CyberRamen security tools
Running
Formatters & Converters
- JSON / YAML / PHP FormatterValidate, format, convert between JSON / YAML / PHP.In browser
- Regex TesterTest regex with highlighting and ReDoS protection.In browser
- SQL FormatterFormat and minify SQL with syntax highlighting.In browser
- CSV ConverterParse CSV/TSV, convert to JSON/SQL/HTML/Markdown.In browser
- Diff ToolCompare texts with side-by-side and unified diff.In browser
- Markdown PreviewWrite Markdown with live preview and export.In browser
- Text ToolkitCase convert, clean & normalize, and analyze text in one.In browser
- Color ConverterHEX, RGB, HSL, CMYK with WCAG contrast checker.In browser
Workflows
All 135 toolsFree security tools
Security tools that run in your browser.
135 tools for SOC analysts, pentesters, GRC teams and developers — headers, phishing, CVSS, Sigma, DORA, DNS, hashing and more.
Today’s set
Exploited CVE of the day
CVE-2015-3306
ProFTPD · ProFTPD
EPSS 0.995 · top 0.1% · CVSS 10.0
Featured tool Subdomain Takeover Checker
Most used this month
Recently updated
Web & Domain Security
TLS, headers, cookies and domain hardening.
Grade a site's HTTP security headers from A+ to F.
Check a TLS certificate's chain, expiry, protocols and cipher strength.
Compose a Content-Security-Policy header with directive guidance and validation.
Scan a domain's DNS, email, TLS and headers for a posture grade.
Detection & SOC
SIEM, detection engineering and SOC operations.
Search MITRE ATT&CK tactics, techniques and procedures offline in your browser.
Build Sigma detection rules visually and convert to Splunk, Sentinel, QRadar.
Build and test YARA rules against sample files in your browser.
Browse ready-made SIEM queries for Splunk, Sentinel, QRadar and Elastic.
GRC & Compliance
Governance, risk and regulatory readiness.
Assess DORA readiness across ICT risk, incident reporting and resilience testing.
Search GDPR, NIS2, DORA, PCI DSS and ISO 27001 controls together.
Self-assess NIS2 obligations and get a gap list with priorities.
Build an ISO 27001 Statement of Applicability across all Annex A controls.
Formatters & Converters
JSON, SQL, CSV, diff, Markdown, text and color.
Beautify, minify and validate JSON with syntax highlighting and error hints.
Test regular expressions live with capture groups, flags and match highlighting.
Compare two blocks of text and highlight every added or removed line.
Convert case, clean and normalise text, and read word and readability stats.
Workflows
Chained tools around one shared case.
URL and headers in; DMARC verdict, defanged indicators, STIX out.
Guided ransomware playbook with embedded tools and after-action export.
DNS, email auth, TLS and headers scored in one pass.
Suggest a workflow →Which tools do you chain by hand? Tell us.
More categories
For network administrators
CyberRamen.com is a defensive, blue-team resource — SOC, DFIR, detection-engineering and GRC references plus utilities that run entirely in your browser (nothing you paste or type leaves the page). It is safe to allow cyberramen.com for your security, SOC and GRC teams.
Offensive / red-team tooling lives on a deliberately separate domain, offensiveramen.com, which you can restrict to your pentest team — so you can set policy per site. Questions: hello@cyberramen.com.
Content filters may list this under “Hacking / Computer Security” — that categorises the topic, not the intent; everything here is for defenders.
Tools are provided for educational and authorized use only. You are responsible for compliance with applicable laws.