Security research
Handy web tools I reach for when researching a target's security posture: TLS and header checks, DNS and certificate recon, and IP intelligence.
These are third-party sites (linked, not affiliated). Only use them against domains, IPs, and systems you own or are authorised to test.
Web & TLS
- Security Headers
Scans a website's HTTP security response headers (CSP, HSTS, X-Frame-Options, and more) and gives it a letter grade with fixes.
- Qualys SSL Labs
The definitive deep test of a site's SSL/TLS configuration: protocols, ciphers, certificate chain, and known weaknesses, with an A-to-F grade.
- Mozilla Observatory
Scans a site's security posture (headers, TLS, and cookies) and returns a letter grade with prioritised fixes. A strong companion to Security Headers and SSL Labs.
- Hardenize
An all-in-one posture report covering TLS, DNS, email, and HTTP headers for a domain on a single page.
- ImmuniWeb SSL Security Test
A free, in-depth TLS/SSL test that also flags PCI DSS and HIPAA compliance gaps in the configuration.
DNS, domains & certificates
- MXToolbox
MX, DNS, blacklist, and email-deliverability (SPF/DKIM/DMARC) lookups in one place. A daily-driver for email and DNS troubleshooting.
- DNSDumpster
DNS recon and subdomain discovery with a visual network map. Great for mapping a domain's public footprint.
- crt.sh (Certificate Transparency)
Searches Certificate Transparency logs. A quick way to enumerate subdomains from certificates that have been issued for a domain.
- ICANN Lookup (WHOIS)
Official WHOIS registration details for a domain: registrar, registration and expiry dates, and name servers.
- Who.is
A fast, free WHOIS lookup that returns a domain's registration, registrar, name servers, and DNS records in one clean view.
- Whois.com
WHOIS lookups with registrar, registration and expiry details, plus domain availability. A useful second source when another WHOIS lookup is rate-limited or sparse.
- NZ Domain Name Commission
WHOIS and registration information for .nz domains (the New Zealand registry).
- SecurityTrails
Historical DNS and WHOIS data plus subdomain discovery. Excellent for mapping a domain's past and present footprint.
- Hurricane Electric BGP Toolkit
A powerful free multi-tool for ASN, IP, BGP, and DNS lookups, and for seeing how networks connect to each other.
- DNSViz
Visualises and troubleshoots a domain's DNSSEC chain, making broken or misconfigured signing easy to spot.
- ViewDNS.info
A broad suite of free DNS and IP tools in one place: reverse IP, DNS records, WHOIS history, port testing, and more.
- DNSChecker
Checks DNS record propagation from servers around the world.
- Robtex
Deep DNS and network research: records, related domains, and hosting relationships.
Recon & subdomains
- SpiderFoot
Automates OSINT collection across hundreds of sources to map a target's footprint.
- theHarvester
Gathers emails, subdomains, hosts, and names for a domain from public sources.
- Subfinder
A fast passive subdomain enumeration tool from ProjectDiscovery.
- Recon-ng
A modular reconnaissance framework with a Metasploit-like workflow.
Attack surface & internet search
- ZoomEye
A search engine for internet-exposed devices and services, similar to Shodan.
- FOFA
An internet asset search engine for discovering exposed hosts, services, and technologies.
- Onyphe
A cyber-defence search engine that indexes internet-facing assets and threat data.
- Netlas.io
Search and monitor internet-connected hosts, certificates, and attack surface.
- FullHunt
Discovers and monitors a company's external attack surface and exposed assets.
- GrayHatWarfare
Searches publicly exposed cloud storage buckets and files. Useful for spotting data leaks.
IP & host reconnaissance
- Shodan
The search engine for internet-connected devices: exposed ports, running services, and banners for an IP, host, or organisation.
- AbuseIPDB
Check an IP address's abuse history and reputation, useful for triaging suspicious sources in logs.
- HackerTarget Reverse IP
Find other domains hosted on the same IP address. Handy for shared-hosting and footprint mapping. Also offers a free API.
- Censys
Internet-wide search of hosts and certificates. The natural companion to Shodan for finding exposed services and assets.
- GreyNoise
Tells you whether an IP is mass-scanning the whole internet (background noise) or targeting you specifically. Invaluable for triaging log sources.
- IPinfo
Clean, accurate IP geolocation, ASN, and hosting-provider details for any address.
- IPVoid
Checks an IP address against blacklists and reputation sources.
Vulnerabilities & exploits
- Exploit-DB
A searchable archive of public exploits and proof-of-concept code.
- NVD
The official US National Vulnerability Database: CVE details, severity scores, and affected products.
- CVE Details
Browse and pivot CVEs by vendor, product, and year, with statistics and trends.
- CISA KEV
CISA's catalogue of vulnerabilities known to be actively exploited in the wild. Patch these first.
- Vulners
A vulnerability search engine aggregating CVEs, exploits, and advisories from many sources.
- Sploitus
A fast search engine for exploits and proof-of-concept code across public sources.
- GTFOBins
A curated list of Unix binaries that can be abused to bypass local security restrictions.
- LOLBAS
The Windows equivalent of GTFOBins: living-off-the-land binaries, scripts, and libraries.
- MITRE ATT&CK
The reference framework of real-world adversary tactics and techniques.
Web app & network testing
- Burp Suite
The industry-standard web application testing proxy. The free Community edition covers the basics.
- OWASP ZAP
A free, open-source web application vulnerability scanner and testing proxy.
- Nuclei
A fast, template-driven vulnerability scanner from ProjectDiscovery.
- Nikto
An open-source web server scanner that checks for thousands of known issues.
- sqlmap
Automates the detection and exploitation of SQL injection flaws.
- ffuf
A fast web fuzzer for content discovery, parameter fuzzing, and virtual-host brute forcing.
- Wappalyzer
Identifies the technologies, frameworks, and services a website runs on.
- WhatWeb
Fingerprints websites to reveal their technologies, servers, and versions.
- BuiltWith
Profiles a site's full technology stack, from analytics to hosting.
- Nmap
The definitive network scanner for host discovery, port scanning, and service detection.
- Wireshark
The standard tool for capturing and analysing network traffic packet by packet.
Malware analysis & sandboxes
- Any.run
An interactive online sandbox for detonating and observing malware in real time.
- Hybrid Analysis
A free automated malware sandbox with detailed behavioural reports.
- Triage
A fast, free malware analysis sandbox from Recorded Future.
- Joe Sandbox
Deep, detailed malware analysis across Windows, macOS, Linux, Android, and iOS.
- Intezer
Analyses files by genetic code reuse to attribute and classify malware.
- MalwareBazaar
A community repository of malware samples for research, run by abuse.ch.
Encoding, crypto & hashes
- CyberChef
GCHQ's 'cyber swiss-army knife' for encoding, decoding, encryption, and data analysis in the browser.
- dCode
A huge collection of tools for ciphers, encodings, and puzzle solving.
- CrackStation
Looks up unsalted password hashes against a massive precomputed table.
- Hashes.com
Identifies hash types and attempts to crack them via a distributed service.
Reputation & threat intel
- VirusTotal
Checks a file, URL, domain, or IP against dozens of antivirus engines and threat feeds. The essential first stop for reputation.
- URLScan.io
Safely sandbox-scans a URL and shows what it loads, the requests it makes, a screenshot, and a verdict. Ideal for investigating a suspicious link.
- Cisco Talos Intelligence
Reputation for an IP, domain, or email sender, backed by one of the largest threat-telemetry networks.
- abuse.ch
Community-run malware and indicator feeds (URLhaus, ThreatFox, and MalwareBazaar) for tracking active threats and IOCs.
- AlienVault OTX
An open threat-intelligence community sharing indicators of compromise.
- Pulsedive
Searches and enriches threat indicators (IPs, domains, URLs) with risk scoring.
- IBM X-Force Exchange
IBM's threat-intelligence platform for researching IPs, domains, malware, and vulnerabilities.
- ThreatMiner
Pivots across threat-intel indicators to enrich an investigation.
- SANS Internet Storm Center
Daily threat analysis and handy lookup tools from the SANS community.
- Mitaka
A browser extension that one-click looks up selected IOCs (IPs, domains, hashes, URLs, CVEs) across dozens of search and threat-intel engines.
Email & breach OSINT
- Have I Been Pwned
Check whether an email address or password has appeared in a known data breach, and subscribe to be alerted if it happens again.
- Hunter.io
Finds the email-address format and known addresses for a domain. Useful for understanding an organisation's email footprint.
Web archives & code search
- Wayback Machine
The Internet Archive's snapshot history of web pages over time.
- archive.today
Captures an on-demand, permanent snapshot of a specific web page.
- PublicWWW
Searches the web by page source code, useful for finding sites sharing a snippet, tag, or tracker.
- grep.app
Searches code across public Git repositories in an instant.
Reference & bigger lists
- OSINT Framework
A browsable directory that maps OSINT tools to what you are trying to find.
- CyberSources
A large community-curated collection of cybersecurity tools and learning resources.