Built for Indian Security Professionals

Stop Adapting.
Tools Built for
Indian Threats.

Every regulation, every attacker group, every compliance deadline — mapped to Indian context. CERT-In, RBI, SEBI, DPDP Act. Not converted from a US framework.

CERT-In Directions 2022 RBI IT Framework SEBI CSCRF 2024 DPDP Act 2023 IRDAI ISRM 2023
KQL — Kerberoasting Detection
// CERT-In: Targeted scanning / intrusion attempt // MITRE T1558.003 • APT: Sidewinder • APT36 • Lazarus SecurityEvent | where EventID == 4769 | where TicketEncryptionType == "0x17" | where ServiceName !endswith "$" | summarize count() by SubjectUserName, IpAddress, bin(TimeGenerated, 10m) | where count_ >= 3 | order by count_ desc ⚠ 100+ use cases like this in the Detection Library
Tools by role

Find what you need, instantly.

Every tool was built around how Indian security practitioners actually work — not adapted from a US framework.

S

SOC Analyst

Detection engineering, alert triage, SIEM tuning, and threat hunting mapped to Indian regulatory requirements.

SIEM Use Case Library › KQL / SPL Translator › Threat Hunting Library › + more tools in this section
R

Red Team / Pen Tester

Active directory attacks, C2 frameworks, payload obfuscation, web app attacks, and India-context assume-breach scenarios.

Active Directory Attacks › C2 Framework Reference › Web App Attack Reference › + more tools in this section
G

GRC / Compliance

CERT-In, RBI, SEBI CSCRF, DPDP Act, and IRDAI compliance tools built for Indian regulators, not US or EU frameworks.

SEBI CSCRF 2024 › CERT-In Directions 2022 › RBI Cloud Guidelines › + more tools in this section
C

Cloud Security

AWS, Azure, and GCP security covering IAM privilege escalation, misconfigurations, native detection, and India data localisation.

IAM Privilege Escalation › Cloud Pentest Checklist › Shared Responsibility Matrix › + more tools in this section
D

DFIR Specialist

Windows forensics, evidence collection, incident timeline reconstruction, malware triage, and artifact location references.

Windows Event ID Reference › Malware Triage Checklist › Incident Timeline Reconstructor › + more tools in this section
A

AI / ML Security

LLM security, prompt injection defense, MITRE ATLAS mapping, MLSecOps maturity, and AI governance frameworks.

Prompt Injection Defense › MITRE ATLAS Mapper › MLSecOps Maturity Assessment › + more tools in this section

Built for the Indian regulatory reality.

The compliance burden on Indian security teams is distinct from every other country. Six-hour CERT-In reporting. RBI data localisation. SEBI CSCRF. DPDP Act breach obligations. IRDAI insurance data rules. Every tool here is built around these — not retrofitted from GDPR or HIPAA.

Why Cyber Guard Forte

What makes this different.

🇮🇳
India-first, not India-adapted

Every tool is built around Indian regulation and Indian threat actors — not converted from a US or EU framework after the fact.

Practitioner-built

Built by security practitioners for the daily reality of Indian SOC analysts, pen testers, and GRC teams — not by a marketing team generating leads.

🔓
Zero paywalls, zero accounts

Every tool works the moment you open it. No trial period, no credit card, no account required.

🔴
Offensive and defensive together

From red team scenarios to SIEM detection rules to GRC checklists — practitioners who do both do not need to switch platforms.

Cloud built for Indian compliance

Cloud tools account for RBI payment data mandate, SEBI primary DC rules, and DPDP cross-border provisions. Not generic AWS guides.

🤖
AI-powered, no setup required

AI log analysis, phishing detection, and CERT-In report drafting — ready to use without connecting your own API key.

Context

The gap this site was built to close.

Indian cybersecurity teams operate under one of the world's most demanding and most India-specific regulatory environments. CERT-In Directions 2022 impose a six-hour incident reporting window with no equivalent in US or EU frameworks. RBI mandates that payment system data be stored only in India — a requirement that changes how every cloud architecture decision gets made. SEBI CSCRF 2024 imposes specific capability requirements on brokers, AMCs, and market infrastructure institutions. DPDP Act 2023 changes cross-border data transfer rules in ways that do not map neatly to GDPR.

The threat landscape is equally distinct. Sidewinder, APT36, SideCopy, and Lazarus Group specifically target Indian government, defence, financial, and critical infrastructure in ways that generic global threat intelligence rarely reflects. A SIEM use case tuned for US financial services is not tuned for an Indian bank facing Lazarus-style SWIFT attacks or an AIIMS-scale ransomware deployment.

Cyber Guard Forte was built to close this gap — with tools that speak the right regulatory language and reference the right attackers from the first page. A solo GRC consultant, a two-person SOC at a regional bank, and a large enterprise red team should all have access to the same quality of tools regardless of budget. That is why everything here is free.

Common questions

Frequently asked.

Are all the tools free?

Yes — every tool works without a subscription, account, or credit card. A handful of AI-powered tools make API calls handled server-side at no cost to you. The site is supported by advertising.

What is the CERT-In six-hour reporting requirement?

Under CERT-In Directions 2022, any organisation operating in India must report specified cyber incidents within six hours of becoming aware — not after confirming or fully investigating. The CERT-In Deadline Calculator on this site computes the exact deadline from a detection timestamp.

Which SIEM platforms are supported?

Microsoft Sentinel (KQL), Splunk (SPL), IBM QRadar (AQL), and Elastic/OpenSearch (EQL). The query translator converts between all four. Most detection use cases include both KQL and SPL versions.

Are the red team tools safe to use?

All red team content is documentation, not executables. The AD attack reference, C2 framework reference, and web app attack tools contain commands and guidance — they require you to run tools in your own authorised environment. Nothing executes in the browser.

Who built this and why?

Cyber Guard Forte was built by a security practitioner who spent years watching Indian teams use tools designed for the wrong regulatory context and the wrong threat landscape. It is maintained independently and supported by advertising — no vendor, no VC, no sales motion.

The toolkit built for your reality.
Not someone else’s framework.

Every tool. Always free. Built for Indian security practitioners, by someone who spent years being one.