Skip to content
INTCSC
Support

Cyber Security Tools

Practical tools used in real programmes — selected for usefulness, not novelty.

50 current resources

Best starting points

Highest starting-point strength resources in this category.

Abuse.ch (opens in a new tab)

Why: Abuse.ch operates free community threat-intelligence projects (malware, botnets, URLhaus and related feeds) widely used for blocking and hunting.

Evergreen hub Strong start
Last verified 6 September 2026 Open

CyberChef (opens in a new tab)

Why: The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.

Living doc Strong start
Last verified 6 September 2026 Open

GTFOBins (opens in a new tab)

Why: Unix living-off-the-land binaries companion to LOLBAS; essential for detection engineering and abuse-path review.

Evergreen hub Strong start
Last verified 6 September 2026 Open

Showing 50 resources

Abuse.ch (opens in a new tab)

Why: Abuse.ch operates free community threat-intelligence projects (malware, botnets, URLhaus and related feeds) widely used for blocking and hunting.

Evergreen hub Strong start
Last verified 6 September 2026 Open

CyberChef (opens in a new tab)

Why: The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis.

Living doc Strong start
Last verified 6 September 2026 Open

GTFOBins (opens in a new tab)

Why: Unix living-off-the-land binaries companion to LOLBAS; essential for detection engineering and abuse-path review.

Evergreen hub Strong start
Last verified 6 September 2026 Open

MITRE ATT&CK Navigator (opens in a new tab)

Why: Interactive ATT&CK layer viewer for mapping techniques to detections and coverage, helping teams visualise gaps and brief stakeholders on adversary behaviour.

Evergreen hub Strong start
Last verified 6 September 2026 Open

MITRE Caldera (opens in a new tab)

Why: Open-source automated adversary-emulation platform for running ATT&CK-mapped red-team and purple-team exercises safely in your own lab.

Evergreen hub Strong start
Last verified 6 September 2026 Open

abuseipdb (opens in a new tab)

Why: Community IP reputation database for checking whether an address has been reported for abuse before you block or investigate it.

Living doc Solid
Last verified 6 September 2026 Open

Bayse Intelligence (opens in a new tab)

Why: Scans websites and maps related attack infrastructure, helping analysts pivot from a single site to the wider hosting and threat landscape behind it.

Living doc Solid
Last verified 6 September 2026 Open

BeVigil (opens in a new tab)

Why: Mobile-app security search — find exposed endpoints, secrets and risky configurations across Android and iOS applications.

Living doc Solid
Last verified 6 September 2026 Open

Censys (opens in a new tab)

Why: Internet-wide asset search that helps teams discover exposed hosts, certificates and services on their attack surface.

Living doc Solid
Last verified 6 September 2026 Open

CRT sh (opens in a new tab)

Why: Certificate Transparency log search — enumerate domains and subdomains that have obtained TLS certificates.

Living doc Solid
Last verified 6 September 2026 Open

DeHashed (opens in a new tab)

Why: Search leaked credentials and related identity artefacts from known breaches — useful when checking exposure after phishing or account takeover.

Living doc Solid
Last verified 6 September 2026 Open

DNSDumpster (opens in a new tab)

Why: Fast DNS reconnaissance that maps hosts, records and related infrastructure for a domain during investigations and attack-surface reviews.

Living doc Solid
Last verified 6 September 2026 Open

DNSTwist.it (opens in a new tab)

Why: Generates lookalike domain variants so you can spot typosquatting and phishing infrastructure before attackers use it against your brand.

Living doc Solid
Last verified 6 September 2026 Open

ExploitDB (opens in a new tab)

Why: Curated archive of public exploits and proof-of-concept code for vulnerability research, detection writing and controlled testing.

Living doc Solid
Last verified 6 September 2026 Open

Fofa (opens in a new tab)

Why: Cyberspace search engine (FOFA) for finding exposed assets and fingerprinting services on the public internet during OSINT and attack-surface reviews.

Living doc Solid
Last verified 6 September 2026 Open

FullHunt (opens in a new tab)

Why: Attack-surface search that helps organisations discover internet-facing assets tied to their domains, supporting continuous external exposure monitoring and review.

Living doc Solid
Last verified 6 September 2026 Open

Ghidra (opens in a new tab)

Why: Open-source reverse-engineering suite (NSA-origin) for analysing binaries when dissecting malware or unknown software.

Living doc Solid
Last verified 6 September 2026 Open

GrayHatWarfare (opens in a new tab)

Why: Indexes publicly exposed cloud storage buckets so analysts can find accidental data spills and misconfigured object stores.

Living doc Solid
Last verified 6 September 2026 Open

Grep App (opens in a new tab)

Why: Code search across hundreds of thousands of public git repositories — useful for finding secrets, vulnerable patterns and reuse of known code.

Living doc Solid
Last verified 6 September 2026 Open

GreyNoise (opens in a new tab)

Why: Internet noise intelligence — tell scanner/benign mass probing apart from targeted attacks on your IPs.

Living doc Solid
Last verified 6 September 2026 Open

Hunter (opens in a new tab)

Why: Finds publicly listed email addresses tied to a domain — useful for OSINT checks and phishing-defence awareness work.

Living doc Solid
Last verified 6 September 2026 Open

Inquest Labs (opens in a new tab)

Why: Deep file-inspection laboratory for analysing suspicious samples and extracting indicators — useful when you need richer context than a quick multi-engine scan.

Living doc Solid
Last verified 6 September 2026 Open

IntelligenceX (opens in a new tab)

Why: Search engine for leaked data, dark-web content and historical internet records when investigating compromised accounts and domains.

Living doc Solid
Last verified 6 September 2026 Open

LeakIX (opens in a new tab)

Why: Search engine for publicly indexed services and leak indicators — helps find exposed databases, panels and misconfigurations on the open internet.

Living doc Solid
Last verified 6 September 2026 Open

LOLBAS Project (opens in a new tab)

Why: Living Off the Land Binaries and Scripts for Windows — essential reference for detection engineering and abuse-path reviews alongside GTFOBins.

Evergreen hub Solid
Last verified 6 September 2026 Open

Netlas (opens in a new tab)

Why: Internet-wide asset search and monitoring for hosts, services and related observables during OSINT and attack-surface work.

Living doc Solid
Last verified 6 September 2026 Open

ONYPHE (opens in a new tab)

Why: Cyber threat intelligence search across IPs, domains and related observables — a practical OSINT and enrichment source when investigating hosts and infrastructure.

Living doc Solid
Last verified 6 September 2026 Open

PimEyes (opens in a new tab)

Why: Facial recognition search — find where a face appears online (use carefully; privacy-sensitive).

Living doc Solid
Last verified 6 September 2026 Open

PolySwarm (opens in a new tab)

Why: Crowdsourced malware scanning for files and URLs, giving multi-engine verdicts useful in triage and indicator validation.

Living doc Solid
Last verified 6 September 2026 Open

PublicWWW (opens in a new tab)

Why: Source-code search across public websites to find scripts, trackers and technology fingerprints at scale — useful for OSINT, brand protection and supply-chain checks.

Living doc Solid
Last verified 6 September 2026 Open

Pulsedive (opens in a new tab)

Why: Threat intelligence search with community-scored risk context on indicators, helping analysts decide which IPs, domains and hashes deserve closer attention.

Living doc Solid
Last verified 6 September 2026 Open

SearchCode (opens in a new tab)

Why: Source-code search across millions of public projects — useful for finding leaked secrets, vulnerable patterns and library usage.

Living doc Solid
Last verified 6 September 2026 Open

SecurityTrails (opens in a new tab)

Why: Historical DNS, WHOIS and domain intelligence that helps investigators reconstruct past infrastructure and related assets during domain and host research.

Living doc Solid
Last verified 6 September 2026 Open

Shodan (opens in a new tab)

Why: Search engine for internet-connected devices and services — classic attack-surface reconnaissance.

Living doc Solid
Last verified 6 September 2026 Open

Trellix Tools and Techniques Library (opens in a new tab)

Why: Trellix Advanced Threat Research white-paper library covering laboratory techniques (function hooking, patch diffing, ICS simulation, Android SSL pinning, and related methods) for practitioners reducing attack surfaces.

Living doc Solid
Last verified 6 September 2026 Open

Uncoder.io (opens in a new tab)

Why: Converts Sigma detection rules into formats used by common SIEM and EDR platforms, speeding up detection engineering when the same logic must run across tools.

Living doc Solid
Last verified 6 September 2026 Open

URL Haus (opens in a new tab)

Why: abuse.ch malware URL blocklist publishing known-bad links for blocking, hunting and research — a trusted free feed for defenders tracking malicious URLs.

Living doc Solid
Last verified 6 September 2026 Open

URL Scan (opens in a new tab)

Why: Sandbox a suspicious URL — see page behaviour, redirects, and related indicators without opening it yourself.

Living doc Solid
Last verified 6 September 2026 Open

virustotal (opens in a new tab)

Why: Multi-engine file and URL scanner that helps analysts quickly see whether a sample or link is widely flagged as malicious.

Living doc Solid
Last verified 6 September 2026 Open

Vulners (opens in a new tab)

Why: Large vulnerability knowledge base spanning CVEs, advisories and related artefacts for prioritisation and research.

Living doc Solid
Last verified 6 September 2026 Open

Wigle (opens in a new tab)

Why: Community wireless-network map and database for locating Wi-Fi and cellular observations during physical and RF investigations.

Living doc Solid
Last verified 6 September 2026 Open

ZoomEye (opens in a new tab)

Why: Cyberspace search for hosts, services and exposures across the public internet — useful for OSINT, red-team reconnaissance and attack-surface checks. Canonical hub remapped from zoomeye.org (HTTP 521) to zoomeye.ai.

Living doc Solid
Last verified 6 September 2026 Open

← Back to full library