Free tools
39 tools that show you where you stand.
Each one runs on assets you own or on public data, gives a clear result, and says what it could not see. No signup, no email gate. Where a result deserves a record, the tool issues a signed report you can verify.
Authorized use only. These tools are defensive. Use them on systems you own or are entitled to assess, or on lawfully public data — never to probe systems or people that are not yours.
I have…
Matching tools
All 39 tools.
- Cybersecurity
Security Header & SSL Grader
Grade any site's HTTP security headers and TLS configuration.
Run it - Cybersecurity
SPF/DKIM/DMARC Spoof Checker
Check whether attackers can spoof your email domain.
Run it - Cybersecurity
Password Exposure & Entropy Analyzer
Measure password strength and check breach exposure privately.
Run it - Cybersecurity
Phishing Link Inspector
Spot the red flags in a suspicious link, safely.
Run it - Cybersecurity
Attack Surface Mapper
Triage the hostnames your domain has already made public.
Run it - Cybersecurity
Vulnerability CVE Lookup
Search CVEs by product and version with severity and guidance.
Run it - Blockchain & Web3
Smart Contract Address Risk Scanner
Flag risk signals for a smart contract address.
Run it - Blockchain & Web3
Token Approval Revoke Inspector
Find risky token approvals on a wallet and revoke them.
Run it - Blockchain & Web3
Wallet Exposure Checker
Surface interaction and exposure risk for a public wallet.
Run it - Intelligence & OSINT
Metadata Extractor / Scrubber
Reveal and strip hidden metadata from your files.
Run it - Intelligence & OSINT
Threat Intel Indicator / IP Lookup
Reputation and context for an IP, domain or hash — with honest coverage.
Run it - Intelligence & OSINT
Public Data Leak Exposure Finder
See which public breaches name your domain — and what cannot be undone.
Run it - Cybersecurity
Backup Recoverability Analyzer
Find out whether your backup policy would actually recover you.
Run it - Blockchain & Web3
Backtest Integrity Analyzer
Check a backtest summary for the ways it can be true and still misleading.
Run it - Cybersecurity
Detection Rule Analyzer
Review a Sigma, YARA or KQL rule before it reaches production.
Run it - Intelligence & OSINT
IOC Normaliser & Correlator
Turn a messy pile of indicators into one comparable set.
Run it - Cybersecurity
Incident Timeline Builder
Turn mixed log formats into one ordered, honestly-qualified timeline.
Run it - Cybersecurity
Mobile App Permission Auditor
See what a mobile app's manifest actually asks for.
Run it - Cybersecurity
SSH Configuration Analyzer
See what your sshd_config actually does, not what it appears to say.
Run it - Cybersecurity
Email Header Forensics
Read what the receiving server actually recorded about a message.
Run it - Cybersecurity
Password Policy Analyzer
Judge a password policy against what actually works.
Run it - Cybersecurity
Encoded Payload Decoder
Peel an obfuscated string apart without running it.
Run it - Cybersecurity
Dockerfile Hardening Analyzer
See what your image will actually be when it runs.
Run it - Cybersecurity
Kubernetes Manifest Analyzer
See what a workload can reach once it is scheduled.
Run it - Intelligence & OSINT
Tabular PII Scanner
Find the personal data in an extract before you share it.
Run it - Cybersecurity
Web Server Config Analyzer
Read the file that decides your headers, not just the response.
Run it - Cybersecurity
GitHub Actions Workflow Analyzer
Find the workflow patterns that hand a fork your secrets.
Run it - Cybersecurity
Cloud IAM Policy Analyzer
Find the permission pairs that reach administrator.
Run it - Cybersecurity
TLS Certificate Chain Analyzer
Find the missing intermediate before a client without your cache does.
Run it - Cybersecurity
Dependency Manifest Analyzer
See what installing this actually runs.
Run it - Cybersecurity
Terraform Exposure Analyzer
The port decides the severity, not the CIDR.
Run it - Intelligence & OSINT
OSINT Exposure Scanner
See what your domain reveals about you in public sources.
Run it - Intelligence & OSINT
Subject Intelligence Scanner
Correlate the identifiers you already hold about a subject — with evidence you can audit.
Run it - Cybersecurity
CSP & Web Security Policy Analyzer
Find what your Content-Security-Policy actually allows.
Run it - Cybersecurity
Cookie Security Auditor
Audit Set-Cookie headers for the flags that actually matter.
Run it - Cybersecurity
JWT Safety Inspector
Decode a JSON Web Token and see what it actually permits.
Run it - Cybersecurity
CORS Configuration Inspector
See what your CORS headers really let other sites do.
Run it - Cybersecurity
OAuth / OIDC Configuration Inspector
See what your authorization server advertises it will accept.
Run it - Cybersecurity
API Security Posture Analyzer
Turn an OpenAPI spec into a map of what to test.
Run it
Cybersecurity
28 tools- Security Header & SSL GraderGrade any site's HTTP security headers and TLS configuration.
- SPF/DKIM/DMARC Spoof CheckerCheck whether attackers can spoof your email domain.
- Password Exposure & Entropy AnalyzerMeasure password strength and check breach exposure privately.
- Phishing Link InspectorSpot the red flags in a suspicious link, safely.
- Attack Surface MapperTriage the hostnames your domain has already made public.
- Vulnerability CVE LookupSearch CVEs by product and version with severity and guidance.
- Backup Recoverability AnalyzerFind out whether your backup policy would actually recover you.
- Detection Rule AnalyzerReview a Sigma, YARA or KQL rule before it reaches production.
- Incident Timeline BuilderTurn mixed log formats into one ordered, honestly-qualified timeline.
- Mobile App Permission AuditorSee what a mobile app's manifest actually asks for.
- SSH Configuration AnalyzerSee what your sshd_config actually does, not what it appears to say.
- Email Header ForensicsRead what the receiving server actually recorded about a message.
- Password Policy AnalyzerJudge a password policy against what actually works.
- Encoded Payload DecoderPeel an obfuscated string apart without running it.
- Dockerfile Hardening AnalyzerSee what your image will actually be when it runs.
- Kubernetes Manifest AnalyzerSee what a workload can reach once it is scheduled.
- Web Server Config AnalyzerRead the file that decides your headers, not just the response.
- GitHub Actions Workflow AnalyzerFind the workflow patterns that hand a fork your secrets.
- Cloud IAM Policy AnalyzerFind the permission pairs that reach administrator.
- TLS Certificate Chain AnalyzerFind the missing intermediate before a client without your cache does.
- Dependency Manifest AnalyzerSee what installing this actually runs.
- Terraform Exposure AnalyzerThe port decides the severity, not the CIDR.
- CSP & Web Security Policy AnalyzerFind what your Content-Security-Policy actually allows.
- Cookie Security AuditorAudit Set-Cookie headers for the flags that actually matter.
- JWT Safety InspectorDecode a JSON Web Token and see what it actually permits.
- CORS Configuration InspectorSee what your CORS headers really let other sites do.
- OAuth / OIDC Configuration InspectorSee what your authorization server advertises it will accept.
- API Security Posture AnalyzerTurn an OpenAPI spec into a map of what to test.
Blockchain & Web3
4 tools- Smart Contract Address Risk ScannerFlag risk signals for a smart contract address.
- Token Approval Revoke InspectorFind risky token approvals on a wallet and revoke them.
- Wallet Exposure CheckerSurface interaction and exposure risk for a public wallet.
- Backtest Integrity AnalyzerCheck a backtest summary for the ways it can be true and still misleading.
Intelligence & OSINT
7 tools- Metadata Extractor / ScrubberReveal and strip hidden metadata from your files.
- Threat Intel Indicator / IP LookupReputation and context for an IP, domain or hash — with honest coverage.
- Public Data Leak Exposure FinderSee which public breaches name your domain — and what cannot be undone.
- IOC Normaliser & CorrelatorTurn a messy pile of indicators into one comparable set.
- Tabular PII ScannerFind the personal data in an extract before you share it.
- OSINT Exposure ScannerSee what your domain reveals about you in public sources.
- Subject Intelligence ScannerCorrelate the identifiers you already hold about a subject — with evidence you can audit.