The toolkit

Everything a defender needs. One console.

A professional-grade toolkit organized into four areas — discover, investigate, operate and report — all passive, read-only and mostly offline.

🌐 Network

Discover & watch your network

🛰

Live discovery & inventory

Every device, service and open port on your network — mapped and monitored passively, in real time.

📊

Device risk scoring

Each host profiled and ranked, with OS/vendor fingerprinting and alerts on fingerprint drift or spoofing.

🌐

DNS live & dashboard

Real-time DNS and browsing visibility, with an optional built-in local DNS server for blocking and insight.

🧬

Passive capture & PCAP

Passive browsing capture and full offline PCAP / packet analysis — no active probing required.

📡

Top talkers + geo

The busiest hosts on the wire and exactly where their outbound traffic is going.

🔒

TLS & DNS hygiene

Per-device TLS/JA4 fingerprints and encrypted-DNS posture, so weak or rogue crypto stands out.

🛡 Threats & Defense

Detect, investigate, defend

🎯

Threat Picture

One ranked, unified view of every device, service and anomaly — so you know what matters in seconds.

🔬

Investigation console

Paste any IP, domain, hash, URL, email or certificate → one combined case with a verdict and pivots.

🦠

Malware triage

Static PE/DLL analysis, macro & document inspection, YARA matching and multi-layer deobfuscation.

🧾

Forensics toolbox

Email, file and link investigators, EXIF/metadata, JWT and X.509 certificate inspectors — mostly offline.

🌍

OSINT suite

WHOIS, breach checks, reputation, email & phone intelligence and username footprint in one place.

🛡

Live defenses

MITM, ARP and rogue-DHCP guards plus endpoint hardening checks — all strictly read-only.

🎯 SOC & Cyber Ops

Run operations like a SOC

🚨

SOC console

A live alert and case queue for the whole environment, with acknowledge/triage workflow.

🕵

Threat hunting

Prebuilt hunting hypotheses, beaconing/C2 detection and lateral-movement analysis.

🗺

Live maps & ATT&CK

Global threat map, a live MITRE ATT&CK heatmap and attack-path (link-analysis) graphs.

Incident replay

A visual timeline that replays an incident end to end for review and handover.

📈

Exposure intelligence

Your external attack surface and an internet-exposure scorecard, prioritized by risk.

Playbooks & SOAR-lite

Incident-response runbooks and rule-driven, passive automation — actions stay safe.

📊 Reporting & Governance

Prove it to the board

🏛

CISO executive briefing

A board-ready posture report — overall score, top business risks and a prioritized action plan.

🎓

Executive scorecard

One graded number for leadership, tracked over time so progress is obvious.

Compliance mapping

CIS Controls · NIST CSF · ISO 27001 mapping generated straight from your findings.

📄

Client-ready reports

Branded, PDF-ready reports for clients and MSSP engagements — no copy-paste.

🔗

SIEM export & alerting

Export as CEF / JSON / syslog and push alerts to Slack, Teams, webhook or email.

💰

Risk quantification

FAIR-based dollar exposure and third-party (vendor) risk tiering for real decisions.

Unlock the full toolkit with Pro.

Start a 14-day free trial and get every tool instantly — no card required.