The independent analyst’s toolkit
Less noise.
More evidence.
Follow the traffic. Unpack the file. Make the call.
Twelve practical security tools, right in your browser.
Free to use No account required Built for real work
Your workbench
A tool for the next question.
From the first indicator to the final report.
Pick a starting point and get to work.
12 tools ready to use
Collect
Examine
- PCAP TriageProtocol decoding and flow tracking over a capture, in the tab..pcap · .pcapng · .cap
- Email ForensicsSender verification, header hops and IOCs from a raw message..eml · .txt
- Binary TriageStatic PE, ELF and Mach-O work: headers, imports, entropy, strings.PE · ELF · Mach-O
- Artifact TriageHashing, entropy, YARA matching and IOC detection on a dropped file.Files · hashes · YARA
- Hash AnalysisHash type identification with hashcat and john command generation.Hashes · hashcat · John
Decide
- Incident ResponseLocal case management with a timeline and evidence trail.Cases · evidence · timelines
- CVSS TriageCVSS v4 vector parsing with context-aware triage guidance.CVSS v4 · context · priority
- Risk RegisterScenario and treatment tracking you can hand to someone else.Scenarios · treatment · review
No matching tools
Try a task like “phishing” or a file type like “pcap”.
Built at the workbench.
Tools for investigating, understanding and sharing what you find.
