Analysis Toolkit

Analysis toolkit. CVSS v3.1 and v4.0 calculators, DGA domain scorer, multi-platform threat hunt query builder, email phishing header analyzer, CSP analyzer with bypass techniques, and HTTP security headers analyzer with attack vectors.

#Vulnerability Scoring

#CVSS v3.1 Calculator

8 clickable metrics (AV/AC/PR/UI/S/C/I/A), exact CVSS 3.1 formula, live score 0-10, severity badge, copyable vector string.

CVSS v3.1 Calculator

-.-
Not Scored
--
Range Severity Color
0.0NoneGrey
0.1 - 3.9LowGreen
4.0 - 6.9MediumYellow
7.0 - 8.9HighOrange
9.0 - 10.0CriticalRed

#CVSS v4.0 Calculator

11 base metrics (AV/AC/AT/PR/UI/VC/VI/VA/SC/SI/SA), Threat (E), Environmental (CR/IR/AR + 11 Modified overrides). MacroVector lookup with interpolation per FIRST spec. Tabs for Base/Threat/Environmental. CVSS-B/BT/BE/BTE nomenclature. Copyable vector string.

CVSS v4.0 Calculator

-.-
Not Scored
--
Range Severity Color
0.0NoneGrey
0.1 - 3.9LowGreen
4.0 - 6.9MediumYellow
7.0 - 8.9HighOrange
9.0 - 10.0CriticalRed

#Threat Intelligence

#DGA Domain Scorer

Shannon entropy, consonant ratio, English n-gram score, digit ratio, suspect TLD - 7 metrics to estimate the probability that a domain is DGA-generated.

DGA Domain Scorer

Analyzes a domain name across 7 statistical metrics to estimate the probability it was generated by a Domain Generation Algorithm. Each metric flags independently; the more flags triggered, the higher the DGA likelihood.

Legit:
DGA:

#Threat Hunting

#Multi-Platform Threat Hunt Query Builder

Select a TTP (encoded PowerShell, Kerberoasting, LSASS dump, scheduled task persistence...) and get hunt queries for Splunk SPL, Elastic KQL, Microsoft Sentinel KQL, and Sigma simultaneously.

Multi-Platform Threat Hunt Query Builder

Splunk SPL

#Email Analysis

#Phishing Header Analyzer

Paste raw email headers -> analyzes SPF/DKIM/DMARC alignment, display name spoofing, Reply-To mismatch, urgency keywords, X-Mailer fingerprint. Score 0-100, verdict: Likely Phishing / Suspicious / Legitimate.

Email Phishing Header Analyzer

Paste raw email headers to get a phishing verdict. No data leaves your browser.

#Web Security Analysis

#CSP Analyzer & Bypass Suggester

Paste a Content-Security-Policy header -> analyzes each directive, grades A-F, identifies weaknesses (unsafe-inline, JSONP, wildcard) and suggests concrete bypass payloads.

CSP Header Analyzer

#HTTP Security Headers Analyzer

Paste HTTP response headers -> analyzes HSTS, CSP, X-Frame-Options, CORS, COOP, Referrer-Policy... Overall grade A-F, lists missing critical headers and information disclosure headers.

HTTP Security Headers Analyzer

#Also See

#Cyber Aurelien Guidi