Analysis toolkit. CVSS v3.1 and v4.0 calculators, DGA domain scorer, multi-platform threat hunt query builder, email phishing header analyzer, CSP analyzer with bypass techniques, and HTTP security headers analyzer with attack vectors.
8 clickable metrics (AV/AC/PR/UI/S/C/I/A), exact CVSS 3.1 formula, live score 0-10, severity badge, copyable vector string.
11 base metrics (AV/AC/AT/PR/UI/VC/VI/VA/SC/SI/SA), Threat (E), Environmental (CR/IR/AR + 11 Modified overrides). MacroVector lookup with interpolation per FIRST spec. Tabs for Base/Threat/Environmental. CVSS-B/BT/BE/BTE nomenclature. Copyable vector string.
Shannon entropy, consonant ratio, English n-gram score, digit ratio, suspect TLD - 7 metrics to estimate the probability that a domain is DGA-generated.
Select a TTP (encoded PowerShell, Kerberoasting, LSASS dump, scheduled task persistence...) and get hunt queries for Splunk SPL, Elastic KQL, Microsoft Sentinel KQL, and Sigma simultaneously.
Paste raw email headers -> analyzes SPF/DKIM/DMARC alignment, display name spoofing, Reply-To mismatch, urgency keywords, X-Mailer fingerprint. Score 0-100, verdict: Likely Phishing / Suspicious / Legitimate.
Paste a Content-Security-Policy header -> analyzes each directive, grades A-F, identifies weaknesses (unsafe-inline, JSONP, wildcard) and suggests concrete bypass payloads.
Paste HTTP response headers -> analyzes HSTS, CSP, X-Frame-Options, CORS, COOP, Referrer-Policy... Overall grade A-F, lists missing critical headers and information disclosure headers.