Live

CRITICAL: Zero-day exploit in Apache Log4j — Active exploitation worldwide

Analyst Toolkit

Cyber Tools

Scan URLs and domains for malicious indicators instantly — and explore a curated toolkit of industry-standard platforms used by cybersecurity and threat intelligence analysts worldwide.

URL Intelligence Scanner

Check any URL, domain, or IP for malicious indicators using live threat feeds

Analyst Toolkit

Essential Tools for Analysts

Industry-standard platforms for OSINT research, threat intelligence, malware analysis, network forensics, and vulnerability management.

Shodan
OSINT

Search engine for internet-connected devices. Discover exposed ports, services, and vulnerabilities across any IP or domain.

Maltego
OSINT

Visual link analysis platform for mapping relationships between domains, IPs, people, and organizations.

OSINT Framework
OSINT

Comprehensive directory of OSINT tools and techniques organized by intelligence category.

SpiderFoot
OSINT

Automated OSINT reconnaissance tool covering 200+ data sources for IP, domain, email, and name lookups.

VirusTotal
Threat Intel

Analyze suspicious files, URLs, domains, and IPs using 70+ antivirus engines and threat intelligence feeds.

AbuseIPDB
Threat Intel

Community-driven database of malicious IPs. Report and query IPs involved in hacking, spam, and DDoS.

AlienVault OTX
Threat Intel

Open Threat Exchange — the world's largest open threat intelligence community with 20M+ IoCs.

MXToolbox
Threat Intel

DNS/MX lookup, blacklist checks, email header analysis, and network diagnostics in one platform.

URLScan.io
Threat Intel

Website scanner that captures screenshots, DOM structure, and network requests to detect malicious content.

ThreatFox
Threat Intel

Free platform from abuse.ch to share malware IoCs (indicators of compromise) — IPs, domains, URLs, hashes.

ANY.RUN
Malware Analysis

Interactive online malware sandbox — analyze suspicious executables and URLs in a live Windows/Linux VM.

Hybrid Analysis
Malware Analysis

Free malware analysis service using CrowdStrike Falcon Sandbox. Submit files or URLs for deep behavioral analysis.

Joe Sandbox
Malware Analysis

Deep malware analysis platform supporting Windows, macOS, Linux, Android, and iOS samples.

Cuckoo Sandbox
Malware Analysis

Open-source automated malware analysis system — deploy locally or use cloud versions for file detonation.

Wireshark
Network & Forensics

Industry-standard network protocol analyzer for capturing and inspecting packet-level traffic in real time.

Censys
Network & Forensics

Internet-wide scan data for IPv4, certificates, and ASNs. Essential for attack surface mapping.

DNSDumpster
Network & Forensics

Free domain research tool that discovers hosts related to a domain including DNS records and subdomains.

NVD (NIST)
CVE & Exploit DB

US National Vulnerability Database — authoritative CVE data with CVSS scores, patch info, and references.

Exploit-DB
CVE & Exploit DB

Archive of public exploits and vulnerable software — maintained by Offensive Security (OffSec).

MITRE ATT&CK
CVE & Exploit DB

Globally-accessible knowledge base of adversary tactics and techniques based on real-world observations.

Cookie and Data Preferences

We use cookies for security, analytics, and your preferences. See our Privacy Policy for details.