Every routable page in the DFIR / security-toolkit area - 134 pages across 21 hubs. Search by name, route, or keyword, or filter by category. New pages are added to the home page and the sidebar automatically.
?q=...&cat=...Catalog and entry points for the DFIR / security toolkit area.
Check, extract, and track indicators across 60+ sources - IP, domain, URL, hash pivots with cross-source consensus.
Cross-source investigation hub - paste any indicator type and pivot across all sources.
/dfir/ioc-investigateopen Pull IOCs from any text blob - refang-aware.
/dfir/extractopen Watch CT logs for new certificates matching your watchlist.
/dfir/ct-monitoropen Curated catalog of 145+ free open-source threat intel feeds - IP, DNS, URL, hash, CVE, JA3, and more. Search by vendor, category, or keyword.
/dfir/oss-feedsopen Search the ORKL open-source threat intelligence library - reports, actors, CVEs from hundreds of sources.
/dfir/orklopen SHA-256 hash reputation lookup via Traceix - per-engine antivirus/AV verdicts (Safe/Malicious/Unknown).
/dfir/traceixopen Multi-source URL risk scoring - static signals + VirusTotal, Safe Browsing, URLScan, AbuseIPDB and WHOIS-age correlation (IntelX framework port). 0-100 score with evidence chain.
/dfir/url-riskopen Reverse WHOIS lookup via Whoxy - find all domains registered by an email, name, company, or keyword.
/dfir/whoxyopen Triage, parse, and deobfuscate samples - stealer logs, packed binaries, malicious documents, and PCAPs.
PE / ELF / Mach-O static analysis with import hashing + section entropy.
/dfir/malware-analyzeropen Parse RedLine / Raccoon / Vidar / LummaC stealer logs - credentials, system, browser data.
/dfir/stealer-parseropen Infostealer-specific intelligence dashboard - prevalent families, log types, and compromised credential tracking.
/dfir/infostealer-intelopen Decode, hash, and inspect binaries, encoded payloads, and document formats - runs entirely in the browser.
Decode and encode across base64, hex, URL, rot13, zlib, gzip with auto-detection.
/dfir/codecopen MD5 - SHA1 - SHA256 - SHA512 - SSDEEP - TLSH - drag a file in.
/dfir/hash-calcopen Epoch - Windows FILETIME - Unix - human - bidirectional.
/dfir/timestampopen Manifest + permissions + signing certs + native libs.
/dfir/apk-analyzeropen EXIF - IPTC - XMP - MakerNotes - camera, GPS, software fingerprints.
/dfir/exifopen Apple binary plist + protobuf human-readable view.
/dfir/plist-protobufopen Visualise IDN homograph attacks - Cyrillic vs Latin lookalikes.
/dfir/punycodeopen Unroll encoded / base64 / invoke-expression chains - step by step.
/dfir/powershell-deobfopen Static-analysis a PowerShell script for malicious behavior - 250+ signatures, MITRE ATT&CK mapping, IOC extraction, obfuscation scoring, risk score, 100% client-side.
/dfir/powershell-analyzeropen Upload a file - extract metadata, hashes, strings, and embedded indicators.
/dfir/fileopen Endpoint forensic artifacts - PCAP, registry, EVTX, SQLite, browser, mobile, and web logs.
Protocol breakdown - top talkers - DNS / HTTP / TLS summaries.
/dfir/pcap-triageopen Browse - search - diff Windows registry hives offline.
/dfir/registry-hiveopen Parse Windows Event Log files - event IDs, channels, time-range filter.
/dfir/evtxopen Browser profile - chat history - mobile backups - query in-browser via WASM.
/dfir/sqliteopen Manifest.db - plists - SQLite artifacts from a local iTunes backup.
/dfir/ios-backupopen Apache - nginx - IIS access logs - anomaly detection + pivots.
/dfir/web-logopen Parse Windows Prefetch files - execution evidence, run count, last run time.
/dfir/prefetchopen Windows Registry Forensic Artifact Reference - 292 artifacts, 16 categories, 10 hive types, 77 MITRE techniques.
/dfir/winregopen Neo23x0 signature-base - 746 YARA rule files (5,784 rules) + 4 IOC lists (hashes, C2, filenames, keywords).
/dfir/sigbaseopen Event IDs, memory forensics, browser artifacts, evidence collection phases — practitioner reference.
/dfir/dfir-refopen Build a defensible custody timeline — evidence inventory with hashes, transfer handlers, timestamps.
/dfir/coc-generatoropen WHOIS, DNS, reputation, certificates, and infrastructure pivots - passive reconnaissance, no active scanning.
Cross-source domain investigation hub - 6 aliases route here (domain-rep, webcheck, etc.).
/dfir/domain-investigatoropen Historical WHOIS pivots - registrant, nameserver, status changes.
/dfir/whois-historyopen ASN details - prefix ranges - peer relationships.
/dfir/asnopen crt.sh-style CT log search for a domain - subdomains - cert chain.
/dfir/cert-searchopen Graph view of a domain's nameservers, mail servers, and cross-delegations
/dfir/dnscopeopen Graph of related domains, IPs, and ASNs for a target.
/dfir/host-graphopen Search historical snapshots for a URL - changes over time.
/dfir/waybackopen Historical DNS resolution data for infrastructure tracking - migrations + fast-flux detection.
/dfir/passive-dnsopen Exposed-host analysis, asset intelligence, and web vulnerability scanning - see what an attacker would see.
Aggregate asset inventory - domains, subdomains, services, certificates.
/dfir/asset-intelopen Per-host exposure score and evidence - services, versions, CVEs.
/dfir/exposed-hostopen Detect misconfigured web servers exposing file listings.
/dfir/open-directoryopen Safe, sandboxed preview of a URL - headers, redirects, screenshot.
/dfir/url-previewopen Detect dangling CNAMEs pointing to expired or unclaimed third-party services.
/dfir/subdomain-takeoveropen External attack surface exposure - open ports, services, certificates, and misconfigurations.
/dfir/exposureopen Phishing analysis, BEC defense, and email authentication audits - SPF / DKIM / DMARC / BIMI without sending data off-host.
SPF / DKIM / DMARC / BIMI audit with failure modes called out.
/dfir/email-defenseopen URL + sender + header analysis with risk score.
/dfir/phishingopen Parse a DMARC aggregate report (RUA) - alignment, volume, failures.
/dfir/dmarc-analyzeropen Headers - body - attachments - URL / hash extraction from a .eml file.
/dfir/emlopen Sender domain + IP reputation with deliverability signals.
/dfir/email-repopen Build digital identity from email - GitHub, Gravatar, breach, reputation, DNS, PGP.
/dfir/email-osnitopen Curated playbook of phishing patterns, lures, and IOCs.
/dfir/phishbookopen Phishing-as-a-service operator catalog and tracking.
/dfir/phishopsopen Username, email, phone, image, and social reconnaissance - cross-platform pivots for a single subject.
Alias of /dfir/username - the canonical page.
/dfir/username-investigatoropen Phone number OSINT - carrier lookup, line type, breach presence, and AI-powered risk scoring.
/dfir/phone-hubopen Wireless network - BSSID vendor lookup, SSID analysis, security flags.
/dfir/wifi-investigationopen Social-media intelligence - X / Reddit / Telegram / Mastodon pivots.
/dfir/socmintopen Build a mind-map of an investigation - nodes are entities, edges are pivots.
/dfir/osint-mapperopen Email / username / domain - cross-correlate public breach corpora.
/dfir/breachopen Image analysis - reverse search, perceptual fingerprinting, and OCR screenshot intelligence.
/dfir/image-intelopen Detect typosquats / look-alike domains targeting your brand.
/dfir/brand-impersonationopen Inventory and risk-tier non-human & agent identities (service accounts, API keys, AI agents) against the OWASP NHI Top 10 - deterministic Tier 1-4 rules with least-privilege remediation for every finding.
/dfir/nhi-scanopen CVE lookup, prioritisation, exploit intel, and dependency scanning - know what to patch first.
Single-CVE detail - NVD, KEV, EPSS, exploit availability.
/dfir/cveopen CVSS + EPSS + KEV + ransomware-use - single patch-priority call.
/dfir/cve-prioritizeropen Curated list of CVE databases, exploit trackers, vendor PSIRTs.
/dfir/vuln-toolkitopen Paste a manifest.json / package-lock / requirements.txt - known vulns.
/dfir/osv-scanopen CTI priority score (CVSS + EPSS + KEV + recency) plotted against CVSS — quadrant scatter plot + sortable table + SSVC-V decisions.
/dfir/cve-risk-matrixopen Continuous threat exposure management - fusion scoring, attack path analysis, risk register, GRC evidence, vulnerability ops, ransomware quantification, patch management, and SOC automation.
Composite 4-dimension scoring (CVSS/KEV/EPSS/Exploit-DB) - ranked worklist with per-dimension breakdown.
/dfir/fusion-exposureopen Full lifecycle CRUD with FAIR quantification, inherent->residual levels, and treatment plans.
/dfir/risk-registeropen BFS shortest-path reachability from exposed assets to crown jewels - choke point detection, demo fallback.
/dfir/attack-pathopen Framework selector (SOC2/ISO27001/NIST/PCI/HIPAA), control tree, evidence collection with inline status.
/dfir/grc-evidenceopen Intake / triage / SLA tracking - severity, status, source filters with auto-computed deadlines.
/dfir/vulnerability-opsopen Scenario-based financial impact across 7 cost dimensions with insurance recovery modeling.
/dfir/ransomware-quantopen Vendor advisory intake, maintenance window scheduling, approval workflows, deploy tracking.
/dfir/patch-task-mgropen Playbook engine with configurable actions (webhook/email/slack/KB/MCP) - one-click execute, run history.
/dfir/soc-automationopen Author, convert, and test detection rules - Sigma, KQL, SPL, YARA, ATT&CK mapping, hunting queries.
Sigma - KQL - SPL - YARA via one canonical IR.
/dfir/rule-converteropen Collaborative YARA editor with malware test corpus.
/dfir/yara-workbenchopen Indicator - relationship graph - visual pivot from any node.
/dfir/threat-graphopen Invariant detection points - prerequisites attackers cannot bypass, mapped to MITRE ATT&CK.
/dfir/detection-chokepointsopen Step-by-step playbooks for common incident types.
/dfir/ir-playbooksopen Trace a rule back to its source intel - coverage and lineage.
/dfir/tracerulesopen 60 detection use-cases across 16 categories — KQL + SPL starter rules with MITRE mapping.
/dfir/siem-libraryopen 154 hunt hypotheses across 12 MITRE tactics — technique-driven, data-source-aware starter queries.
/dfir/hunt-hypothesesopen Alert fatigue index, SOAR ROI, EDR maturity, and log volume estimators.
/dfir/soc-calculatorsopen Build v15 Sysmon XML configs — verbose, baseline, and lean presets with field-level exclude mode.
/dfir/sysmon-configopen STIX 2.1 bundle builder, TAXII server, and viewable graph - interoperable CTI artefacts.
IAM, network, secrets, and configuration analysis for AWS, GCP, Azure, and Kubernetes.
Cloud identity analysis - AWS, GCP, Azure, and Kubernetes RBAC policy analyzers.
/dfir/iam-hubopen AWS security group visualizer - 0.0.0.0/0 + port exposure heatmap.
/dfir/sg-analyzeropen Filter CloudTrail logs for an incident timeframe - IAM, EC2, S3, KMS.
/dfir/cloudtrail-triageopen Static analysis of HCL - misconfigurations + drift.
/dfir/terraform-scanopen Catalogue service accounts, API keys, OAuth grants.
/dfir/nhiopen Verify identity + intent for autonomous agent actions.
/dfir/zero-trust-ai-agentsopen AWS / Azure / GCP / OCI SRM — 16 domains, customer/cloud responsibilities, cloud hunt queries by provider.
/dfir/cloud-referenceopen LLM red-teaming, prompt-injection defense, MCP audit, and agent attack-surface analysis.
Test a prompt against a curated set of injection payloads.
/dfir/prompt-injectionopen Arcanum Prompt Injection Taxonomy - 172 classified attack nodes.
/dfir/pi-taxonomyopen Audit a Model Context Protocol server for tool-poisoning vectors.
/dfir/mcp-auditopen AI agent investigation - tool-call analysis, observable enrichment, and attack-surface mapping.
/dfir/agent-suiteopen Tracked real-world threat-actor uses of AI/LLMs - 79 entries, MITRE ATT&CK mapped, from the Cybershujin tracker.
/dfir/ai-threatsopen AI-assisted investigation - incident summarisation, query generation, timeline reconstruction, malware briefing, and IOC verdicts.
/dfir/ai-suiteopen OpenAPI, GraphQL, JWT, secrets, and headers - application-layer security analysis.
Lint an OpenAPI spec - missing auth, schema issues, PII exposure.
/dfir/openapi-auditopen Introspection + query depth/complexity + authz analysis.
/dfir/graphql-auditopen Decode - verify - alg-confusion check - claim analysis.
/dfir/jwtopen Third-party live HSTS/CSP/X-Frame-Options scan via IntoDNS.ai with ready-to-paste Nginx/Apache/Caddy/Cloudflare configs.
/dfir/sec-headers-liveopen Scan a text blob / repo for API keys, tokens, private keys.
/dfir/secret-scanopen AI-first security scanner - SAST (Python/JS/Go/Rust/PHP), secrets, prompt injection detection. 140+ rules, runs entirely in browser.
/dfir/medusa-scanopen Generate HTML/XHR/fetch proof-of-concept exploits for CSRF testing.
/dfir/csrf-pocopen Curated XSS payload library - filter by context, severity, or tags.
/dfir/xss-payloadsopen Compose a Google dork for a target - site:, inurl:, filetype:.
/dfir/google-dorksopen Generic log parser - pattern detection + anomaly highlighting.
/dfir/log-parseropen Conversational copilots and AI-assisted investigation workbenches - natural-language pivots.
Conversational copilot - ask in plain English, get a runbook.
/dfir/copilotopen Cross-chain transaction tracing, real-time flow monitoring, and quick address lookups for AML and ransomware investigations.
/dfir/crypto-traceropen Pivot explorer - graph-style pivots from any entity.
/dfir/pivexopen AI agent investigation sessions - quality scores, IOCs, and key findings.
/dfir/agent-historyopen Draft investigation reports, ingest external reports, and export IOCs to any standard format.
Analyze external reports and compose investigation reports - AI summarisation, IOC extraction, MITRE mapping, PDF/DOCX export.
/dfir/report-hubopen Export IOCs to STIX 2.1, MISP, Sigma, YARA, Snort, Suricata, CSV.
/dfir/export-hubopen Generate network blocklists (pfSense, MikroTik, Cisco) from IOCs.
/dfir/blocklistsopen Persistent notes, IOC snapshots, and findings for DFIR investigations.
/dfir/notebooksopen PGP, Tor, and dark-web workbench - the on-ramp and off-ramp tooling for sensitive investigations.
Compliance, maturity, tabletop exercises, and reference frameworks - policy and posture.
Control mapping - risk register - vendor assessment.
/dfir/grcopen Living-off-the-land binaries - search by binary or behaviour.
/dfir/lolbinsopen Tag data with sensitivity + handling requirements.
/dfir/data-classificationopen GDPR / CCPA references, DPIA templates, privacy notice generator.
/dfir/privacy-hubopen Data-loss-prevention scan for files + clipboard + screenshots.
/dfir/dlp-scanopen Bash one-liners for live Linux incident response.
/dfir/linux-triageopen Control checklists for NIST CSF, ISO 27001, SOC 2, PCI DSS v4, DPDP 2023, CERT-In, SEBI — plus cross-framework mapper.
/dfir/grc-checklistsopen Algorithm profiles, HNDL threat model, crypto-class readiness assessment, and migration checklist.
/dfir/pqcopen Reference frameworks, attack models, and visual matrices analysts use to structure intrusions and security programs.
Layered ATT&CK matrix - coverage heatmap, gap analysis.
/dfir/attack-navigatoropen Lockheed Martin 7-phase kill chain with ATT&CK cross-links.
/dfir/kill-chainopen Adversary - capability - infrastructure - victim - reference.
/dfir/diamondopen Web 2021 - API 2023 - LLM 2025 reference + checklist.
/dfir/owaspopen Concealment Layers for Online Anonymity and Knowledge — adversary tactics, techniques, sub-techniques, and procedures.
/dfir/cloakopen