Security
Security
| List of tools tagged as Security |
|---|
|
.htaccess Generator
Build an Apache .htaccess draft with routing, caching, headers, and access rules plus warnings to resolve before server testing.
|
|
ACL Wildcard Mask Calculator
Calculate IPv4 ACL wildcard masks from CIDR and dotted entries, then audit generated lines for address coverage and dangerous overlaps.
|
|
ACME DNS Challenge Readiness Check
Check ACME DNS-01 readiness before retrying issuance with exact TXT matching, delegation-path validation, and public-resolver cache hints.
|
|
ACME HTTP 01 Readiness Validator
Check ACME HTTP-01 retry readiness with a weighted evidence review of the public challenge route and a clear fix-before-retry verdict.
|
|
API Key Generator
Generate cryptographically random API keys in your browser with public lookup IDs, SHA-256 verifier hashes, and issuance warnings.
|
|
Alternative DCV Checker
Check alternative certificate DCV proofs across DNS and web paths, including CSR-derived values and per-host mismatch or transport evidence.
|
|
Audit Log Anomalies Analyzer
Rank suspicious audit events from common log and CloudTrail exports using transparent signals for failures, source shifts, and privilege changes.
|
|
BGP AS Path Policy Checker
Audit pasted BGP route paths for policy conflicts and trace each pass, watch or reject verdict before changing production router filters.
|
|
BIMI Record Generator
Build a BIMI DNS TXT record for your selector and provider while checking DMARC posture, logo evidence and publication readiness.
|
|
BIMI Validation Report
Check a domain's BIMI readiness across DMARC, logo SVG and certificate evidence with live public DNS results plus prioritized fix notes.
|
|
Blacklist Checker (DNSBL/RBL)
Check a mail host or sender IP across selected DNSBLs, distinguish policy listings from resolver errors, and inspect provider evidence.
|
|
Bulk Sender Requirements Checker
Check bulk sender readiness for Gmail, Yahoo and Outlook using delivered headers plus DNS, complaint-rate and unsubscribe evidence before launch.
|
|
CAA Validation Report
Check a hostname's CAA policy through its effective DNS record set and wildcard rules, with issuer findings and public resolver evidence.
|
|
CIDR Allowlist Risk Checker
Check CIDR allowlists for risky address breadth and service exposure, then review ownership, expiry dates and overlapping rules before approval.
|
|
CORS Policy Risk Checker
Review CORS response headers for unsafe origin trust and credential use, then catch cache or private-network combinations that need priority fixes.
|
|
CSP Header Generator
Draft a Content Security Policy header with nonce, hash, or allowlist script trust plus report-only rollout checks and blocker warnings.
|
|
CSP Header Policy Checker
Check a Content-Security-Policy header for risky script sources and missing baseline directives, with reporting and rollout blockers explained.
|
|
Certificate Inventory Expiry Checker
Review a certificate inventory CSV locally to rank renewal urgency and flag ownership, manual-process, invalid-date and public-lifetime risks.
|
|
Certificate Renewal Window Calculator
Plan certificate renewal capacity across a safe pre-expiry window with retry reserve and daily load, then check spread and deadline slack.
|
|
Certificate Signing Request (CSR) Decoder
Decode a CSR in your browser, verify its self-signature and requested names, and flag key, digest, SAN, or hostname issues before submission.
|
|
Certificate Signing Request (CSR) Generator
Generate a PKCS#10 RSA CSR and matching private key in your browser, with SAN review and optional encrypted PKCS#8 key export.
|
|
Certificate Transparency Checker
Check an exact TLS certificate fingerprint against public CT data and compare hostname coverage, issuer evidence and provider revocation flags.
|
|
Cisco ACL Generator
Generate Cisco ACL commands from IPv4 flow rows for IOS, NX-OS, and ASA with platform-aware address conversion and safety checks before use.
|
|
Container Security Scan Analyzer
Normalize container scan reports, apply critical and high release limits, and rank fixable findings for a focused remediation queue.
|
|
DANE TLSA Validation Report
Validate DANE TLSA records across mail or direct TLS routes with DNSSEC evidence, record checks, and optional certificate digest comparison.
|
|
DKIM DNS Record Generator
Build a DKIM TXT record from a selector and public key with validation and DNS string splitting, plus rollout checks before publishing.
|
|
DKIM Validation Report
Check a DKIM selector in public DNS and review its record count, key strength and policy tags with clear testing and resolver evidence.
|
|
DMARC DNS Record Generator
Build a current or legacy DMARC TXT record with policy inheritance and reporting destinations plus DNS string splitting and rollout review.
|
|
DMARC Validation Report
Validate a domain's DMARC policy and check syntax, alignment and external report receivers before making stricter mail enforcement changes.
|
|
DNS Denial Proof Report
Investigate NXDOMAIN or NODATA using recursive resolver evidence plus NSEC or NSEC3 coverage, DNSSEC clues and negative-cache retry timing.
|
|
DNS Glue & Delegation Check
Check DNS glue and delegation for a public zone, compare resolver views, and identify missing NS addresses, aliases, or DS evidence.
|
|
DNS Record Enumerator
Enumerate public DNS records for a domain or IP through Cloudflare or Google, compare query coverage, and flag mail or DNSSEC gaps.
|
|
Dependency License Flags Checker
Check dependency license evidence against your release policy, interpret SPDX choices and prioritize packages that are blocked or need review.
|
|
Dependency Update Risk Analyzer
Rank dependency updates by release movement, runtime exposure, security and test evidence to plan safer review and merge lanes for your project.
|
|
Diceware Passphrase Generator
Generate a Diceware passphrase from the EFF long list with secure browser or manual dice rolls, entropy estimates and policy checks.
|
|
Dockerfile Security Basics Checker
Check a Dockerfile for risky base images, embedded secrets, broad copies, root users, package residue, and missing runtime safeguards.
|
|
Email Header Analyzer
Inspect raw email headers locally to trace relay delays and compare recorded SPF, DKIM and DMARC evidence while spotting sender mismatches.
|
|
Exchangeable Image File Format (EXIF) Viewer & Editor
Inspect EXIF metadata locally, flag location and device details, then export a stripped or selectively edited image with an auditable privacy score.
|
|
File Encryptor & Decryptor
Encrypt a local file into an authenticated .stenc envelope or recover it in your browser with AES-GCM, PBKDF2 or Argon2id, and no upload.
|
|
File Hash Generator
Hash one local file in your browser and compare its full digest with SHA-2 or SHA-3 plus required RIPEMD-160 and legacy references.
|
|
Firewall Deny Log Analyzer
Analyze firewall deny logs into ranked traffic paths using format-aware parsing, CIDR direction checks and transparent priority scores.
|
|
Firewall Rule Matrix Generator
Build a reviewable firewall rule matrix from flow rows with least-privilege findings, deterministic risk cues, and platform handoff guidance.
|
|
Firewall Rule Review Report
Review firewall rules for stale use and broad exposure while scoring expiry, ownership and privileged-service evidence into a cleanup queue.
|
|
Firewall Shadow Rule Checker
Find full and partial firewall rule shadows in ordered IPv4 policy exports, with precedence-aware evidence and safer cleanup priorities.
|
|
HMAC Generator
Generate and verify HMAC values from text or local files with exact byte encodings, SHA choices, header prefixes, and local secret handling.
|
|
HTTP Security Headers Checker
Audit pasted HTTP security headers for browser policy, session protection and exposure risks with local scoring and a prioritized fix order.
|
|
Hash Type Identifier
Identify likely hash formats from pasted values or local text files with confidence labels, cleanup clues and browser-local analysis.
|
|
Hypertext Transfer Protocol (HTTP) Header Checker
Check a public URL’s HTTP headers across redirects and review security, cache behavior, browser state and cross-origin exposure.
|
|
IAM Policy Permissions Analyzer
Review AWS IAM policy JSON for wildcard breadth, privilege paths, and policy-shape issues before validating effective access in AWS.
|
|
IAM Policy Wildcards Checker
Check AWS IAM policy JSON for wildcard permissions and broad PassRole exposure, then rank the statements that need least-privilege remediation.
|
|
Image Metadata Stripper
Strip hidden metadata from an image in your browser and create a clean JPEG, PNG, or WebP copy with a check for remaining privacy markers.
|
|
Image Region Obscurer
Obscure selected areas of a local image with pixelation, blur, or opaque covers, then flatten and review the result before sharing.
|
|
Incident Action Items Tracker
Turn incident action rows into due-state and owner follow-up views with blocker, missing-detail, stale-overdue and workload checks.
|
|
JWT Claims Risk Checker
Check JWT headers and claims against issuer, audience, time, algorithm, replay, exposure, and token-profile rules without uploading the token.
|
|
JWT Decoder
Decode a compact or Bearer JWT locally and inspect readable claims with focused checks for timing, identity, lifetime and unverified signatures.
|
|
JavaScript Obfuscator
Obfuscate JavaScript locally with repeatable profiles, runtime targets, reserved names, and size checks while keeping secrets out of source.
|
|
Kubernetes NetworkPolicy Generator
Build Kubernetes NetworkPolicy YAML from pod labels and allow rules with selector checks, rollout guidance, and security review warnings.
|
|
Kubernetes Pod Security Context Checker
Check Kubernetes workload YAML for inherited security contexts, Pod Security gaps, weighted findings, and a reviewable hardening patch.
|
|
MTA-STS Validator
Check an email domain's MTA-STS TXT and HTTPS policy, then review MX patterns and the policy-host certificate before enforcement.
|
|
NAT Pool Capacity Calculator
Size a NAT or SNAT public address pool from client sessions, planning reserve and hot-destination demand with headroom and failure checks.
|
|
Nameserver Health Check
Check a domain’s resolver-visible nameserver set and verify address coverage, SOA presence, and cross-resolver drift before a DNS cutover.
|
|
Network Audit Findings Report
Turn network audit findings into a ranked remediation register with escalation counts, due-state checks, owner gaps, and browser-local reporting.
|
|
OAuth Redirect URI Policy Checker
Compare OAuth redirect URI registrations with observed requests to find exact-match drift, unsafe schemes and wildcard or nested-redirect risk.
|
|
OpenVPN Client Config Generator
Generate an OpenVPN client profile with matched routing, TLS, cipher, and credential choices plus import and security review warnings.
|
|
PDF Metadata Editor
Edit PDF Document Info fields locally for cataloguing or privacy cleanup and verify page content plus XMP preservation before downloading.
|
|
PDF Password Workflow Planner
Plan open and owner passwords for a PDF, check effective search space, and produce a redacted handoff without uploading or encrypting the file.
|
|
PDF Protector
Protect a PDF locally with AES encryption, separate open and owner passwords, permission choices, and password checks before download.
|
|
PDF Redactor
Plan PDF redactions locally, inspect selectable text and hidden-data risks, and prepare a handoff for true removal and final-file verification.
|
|
PDF Unlocker
Unlock an authorized PDF locally with a known password, verify the rewritten copy, and keep document bytes and credentials in your browser.
|
|
PEM Bundle Extractor
Split a PEM bundle into complete certificates, requests, and keys while preserving line spans and adding SHA-256 evidence through local file handling.
|
|
Password Strength Calculator
Check a password against predictable patterns and attack scenarios, compare estimated crack times, and keep the candidate in your browser.
|
|
Port Exposure Summary Checker
Turn firewall, scanner, or cloud-rule port rows into a local exposure review that prioritizes risky public listeners and missing ownership.
|
|
Port List Checker
Normalize mixed TCP and UDP port lists into compact ranges and target strings with IANA bands, duplicate checks and service exposure cues.
|
|
Punycode IDN Converter
Convert Unicode hostnames and xn-- Punycode labels in your browser with DNS length checks, normalization choices and mixed-script warnings.
|
|
RADIUS Client Config Generator
Build FreeRADIUS client stanzas from NAS rows with device-specific secret checks, address-scope warnings, and hardened security settings.
|
|
RADIUS Request Load Calculator
Estimate RADIUS request load from access, accounting, retries, and bursts, then check per-server budgets and N-1 failover headroom.
|
|
RSA Keys Converter
Rewrap an existing RSA key for PKCS#1, PKCS#8 or SPKI consumers with optional encrypted output and local public-identity checks.
|
|
Resolver Policy Difference Comparator
Compare public DNS answers across open and filtered profiles to separate policy splits from cache or DNSSEC drift with repeatable evidence.
|
|
Reverse DNS (PTR) Checker
Check PTR records for an IP or hostname, verify forward-confirmed reverse DNS, and compare expected names or public resolver views.
|
|
S3 Bucket Policy Public Access Checker
Review an S3 bucket policy for public or cross-account grants, test trust boundaries, and prepare the live AWS checks needed before approval.
|
|
SAML Assertion Timing Checker
Check SAML assertion timing from XML or encoded captures, apply clock-skew and expiry rules, and separate bearer from replay and session evidence.
|
|
SAML Metadata Validator
Review SAML metadata XML for import blockers across roles and endpoints with local checks for certificate dates, refresh validity and signature presence.
|
|
SARIF Security Findings Analyzer
Analyze SARIF logs into a local release gate with prioritized findings plus hotspot and tracking-coverage checks for security review.
|
|
SBOM Component Risk Analyzer
Review SBOM components with a transparent risk score and separate queues for vulnerabilities, licenses, and incomplete package identity.
|
|
SMIMEA / OPENPGPKEY Lookup
Look up SMIMEA or OPENPGPKEY records for a mailbox and derive its RFC owner name with DNSSEC and resolver evidence plus cache and payload details.
|
|
SPF Record Generator
Build an SPF TXT record from real sender paths with ordered mechanisms and lookup-budget planning plus DNS packaging and rollout checks.
|
|
SPF Validation Report
Check a domain's SPF record, trace include and redirect dependencies, and flag duplicate policies or lookup-budget risks from public DNS.
|
|
SSH Algorithm Policy Checker
Check SSH algorithms from configs or scans against a chosen policy and review blockers, exceptions and a safer configuration baseline.
|
|
SSL CA Matcher
Match a TLS leaf certificate to a candidate issuer with signature verification, CA checks, expiry horizons, and policy-based review guidance.
|
|
SSL Certificate Chain Checker
Check a live TLS host or pasted PEM chain for broken issuer links, hostname and expiry problems, then build a root-aware install bundle.
|
|
SSL Checker
Check a public hostname across SSL Labs endpoints for weak protocols and trust gaps, then prioritize certificate renewal and TLS fixes.
|
|
SSL Expiry Checker
Check a live TLS listener for certificate expiry and SAN coverage, then verify renewal timing plus the served serial number and fingerprints.
|
|
SSL Matcher (Certificate, CSR, and Key)
Compare a TLS certificate with a CSR or RSA private key in your browser, using exact SHA-256 SPKI identity checks without uploading secrets.
|
|
SSL OCSP Checker
Check a public TLS host or pasted certificate for OCSP status and responder timing with freshness warnings and independent-verification evidence.
|
|
SameSite Cookie Policy Checker
Check Set-Cookie headers for SameSite delivery and find Secure or HttpOnly gaps, prefix mistakes, partitioned-cookie issues and flow breakage.
|
|
Secret Pattern Sample Checker
Scan config, log and ticket samples for secret-like values with masked findings plus provider signatures, entropy scoring and rotation guidance.
|
|
Secrets Rotation Planner
Plan a secret rotation with staged cutover timing and consumer validation, rollback gates, and a transparent risk score without entering credentials.
|
|
Secure Password Generator
Generate a unique password in your browser with adjustable character rules, unbiased random selection, and clear strength estimates.
|
|
Secure Shell (SSH) Public Key Converter
Convert SSH public keys among OpenSSH, SSH2 and PEM locally while verifying key identity through matching SHA-256 fingerprints and safety checks.
|
|
Secure Shell (SSH) Public Key Extractor
Extract a supported SSH public key locally, verify its SHA-256 fingerprint, and assemble a reviewed authorized_keys entry from key material.
|
|
Secure Sockets Layer (SSL) Certificate Converter
Convert PEM/DER/P7B/PFX certificates in your browser and inspect chain expiry plus private-key requirements before downloading.
|
|
Secure Sockets Layer (SSL) Certificate Decoder
Decode X.509 certificate text or files locally and review validity, DNS coverage and key details alongside fingerprints and chain entries.
|
|
TLS Handshake Trace
Trace a live TLS handshake to review protocol and cipher, certificate identity and trust, plus DNS-to-negotiation timing from one remote probe.
|
|
TLS-RPT Record Validator
Validate a TLS-RPT policy from live DNS or pasted text, check report destinations and RFC rules, then build a reviewable TXT record.
|
|
Text Encryptor & Decryptor
Encrypt or decrypt small text locally with AES-GCM, Argon2id or PBKDF2, portable recovery metadata, and integrity checks for safer handoffs.
|
|
Text Hash Generator
Hash exact UTF-8 text in your browser with SHA-2 or SHA-3 and verify byte counts, salt rules, and fixed-width digests before comparison.
|
|
Tie Down Strap Capacity Calculator
Plan cargo tie-down count and capacity from weight, WLL, strap path, blocking, and length rules with weak-link and margin checks.
|
|
URL Blacklist Status Lookup
Check a suspicious URL with Safe Browsing and SURBL plus weighted string clues, then review every source's scope and gaps before choosing a safer next step.
|
|
VPN Tunnel Capacity Calculator
Estimate practical VPN concurrent-user capacity from tunnel rate and packet overhead with gateway limits, busy-hour demand, and MTU risk checks.
|
|
Vulnerability Remediation SLA Calculator
Turn vulnerability backlog CSV into policy-based due dates and owner-ready remediation priorities with overdue, due-soon and compliance signals.
|
|
WireGuard Config Generator
Generate WireGuard server and client configurations with CIDR validation, route-scope warnings, and explicit placeholders for safer key handling.
|
|
iptables Rule Generator
Build bounded iptables or ip6tables commands for a packet path with explicit CIDR and port matches, persistence choices, and production-safety checks.
|
|
npm Audit Summary Analyzer
Analyze npm audit JSON or terminal output into a severity-weighted release gate and prioritized remediation queue with local processing.
|