a posture grade.
Detection & SOC
激辛SIEM, detection engineering and SOC operations.
Search MITRE ATT&CK tactics, techniques and procedures offline in your browser.
Build Sigma detection rules visually and convert to Splunk, Sentinel, QRadar.
Build and test YARA rules against sample files in your browser.
Browse ready-made SIEM queries for Splunk, Sentinel, QRadar and Elastic.
GRC & Compliance
弁当Governance, risk and regulatory readiness.
Assess DORA readiness across ICT risk, incident reporting and resilience testing.
Search GDPR, NIS2, DORA, PCI DSS and ISO 27001 controls together.
Self-assess NIS2 obligations and get a gap list with priorities.
Build an ISO 27001 Statement of Applicability across all Annex A controls.
Dev & Everyday Utilities
サイドFormatters, converters, encoders and generators.
Beautify, minify and validate JSON with syntax highlighting and error hints.
Test regular expressions live with capture groups, flags and match highlighting.
Compare two blocks of text and highlight every added or removed line.
Generate and validate UUID versions 1, 4 and 7 in bulk.
Workflows
定食Chained tools around one shared case.
URL and headers in; DMARC verdict, defanged indicators, STIX out.
Guided ransomware playbook with embedded tools and after-action export.
DNS, email auth, TLS and headers scored in one pass.
Suggest a workflow →Which tools do you chain by hand? Tell us.
Also on the menu
Browse the full menu — 144 tools →
For network administrators
CyberRamen.com is a defensive, blue-team resource — SOC, DFIR, detection-engineering and GRC references plus utilities that run entirely in your browser (nothing you paste or type leaves the page). It is safe to allow cyberramen.com for your security, SOC and GRC teams.
Offensive / red-team tooling lives on a deliberately separate domain, offensiveramen.com, which you can restrict to your pentest team — so you can set policy per site. Questions: hello@cyberramen.com.
Content filters may list this under “Hacking / Computer Security” — that categorises the topic, not the intent; everything here is for defenders.
Tools are provided for educational and authorized use only. You are responsible for compliance with applicable laws.