Skip to main content
QUIETLYTIC
All tools

Cyber Security Tools for Analysts

Extract and defang indicators of compromise, score CVSS, read STIX, YARA and Sigma, and inspect certificates, keys and CSP headers, all in your browser.

Cyber Security Tools for Analysts

IOC Extractor

Pull indicators of compromise out of any block of text, log or report.

Local

IOC Defanger

Neutralise indicators so they can be shared without becoming clickable.

Local

IOC Refanger

Restore defanged indicators to their original, machine-readable form.

Local

IOC Deduplicator

Collapse a messy indicator list down to its unique entries.

Local

IOC Normalizer

Standardise a mixed indicator list into one consistent format.

Local

Security Headers Analyzer

Review a set of pasted HTTP response headers against current guidance.

Local

CSP Analyzer

Break a Content-Security-Policy into its directives and flag the weak ones.

Local

CORS Analyzer

Check a set of CORS response headers for the combinations that undo them.

Local

STIX Viewer

Read a STIX 2.1 bundle as structured objects instead of raw JSON.

Local

STIX Validator

Check a STIX 2.1 bundle for structural and required-property errors.

Local

STIX Bundle Explorer

Trace the relationship graph inside a STIX bundle object by object.

Local

YARA Syntax Viewer

Break a YARA rule into its meta, strings and condition sections.

Local

YARA Rule Formatter

Reformat a YARA rule to consistent indentation and section order.

Local

Sigma Syntax Viewer

Read a Sigma detection rule as structured logsource and detection blocks.

Local

Sigma Rule Formatter

Reorder a Sigma rule’s top-level keys to the conventional sequence.

Local

ATT&CK Technique Lookup

Find a MITRE ATT&CK technique by ID or name from a bundled dataset.

Local

Hash Identifier

Narrow an unlabelled hash down to the algorithms that could have produced it.

Local

CVSS Calculator

Build or decode a CVSS v3.1 vector and see which metric drives the score.

Local

User-Agent Parser

Read a User-Agent string, with the token behind every claim and the spoofing tells named.

Local

SRI Hash Generator

Paste a script or stylesheet, get its sha256/sha384/sha512 integrity attribute.

Local

CSP Generator

Build a Content-Security-Policy header directive by directive, not by editing a string.

Local

Permissions-Policy Builder

Turn on, off or origin-scope a browser feature per directive, then copy the header.

Local

X.509 Certificate Decoder

Paste a PEM certificate to read its subject, issuer, validity, key and extensions.

Local

CSR Decoder

Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.

Local

Certificate Fingerprint Calculator

Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.

Local

SSH Public Key Inspector

Paste an OpenSSH public key line to read its type, size and SHA256 fingerprint.

Local

Secret Pattern Detector

Scan pasted text or code for the shape of a leaked API key, token or private key.

Local

Password Entropy Checker

A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.

Local