Twenty-six tools, no signup required to try most of them.
Checklists, calculators, generators, live feeds and simulations — built by practitioners across SOC, GRC, pen testing, and DFIR. Most run instantly with no signup.
Ransomware Readiness Checklist
10 questions on backups, segmentation and response — score plus a downloadable PDF gap list.
Start checklist →Cyber Insurance Readiness Checker
The controls insurers actually look for — MFA, backups, EDR — scored against typical underwriting questions.
Start checklist →DPDP Act Quick-Check
A fast gut-check on how your personal-data handling stacks up against India's DPDP Act, 2023.
Start checklist →MFA & Access Control Self-Assessment
Eight questions on MFA coverage, privileged access and access reviews — identity-focused.
Start checklist →SOC-CMM Maturity Assessment
Our flagship 15-question, 5-domain assessment with instant gauge scoring.
Start assessment →Industry Maturity Benchmark
Already have a SOC-CMM score? See how it compares to illustrative ranges for your industry.
Compare your score →CERT-In Reporting Deadline Calculator
Enter your detection time, get the exact six-hour cutoff and a who-to-call checklist.
Calculate deadline →Data Breach Cost Estimator
Industry and record count in, a rough breach-cost range out — useful for budget conversations.
Estimate cost →SOC Staffing Calculator
Alert volume and coverage hours in, an estimated analyst headcount for 24x7 coverage out.
Calculate staffing →Vendor Risk Questionnaire Generator
Pick your industry, get a tailored third-party security questionnaire to send to vendors.
Build questionnaire →IR Contact Tree Builder
Fill in your roles and names, get a printable escalation tree for the wall.
Build contact tree →Security Policy Pack Generator
Pick which policies you need, get downloadable starter outlines for each.
Build policy pack →Tabletop Exercise Scenario Picker
Choose your top concern, get a free scenario script to run with your IR team.
Pick a scenario →Phishing Email Simulator
A realistic inbox view — click the parts of the email that gave the scam away.
Try the demo →Spot the Fake Login Page
Find the tells on a spoofed login page before you'd ever type a password.
Try the demo →Vishing Call Simulator
A simulated "IT support" call — pick your responses and see what gave the scam away.
Try the demo →Email Spoofing Risk Checker
SPF, DKIM and DMARC analyzed instantly — see how easy it'd be to spoof email from your domain.
Check your domain →Typosquat & Lookalike Domain Detector
Generates likely typosquat variants of your domain and checks which are actually registered.
Check for lookalikes →Domain Age Checker
See exactly when any domain was registered — a brand-new domain is a classic scam signal.
Check domain age →CISA Known Exploited Vulnerabilities
Vulnerabilities actively being exploited right now — refreshed from CISA's public catalog.
View live feed →Live Phishing Domain Watcher
Watches Certificate Transparency logs in real time for newly-issued lookalike-brand certs.
View live feed →Global Threat Activity Map
Real, recently-reported malicious IPs, geolocated and visualised — refreshed hourly.
View map →Email Header Analyzer
Paste raw headers, get SPF/DKIM/DMARC results and the server hop path — parsed in your browser.
Analyze headers →Dependency Vulnerability Checker
Paste your package.json or requirements.txt, checked against Google's free OSV.dev database.
Check dependencies →Port & Protocol Reference
Searchable reference of common ports, what runs on them, and why each one matters.
Search ports →What This Website Already Knows About You
Live browser exposure demo — see your own fingerprint surface the instant you load the page.
See your exposure →Build the Kill Chain
Drag the stages of a cyber attack into the correct order — a quick game, not just a quiz.
Play now →Operation Foothold — Mini CTF
A real three-clue capture-the-flag challenge hidden in page source, HTTP headers, and cookies.
Start the challenge →Missing a tool you'd find useful?
Everything here is free and built by practitioners. If there's a gap, let us know.