Every routable page in the DFIR / security-toolkit area - 145 pages across 21 hubs. Search by name, route, or keyword, or filter by category. New pages are added to the home page and the sidebar automatically.
?q=...&cat=...Catalog and entry points for the DFIR / security toolkit area.
Check, extract, and track indicators across 24+ sources - IP, domain, URL, hash pivots with cross-source consensus.
Cross-source investigation hub - paste any indicator type and pivot across all sources.
/dfir/ioc-investigateopen Pull IOCs from any text blob - refang-aware.
/dfir/extractopen Track an IOC from collection to enrichment to retirement.
/dfir/ioc-lifecycleopen Watch CT logs for new certificates matching your watchlist.
/dfir/ct-monitoropen Cross-source reputation: AbuseIPDB, Spamhaus, OTX, URLhaus.
/dfir/abuse-repopen Streaming verdicts from X (Twitter) intelligence feeds.
/dfir/x-verdiktopen Curated catalog of 145+ free open-source threat intel feeds - IP, DNS, URL, hash, CVE, JA3, and more. Search by vendor, category, or keyword.
/dfir/oss-feedsopen Search the ORKL open-source threat intelligence library - reports, actors, CVEs from hundreds of sources.
/dfir/orklopen SHA-256 hash reputation lookup via Traceix - per-engine antivirus/AV verdicts (Safe/Malicious/Unknown).
/dfir/traceixopen Reverse WHOIS lookup via Whoxy - find all domains registered by an email, name, company, or keyword.
/dfir/whoxyopen Triage, parse, and deobfuscate samples - stealer logs, packed binaries, malicious documents, and PCAPs.
PE / ELF / Mach-O static analysis with import hashing + section entropy.
/dfir/malware-analyzeropen Parse RedLine / Raccoon / Vidar / LummaC stealer logs - credentials, system, browser data.
/dfir/stealer-parseropen Membership-test against a corpus of known-bad indicators.
/dfir/bloomopen Infostealer-specific intelligence dashboard - prevalent families, log types, and compromised credential tracking.
/dfir/infostealer-intelopen Rhysida ransomware intrusion analysis - TTPs, IOCs, detection rules, and mitigation guidance.
/dfir/rhysida-intrusionopen Decode, hash, and inspect binaries, encoded payloads, and document formats - runs entirely in the browser.
Decode and encode across base64, hex, URL, rot13, zlib, gzip with auto-detection.
/dfir/codecopen MD5 - SHA1 - SHA256 - SHA512 - SSDEEP - TLSH - drag a file in.
/dfir/hash-calcopen Epoch - Windows FILETIME - Unix - human - bidirectional.
/dfir/timestampopen Sections, imports, exports, version info - 0x12 lite profile.
/dfir/peopen Manifest + permissions + signing certs + native libs.
/dfir/apk-analyzeropen EXIF - IPTC - XMP - MakerNotes - camera, GPS, software fingerprints.
/dfir/exifopen Apple binary plist + protobuf human-readable view.
/dfir/plist-protobufopen Visualise IDN homograph attacks - Cyrillic vs Latin lookalikes.
/dfir/punycodeopen Unroll encoded / base64 / invoke-expression chains - step by step.
/dfir/powershell-deobfopen Upload a file - extract metadata, hashes, strings, and embedded indicators.
/dfir/fileopen Endpoint forensic artifacts - PCAP, registry, EVTX, SQLite, browser, mobile, and web logs.
Protocol breakdown - top talkers - DNS / HTTP / TLS summaries.
/dfir/pcap-triageopen Browse - search - diff Windows registry hives offline.
/dfir/registry-hiveopen Parse Windows Event Log files - event IDs, channels, time-range filter.
/dfir/evtxopen Browser profile - chat history - mobile backups - query in-browser via WASM.
/dfir/sqliteopen Manifest.db - plists - SQLite artifacts from a local iTunes backup.
/dfir/ios-backupopen Apache - nginx - IIS access logs - anomaly detection + pivots.
/dfir/web-logopen Parse Windows Prefetch files - execution evidence, run count, last run time.
/dfir/prefetchopen Multi-hive registry scope: persistence, autoruns, services, scheduled tasks.
/dfir/regscopeopen Windows Registry Forensic Artifact Reference - 292 artifacts, 16 categories, 10 hive types, 77 MITRE techniques.
/dfir/winregopen WHOIS, DNS, reputation, certificates, and infrastructure pivots - passive reconnaissance, no active scanning.
Cross-source domain investigation hub - 6 aliases route here (domain-rep, webcheck, etc.).
/dfir/domain-investigatoropen Historical WHOIS pivots - registrant, nameserver, status changes.
/dfir/whois-historyopen ASN details - prefix ranges - peer relationships.
/dfir/asnopen crt.sh-style CT log search for a domain - subdomains - cert chain.
/dfir/cert-searchopen Graph view of a domain's nameservers, mail servers, and cross-delegations
/dfir/dnscopeopen Graph of related domains, IPs, and ASNs for a target.
/dfir/host-graphopen Search historical snapshots for a URL - changes over time.
/dfir/waybackopen IP - country / city / ASN / org / hosting type.
/dfir/ip-geoopen Historical DNS resolution data for infrastructure tracking - migrations + fast-flux detection.
/dfir/passive-dnsopen Map and visualize infrastructure fleet - hosts, services, domains, and relationships.
/dfir/fleet-mapopen Exposed-host analysis, asset intelligence, and web vulnerability scanning - see what an attacker would see.
Aggregate asset inventory - domains, subdomains, services, certificates.
/dfir/asset-intelopen Per-host exposure score and evidence - services, versions, CVEs.
/dfir/exposed-hostopen Detect misconfigured web servers exposing file listings.
/dfir/open-directoryopen Safe, sandboxed preview of a URL - headers, redirects, screenshot.
/dfir/url-previewopen Detect dangling CNAMEs pointing to expired or unclaimed third-party services.
/dfir/subdomain-takeoveropen External attack surface exposure - open ports, services, certificates, and misconfigurations.
/dfir/exposureopen Phishing analysis, BEC defense, and email authentication audits - SPF / DKIM / DMARC / BIMI without sending data off-host.
SPF / DKIM / DMARC / BIMI audit with failure modes called out.
/dfir/email-defenseopen URL + sender + header analysis with risk score.
/dfir/phishingopen Parse a DMARC aggregate report (RUA) - alignment, volume, failures.
/dfir/dmarc-analyzeropen Headers - body - attachments - URL / hash extraction from a .eml file.
/dfir/emlopen Paste or upload a raw .eml to get spam score, SPF/DKIM/DMARC alignment, and inbox-placement suggestions.
/dfir/email-deliverabilityopen Sender domain + IP reputation with deliverability signals.
/dfir/email-repopen Build digital identity from email - GitHub, Gravatar, breach, reputation, DNS, PGP.
/dfir/email-osnitopen Curated playbook of phishing patterns, lures, and IOCs.
/dfir/phishbookopen Phishing-as-a-service operator catalog and tracking.
/dfir/phishopsopen Cross-source URL reputation - PhishTank, OpenPhish, Google Safe Browsing.
/dfir/url-repopen Username, email, phone, image, and social reconnaissance - cross-platform pivots for a single subject.
Alias of /dfir/username - the canonical page.
/dfir/username-investigatoropen Phone number OSINT - carrier lookup, line type, breach presence, and AI-powered risk scoring.
/dfir/phone-hubopen Wireless network - BSSID vendor lookup, SSID analysis, security flags.
/dfir/wifi-investigationopen Reverse geocoding + historical weather for a timestamp + coordinates.
/dfir/weather-osintopen Social-media intelligence - X / Reddit / Telegram / Mastodon pivots.
/dfir/socmintopen Build a mind-map of an investigation - nodes are entities, edges are pivots.
/dfir/osint-mapperopen Email / username / domain - cross-correlate public breach corpora.
/dfir/breachopen Image analysis - reverse search, perceptual fingerprinting, and OCR screenshot intelligence.
/dfir/image-intelopen Detect typosquats / look-alike domains targeting your brand.
/dfir/brand-impersonationopen Real-time OSINT command center - alerts, flights, strikes, markets, satellite thermal.
/dfir/ironsightopen CVE lookup, prioritisation, exploit intel, and dependency scanning - know what to patch first.
Single-CVE detail - NVD, KEV, EPSS, exploit availability.
/dfir/cveopen CVSS + EPSS + KEV + ransomware-use - single patch-priority call.
/dfir/cve-prioritizeropen Curated list of CVE databases, exploit trackers, vendor PSIRTs.
/dfir/vuln-toolkitopen Paste a manifest.json / package-lock / requirements.txt - known vulns.
/dfir/osv-scanopen Simulate WordPress vulnerability scenarios - core, plugin, and theme CVE testing.
/dfir/wordpress-simopen Continuous threat exposure management - fusion scoring, attack path analysis, risk register, GRC evidence, vulnerability ops, ransomware quantification, patch management, and SOC automation.
Composite 4-dimension scoring (CVSS/KEV/EPSS/Exploit-DB) - ranked worklist with per-dimension breakdown.
/dfir/fusion-exposureopen Full lifecycle CRUD with FAIR quantification, inherent->residual levels, and treatment plans.
/dfir/risk-registeropen BFS shortest-path reachability from exposed assets to crown jewels - choke point detection, demo fallback.
/dfir/attack-pathopen Framework selector (SOC2/ISO27001/NIST/PCI/HIPAA), control tree, evidence collection with inline status.
/dfir/grc-evidenceopen Intake / triage / SLA tracking - severity, status, source filters with auto-computed deadlines.
/dfir/vulnerability-opsopen Scenario-based financial impact across 7 cost dimensions with insurance recovery modeling.
/dfir/ransomware-quantopen Vendor advisory intake, maintenance window scheduling, approval workflows, deploy tracking.
/dfir/patch-task-mgropen Playbook engine with configurable actions (webhook/email/slack/KB/MCP) - one-click execute, run history.
/dfir/soc-automationopen Author, convert, and test detection rules - Sigma, KQL, SPL, YARA, ATT&CK mapping, hunting queries.
Sigma - KQL - SPL - YARA via one canonical IR.
/dfir/rule-converteropen Collaborative YARA editor with malware test corpus.
/dfir/yara-workbenchopen Indicator - relationship graph - visual pivot from any node.
/dfir/threat-graphopen AI-assisted mapping of detection rules to ATT&CK techniques.
/dfir/attmap-aiopen AI-assisted KQL / SPL / Lucene generation from a hypothesis.
/dfir/hunting-query-generatoropen Generate a Sigma/YARA rule from a natural-language description.
/dfir/ai-rule-generatoropen False-positive analyst - score a detection against historical FPs.
/dfir/fp-lensopen Invariant detection points - prerequisites attackers cannot bypass, mapped to MITRE ATT&CK.
/dfir/detection-chokepointsopen Interactive network defense simulation - 3 scenarios over 8 years of attack evolution.
/dfir/long-watchopen Step-by-step playbooks for common incident types.
/dfir/ir-playbooksopen Trace a rule back to its source intel - coverage and lineage.
/dfir/tracerulesopen STIX 2.1 bundle builder, TAXII server, and viewable graph - interoperable CTI artefacts.
IAM, network, secrets, and configuration analysis for AWS, GCP, Azure, and Kubernetes.
Cloud identity analysis - AWS, GCP, Azure, and Kubernetes RBAC policy analyzers.
/dfir/iam-hubopen AWS security group visualizer - 0.0.0.0/0 + port exposure heatmap.
/dfir/sg-analyzeropen Filter CloudTrail logs for an incident timeframe - IAM, EC2, S3, KMS.
/dfir/cloudtrail-triageopen Static analysis of HCL - misconfigurations + drift.
/dfir/terraform-scanopen Catalogue service accounts, API keys, OAuth grants.
/dfir/nhiopen Verify identity + intent for autonomous agent actions.
/dfir/zero-trust-ai-agentsopen LLM red-teaming, prompt-injection defense, MCP audit, and agent attack-surface analysis.
Test a prompt against a curated set of injection payloads.
/dfir/prompt-injectionopen Arcanum Prompt Injection Taxonomy - 172 classified attack nodes.
/dfir/pi-taxonomyopen Audit a Model Context Protocol server for tool-poisoning vectors.
/dfir/mcp-auditopen AI agent investigation - tool-call analysis, observable enrichment, and attack-surface mapping.
/dfir/agent-suiteopen Tracked real-world threat-actor uses of AI/LLMs - 79 entries, MITRE ATT&CK mapped, from the Cybershujin tracker.
/dfir/ai-threatsopen AI-assisted investigation - incident summarisation, query generation, timeline reconstruction, malware briefing, and IOC verdicts.
/dfir/ai-suiteopen OpenAPI, GraphQL, JWT, secrets, and headers - application-layer security analysis.
Lint an OpenAPI spec - missing auth, schema issues, PII exposure.
/dfir/openapi-auditopen Introspection + query depth/complexity + authz analysis.
/dfir/graphql-auditopen Decode - verify - alg-confusion check - claim analysis.
/dfir/jwtopen Third-party live HSTS/CSP/X-Frame-Options scan via IntoDNS.ai with ready-to-paste Nginx/Apache/Caddy/Cloudflare configs.
/dfir/sec-headers-liveopen Scan a text blob / repo for API keys, tokens, private keys.
/dfir/secret-scanopen AI-first security scanner - SAST (Python/JS/Go/Rust/PHP), secrets, prompt injection detection. 140+ rules, runs entirely in browser.
/dfir/medusa-scanopen Generate HTML/XHR/fetch proof-of-concept exploits for CSRF testing.
/dfir/csrf-pocopen Curated XSS payload library - filter by context, severity, or tags.
/dfir/xss-payloadsopen Compose a Google dork for a target - site:, inurl:, filetype:.
/dfir/google-dorksopen Generic log parser - pattern detection + anomaly highlighting.
/dfir/log-parseropen Conversational copilots and AI-assisted investigation workbenches - natural-language pivots.
Conversational copilot - ask in plain English, get a runbook.
/dfir/copilotopen Query 30+ intel sources in parallel - paste an IOC or entity.
/dfir/multi-searchopen Cross-chain transaction tracing, real-time flow monitoring, and quick address lookups for AML and ransomware investigations.
/dfir/crypto-traceropen Pivot explorer - graph-style pivots from any entity.
/dfir/pivexopen AI agent investigation sessions - quality scores, IOCs, and key findings.
/dfir/agent-historyopen Draft investigation reports, ingest external reports, and export IOCs to any standard format.
Analyze external reports and compose investigation reports - AI summarisation, IOC extraction, MITRE mapping, PDF/DOCX export.
/dfir/report-hubopen Export IOCs to STIX 2.1, MISP, Sigma, YARA, Snort, Suricata, CSV.
/dfir/export-hubopen Generate network blocklists (pfSense, MikroTik, Cisco) from IOCs.
/dfir/blocklistsopen Persistent notes, IOC snapshots, and findings for DFIR investigations.
/dfir/notebooksopen PGP, Tor, and dark-web workbench - the on-ramp and off-ramp tooling for sensitive investigations.
Compliance, maturity, tabletop exercises, and reference frameworks - policy and posture.
Control mapping - risk register - vendor assessment.
/dfir/grcopen Living-off-the-land binaries - search by binary or behaviour.
/dfir/lolbinsopen Tag data with sensitivity + handling requirements.
/dfir/data-classificationopen GDPR / CCPA references, DPIA templates, privacy notice generator.
/dfir/privacy-hubopen OPSEC checklist - threat-modelling for individuals.
/dfir/personal-securityopen Data-loss-prevention scan for files + clipboard + screenshots.
/dfir/dlp-scanopen Bash one-liners for live Linux incident response.
/dfir/linux-triageopen Reference frameworks, attack models, and visual matrices analysts use to structure intrusions and security programs.
Layered ATT&CK matrix - coverage heatmap, gap analysis.
/dfir/attack-navigatoropen Visualise a multi-stage attack as a connected kill-chain.
/dfir/attack-chainopen Lockheed Martin 7-phase kill chain with ATT&CK cross-links.
/dfir/kill-chainopen Adversary - capability - infrastructure - victim - reference.
/dfir/diamondopen Web 2021 - API 2023 - LLM 2025 reference + checklist.
/dfir/owaspopen Static reference view of the MITRE ATT&CK matrix with tactic/technique lookup.
/dfir/mitre-matrixopen Scenario-driven tabletop exercises - pick a scenario, run it.
/dfir/tabletopopen