Score vulnerabilities using the official CVSS v3.1 methodology with Base, Temporal, and Environmental metrics
Official CVSS v4.0 vulnerability scoring with Base, Threat, Environmental and Supplemental metrics. Real-time scoring, vector string parsing and URL sharing. 100% client-side
Map DNS infrastructure with visual network graphs, subdomain discovery, and ASN lookup
Analyze URLs, domains, and content for phishing indicators and typosquatting
Analyze email headers for phishing indicators, spoofing, and security threats
Generate, verify, and identify cryptographic hashes (MD5, SHA-256, SHA-512, bcrypt, and more)
Calculate IP ranges, subnets, and network addressing for infrastructure planning
Safely defang and refang malicious indicators for secure SOC sharing
Paste or import IOCs, link to incidents and systems, pivot between related objects, and export as CSV or STIX 2.1
Decode and analyze JSON Web Tokens for security issues and debugging
Generate strong passwords, analyze strength with entropy and cracking time, and hash with bcrypt
Validate, format, and convert between JSON, YAML, and PHP array syntax with syntax highlighting and tree view
Analyze IPv4/IPv6 addresses with binary representation and range detection
Convert Unix timestamps to human-readable dates and vice versa, with batch conversion and timezone support
Test regular expressions with highlighting, pattern library, and ReDoS protection
Build HTTP requests and export as cURL, fetch, Python, PHP, and more
Compare two texts with side-by-side diff and unified format output
Parse CSV/TSV data and convert to JSON, SQL, HTML, or Markdown tables
Encode, decode, and detect text encodings: Hex, Binary, URL, HTML, Unicode, Base64, and more
Generate QR codes for URLs, WiFi, contacts, and more with custom colors
Convert colors between HEX, RGB, HSL, CMYK with WCAG contrast checker
Write Markdown with live preview and export as HTML or Markdown file
Analyze text for word count, readability scores, and keyword density
Parse cron expressions, see next run times, and build schedules visually
Decode SSL/TLS certificates to view subject, issuer, validity, and extensions
Format, beautify, and minify SQL queries with syntax highlighting
Calculate Unix/Linux file permissions (chmod) with visual editor
Parse browser user agent strings to extract browser, OS, and device information
Generate and validate UUIDs (v1, v4) with bulk generation support
Parse URLs into components, encode/decode, and build URLs from parts
Look up MAC address vendor/manufacturer from OUI database
Parse and analyze robots.txt files with URL testing and validation
Build Content-Security-Policy headers with visual interface and presets
Convert text between camelCase, snake_case, kebab-case, PascalCase, and more, plus URL slug generation
Look up MIME types by file extension for correct Content-Type headers
Generate favicons from text, emojis, or solid colors in multiple sizes
Create Apache .htaccess files with security, caching, and rewrite rules
Validate Apache and Nginx configuration syntax with best-practice checks
Test Apache mod_rewrite rules and see URL transformations
Look up network port information, security status, and common usage
Convert between number bases with step-by-step explanations and arithmetic
Aggregated security news, CVEs, and threat intel from 40+ sources (CISA, NVD, CERTs, vendors)
Extract and list all links from any webpage with filtering and export options
Analyze SSL/TLS certificates with trust score, expiration alerts, and legitimacy indicators
Convert text, hex, UUIDs, and hashes to NATO phonetic alphabet for clear verbal communication
Convert meeting times across timezones with business hours visualization and calendar export
Create .ics calendar event files compatible with Apple Calendar, Google Calendar, Outlook, and Thunderbird
Complete searchable reference of HTTP response status codes with descriptions and use cases
Complete ASCII character reference with decimal, hex, octal, and binary values
Generate placeholder text for design mockups in various formats and lengths
Check SPF, DKIM, and DMARC records to validate email authentication
Look up domain registration information using RDAP (registrar, dates, nameservers)
Generate ASCII art text banners for MOTD, scripts, and terminal displays
Geolocate any IP address, view your browser fingerprint, and detect VPN/proxy usage with privacy analysis
Generate NIS2, DORA, and GDPR incident report templates with regulatory deadlines, severity classification, and markdown export
Searchable database of 1000+ compliance specifications from NIST 800-53, DORA, GDPR, NIS2, and CRA frameworks
Safely anonymize IPs, emails, JWT tokens, session IDs, and API keys in log snippets before sharing. 100% client-side.
Build interactive incident timelines from log snippets with automatic timestamp normalization, annotations, and JSON export
Analyze USB device lists from lsusb, PowerShell, or CSV exports to identify risky devices like potential BadUSB or unknown vendors
Paste output from uptime, free, df, top, or PowerShell to get CPU, RAM, disk, and IO health analysis with severity ratings
Check if domain names are available across multiple TLDs using RDAP lookups
Generate and verify Time-based One-Time Passwords (RFC 6238) with provisioning URI builder
Generate Ed25519 and RSA SSH key pairs, analyze public keys with fingerprint and security assessment
Look up A, AAAA, MX, TXT, NS, CNAME, and SOA records for any domain with TTL and export
Generate realistic random test data: emails, usernames, IPs, domains, paths, MACs, UUIDs, and more
Encrypt and decrypt text with AES-256-GCM using Web Crypto API and PBKDF2 key derivation
Strip HTML, remove diacritics, normalize whitespace, trim BOMs, fix line endings, and remove invisible characters
Generate instant pivot links to 25+ OSINT services (Shodan, Censys, VirusTotal, urlscan) from a domain or IP
Grade HTTP security headers A+ to F with per-header analysis, scoring, and fix recommendations
Interactive DORA self-assessment covering all five pillars with Luxembourg CSSF specifics and exportable gap report
Fast offline search across ATT&CK Enterprise techniques with detection guidance and SIEM cross-links
Build Sigma detection rules visually with live YAML preview and export to Splunk SPL, QRadar AQL, and Sentinel KQL
Scan package.json, requirements.txt, or composer.json for known CVEs via OSV.dev API
Assess LinkedIn profile exposure risk from an attacker perspective. Score identity leaks, job details, network openness, and posting behavior.
Extract EXIF metadata from images client-side. GPS coordinates, camera info, timestamps, and software details for OSINT and forensics
Remove EXIF and metadata from images before sharing. Strip GPS, camera info, and identifying data. Batch processing supported
Stamp a repeated diagonal watermark onto ID cards, payslips, and PDFs before sending them to a landlord, recruiter, or insurer. 100% in-browser — nothing is uploaded. Images + PDF, batch, templates
Calculate SIEM sizing, storage, and 3-year TCO across Wazuh, Graylog, Splunk, QRadar, Sentinel, and LogRhythm with compliance retention overlay
Decode QR codes from images with URL defanging for safe SOC sharing. Drag & drop, paste, or upload
Generate a compliant /.well-known/security.txt file (RFC 9116) for vulnerability disclosure. Client-side, with validation and PGP key prompts
Visually build YARA detection rules with live preview, validation, and a client-side rule tester for malware hunting
Plot risks on likelihood-vs-impact heatmaps for ISO 27001, DORA, and NIS2 risk registers. 3x3 or 5x5, export PNG/CSV/JSON
Identify file formats by their magic numbers. Drop a file (browser reads first 64 bytes only) or paste hex. 60+ signatures for DFIR and malware triage
Generate ready-to-run incident response tabletop scenarios (ransomware, BEC, insider, supply chain, DDoS, OT) with injects, discussion questions, and Markdown export
Score your password policy against NIST SP 800-63B, NCSC, and CIS guidance. Get a graded gap report and ready-to-publish policy text
Convert IOC lists into STIX 2.1 bundles for TAXII, MISP, or OpenCTI sharing. Auto-detects type, refangs, supports TLP markings and kill-chain phases
Cross-reference NIST CSF 2.0 outcomes to ISO 27001:2022 Annex A and DORA articles. Search, filter, browse all 106 subcategories, and export the mapping as CSV / JSON / Markdown
Build a NIST CSF 2.0 Current and Target Profile across all 106 subcategories. Score on a 0-4 scale, see gap analysis by Function and Category, export JSON / CSV / Markdown. Source: NIST CSWP 29
Self-assess your NIST CSF 2.0 Implementation Tier (Partial / Risk Informed / Repeatable / Adaptive) across the Cybersecurity Risk Governance and Risk Management dimensions defined in CSWP 29
Compose advanced search-engine queries by picking operators (site:, filetype:, inurl:, intitle:, intext:, ...). Live preview, copy, or launch on Google / DuckDuckGo / Bing / Yandex / GitHub. Includes a preset gallery for OSINT and bug bounty
Build a tailored third-party / supplier security questionnaire from curated banks (governance, cloud, IAM, AppSec, IR, privacy, AI, exit) with regulatory overlays for GDPR, DORA, NIS2, PCI, HIPAA, SOC 2
Check DNS CAA records (which CAs may issue certs) and HSTS preload eligibility (max-age, includeSubDomains, preload directive) for any domain
Inspect an OpenPGP public key in your browser: version, algorithm, fingerprint, user IDs, subkeys, expiration, key flags. Refuses private key blocks. Client-side
Find a public OpenPGP key by email, fingerprint, or 16-hex key ID. Queries keys.openpgp.org with keyserver.ubuntu.com fallback; reveals every user ID, alias, email, subkey, capability, and the key timeline
Verify a password against bcrypt or Argon2 hashes, identify the algorithm, and benchmark cost factors on the server. No logging
Drop or paste Nmap -oX XML output and get a clean, filterable HTML report with severity hints. Markdown / CSV export. 100% client-side
Compose CPE 2.3 names from form fields, validate, and get one-click search links to NVD, MITRE, GitHub Advisories, OSV.dev, Vulners, and CISA KEV
Scan and redact text before pasting into ChatGPT, Claude, Gemini, or Copilot. Detects PII, API keys, secrets, internal hostnames, IBAN, credit cards. 100% client-side
Approximate token count for GPT, Claude, Gemini, Llama, DeepSeek, Mistral. Live cost matrix in $/1M tokens, editable pricing, input/output split, volume calculator
Will it fit in 128k or 1M? Paste text or drop files; see pass/warn/fail per model with reserved response budget. 100% client-side
Estimate GPU memory for Llama, Mistral, Qwen, DeepSeek, Phi, Gemma. Tweak quantization (FP16/Q8/Q5/Q4), context, batch, KV-cache dtype. Fits-on-this-GPU table
Lint your system prompt for foot-guns: weak refusals, prompt-injection vulnerabilities, missing role / output anchors, leaked credentials, contradictions
Offline search across MITRE ATLAS tactics & techniques targeting AI/ML systems (prompt injection, model evasion, data poisoning, model extraction). Detection guidance and mitigations
Walk a self-assessment for the EU AI Act (Regulation 2024/1689): scope, prohibited practices, high-risk Annex III, GPAI thresholds, transparency. Markdown export
Plain-language glossary of 100+ AI / LLM terms: token, context window, VRAM, RAG, MoE, quantization, RLHF, prompt injection, jailbreak, agent, EU AI Act. Searchable, cross-linked
Wizard-driven threat model generator for AI/ML systems. 5 steps, 27+ threats mapped to STRIDE + MITRE ATLAS + OWASP LLM Top 10. Risk-scored, with control gap analysis. Markdown / JSON export
Learn prompt injection by breaking a simulated LLM. 8 scenarios (direct, indirect, persona override, smuggling, jailbreak, multi-turn). 100% client-side pattern-matching engine, no API. Educational use only
Operational red-team checklist for LLM application security assessments. 60 items across 6 phases (recon, prompt injection, output handling, excessive agency, data exposure, DoS). Markdown report export
Self-assessment for the OWASP Top 10 for LLM Applications (v1.1 2024/2025). Score your posture across all 10 risks, identify gaps, and export CSV / JSON / Markdown. 100% client-side
Offline searchable reference for Security, System, and Sysmon event IDs with logon-type decoding and MITRE ATT&CK cross-links
Visually compose Sysmon rules and export valid XML. Include/exclude logic, per-event-type filters, and minimal/balanced/verbose presets
Build and test Grok / named-capture regex against a sample log line; export to Logstash, regex, or QRadar extraction syntax
Get the FIRST EPSS exploit-prediction score and percentile for a CVE, with CISA KEV cross-check and triage guidance
Today's must-patch CVEs — vulnerabilities newly added to the CISA KEV catalog (actively exploited) enriched with EPSS, plus the highest exploit-probability CVEs right now
Walk CISA's Stakeholder-Specific Vulnerability Categorization to a Track / Attend / Act outcome with exportable rationale
Generate valid SPF, DKIM, and DMARC DNS records with guided policy choices and common-mistake warnings
Parse DMARC aggregate (RUA) XML reports into a readable pass/fail-by-source view to spot spoofing and misconfigured senders. 100% client-side
Scan one domain and get a graded report across security.txt, DMARC, SPF, MTA-STS, CAA, DNSSEC, and HSTS. Server-side checks, your IP is not forwarded
Check hostnames for dangling CNAMEs vulnerable to subdomain takeover, matching 20+ takeover-prone services with fingerprint confirmation. Server-side, IP not forwarded
Offline searchable reference of living-off-the-land binaries (Unix + Windows) by name and abuse function, with ATT&CK cross-links
Templated reverse/bind-shell commands for authorized testing across bash, nc, python, PowerShell and more, with URL/Base64/PS encoders
Compose Hashcat masks and rule lines (and John rules) with live sample-word preview and keyspace estimates. Builder only, no cracking
Generate a key pair and PKCS#10 CSR in your browser (RSA/ECDSA, SANs), or decode an existing CSR. Private key never leaves your machine
Compute and verify HMAC signatures (SHA-1/256/384/512) for webhook and API signing. Hex or Base64 output, 100% client-side
Generate Subresource Integrity hashes (sha256/384/512) and ready-to-paste script/link tags to lock down third-party assets
Parse Set-Cookie headers and flag missing Secure/HttpOnly/SameSite, weak prefixes, and broad scopes with remediation guidance
Compile the mandatory DORA ICT third-party register across all template tables, with completeness checks and CSV/JSON/Markdown export
Self-assess NIS2 scope, Article 21 risk-management measures, and reporting obligations with scored gap report and Markdown/CSV/JSON export
Run a Business Impact Analysis: rate impact over time, derive RTO/RPO and criticality tiers, flag SPOFs. Maps to DORA operational resilience
Build a Statement of Applicability across all 93 Annex A:2022 controls with applicability decisions, justifications, and CSV/JSON/Markdown export
Self-assess against the NIST AI Risk Management Framework (Govern/Map/Measure/Manage) with scored gaps and Markdown/CSV/JSON export