SOC status:Duty analyst on shift

UK Cyber Defence

Tools · Free to use · No sign-up

Tools we use, published for anyone.

The SOC built these for its own analysts. They run on our servers, they cost nothing to use, and nothing on this page asks for an email address. If one of them tells you something you did not expect, that is what they are for.

VulnerabilitiesCVE ExplorerWhich vulnerabilities actually matter?Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA, with a plain-English verdict on whether it needs an emergency change or the normal patch cycle.390,000+ CVEsCVSS · EPSS · KEV · EPSS trendThis week · KEV calendarOpen CVE ExplorerYour products onlyCVE WatchlistOnly the CVEs that are yours.Enter the products you run, or paste a software inventory, and get a page of new CVEs, CISA KEV additions and EPSS jumps for just those, with an RSS feed and an optional daily or weekly email digest. The link is shareable with the team; there is no account.Inventory pastePage · RSS · Email digestKEV additions firstOpen CVE WatchlistExposureDNS AuditWhat does your DNS tell a stranger?Enter a domain and get a report on weak, insecure and leaking records: RFC 1918 addresses in public DNS, open zone transfers, SPF, DKIM and DMARC, CAA, DNSSEC, dangling CNAMEs, Active Directory service records and the host names an attacker would try first.A · CNAME · CAA · MX · NS · TXT · SRV · HTTPSRead-onlyPDF reportOpen DNS AuditSpoofingEmail SecurityCan someone send email as you?SPF, DKIM and DMARC read together, with the SPF include tree and lookup count, DKIM key sizes under seventy selectors or your own, the DMARC policy and its reporting, MTA-STS, TLS-RPT and DANE behind them — and for every gap, the exact record to publish next, matched to your mail provider.SPF · DKIM · DMARC · MTA-STS · TLS-RPT · DANERecommended recordsPDF reportOpen Email SecurityBrowser protectionsSecurity HeadersIs your site telling browsers to protect its visitors?The A+ to F grade for HTTP security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy, plus cookie flags, CSP quality, cross-origin isolation, and the headers that give away your server stack. Every mark comes with the line that fixes it.HSTS · CSP · XFO · XCTO · Referrer · PermissionsCookies · COOP/COEP/CORPPDF reportOpen Security HeadersHTTPS configurationTLS CheckerHow well does your server do HTTPS?Certificate chain and trust, SSL 2/3 and TLS 1.0 to 1.3, every cipher suite the server will negotiate, forward secrecy, key exchange strength, OCSP stapling, secure renegotiation, compression and HSTS — scored and capped the way SSL Labs does it, so the grade means what people expect it to mean.Certificate · Protocols · Cipher suites · Key exchangeSSL Labs-style gradePDF reportOpen TLS CheckerAttack surfaceCertificate TransparencyWhat do the certificate logs say about you?Every publicly trusted certificate is logged before a browser will accept it, which makes the logs a complete history of every host name your organisation has ever put behind HTTPS. Search them for a domain: which names still resolve, which point at private addresses, which certificates expire soon, which authorities issued them and whether CAA agrees, and what was issued in the last thirty days.Host names · Issuers · CAA · ExpiryPrivate addresses · Recent issuancePDF reportOpen Certificate TransparencyPECR and third partiesCookies & ConsentWhat does your site do before anyone clicks accept?A first visit in a real browser with nothing clicked: every cookie set, tracker fired and third-party script loaded before consent, which consent platform is in use and whether the tags wait for it, plus an inventory of every outside host on the page with Subresource Integrity and Content-Security-Policy coverage. The privacy notice and the supply-chain review, from one page load.Cookies · Trackers · Consent platformThird-party inventory · SRI · CSPPDF reportOpen Cookies & Consent