Skip to main content
Skip to main content
DFIR
Privacy-first · No upload · No login · Local analysis only

DFIR & security toolkit

Scanners, decoders, forensic parsers, lookups and frameworks that run entirely in your browser. Sub-200ms IOC checks across 22 sources, no signup, no key.

122 tools · by Pranith Jain · about · live feeds: /threatintel
Toolkit · 100% client-side

122 tools · client-side · build 2026-06-13

Searches 122 tools by name, path, description, and use-case. ↑↓ to navigate, Enter to open.

Start here

Three picks, one prescribed sequence. Skip the grid below if any of these match what's on your screen right now.

  1. 01ioc-check

    You have one suspicious indicator (IP, domain, URL, or hash).

    Paste it. 24 providers in parallel, cross-source consensus in under a second.

    open
  2. 02detection-lab

    You write or evaluate detection rules.

    Author against a curated event corpus, see fires in seconds, then export through the Rule Converter to Sigma, KQL, SPL, EQL, Lucene, or YARA.

    open
  3. 03cve-prioritizer

    You have a CVE ID and a stakeholder asking how worried to be.

    Get a verdict that combines CVSS, EPSS, CISA KEV, and ransomware-use signals into a single patch-priority call.

    open

Pick a workbench

recent lookups
Used in real cases (4)
Utilities & converters (6). Encoders, hashes, timestamps

These are duplicative of well-known online tools (CyberChef, epochconverter, etc.) — kept here for offline / client-side analysis when you can't send data outside your environment. Not where the toolkit's depth is.

Data Sources
Commercial (key required)
VirusTotalAbuseIPDBShodanOTXURLScanHybrid Analysis
abuse.ch (one shared free key)
ThreatFoxURLhausMalwareBazaar
Public lists & DoH (no signup)
SpamhausTor ExitOpenPhishPhishStatsCINS ArmyCIRCL HashlookupCloudflare DoHQuad9BitwireBlocklist.deBinary DefenseIpsumPhishing ArmyTweetFeedcrt.shRDAP
edge·
github·portfolio