Search security tools
Find the right tool across monitoring, vulnerability, firewall, incident response and more.
Network & Firewall
Audit iptables / UFW / Cisco ACL / security-group rules for risky openings and get fixes.
Look up the reputation and risk of an IP address.
Headers, DNS, TLS, IOC, hashing, JWT, CIDR, CSP — all in one.
Paste iptables, ufw, or AWS security-group rules to find internet-exposed services and risky ports, with fixes.
Monitoring & Detection
Paste logs to detect brute-force, privilege escalation and malware indicators with MITRE mapping.
Ask a Claude-powered SOC analyst for triage, MITRE mapping and detections.
AI-assisted scoring of logs and payloads for suspicious, signature-less patterns.
A live, streaming feed of current threat indicators.
Multi-tenant log ingestion, rule-based detection and alerting.
Paste connection logs to detect C2 beaconing, port scans, risky-port use, and possible exfiltration.
Turn a threat description or log sample into a Sigma detection rule, a SIEM query, false-positive tuning, and test cases.
Aggregated threat intelligence: KEV, CVEs, advisories and vendor reporting.
Curated security news and updates from reputable sources.
Vulnerability & Assessment
Passively scan any site you own for misconfigurations, with AI countermeasures.
Check breached passwords/emails and domain spoofability.
Grade a site's response headers and get copy-paste fixes.
Decode and audit a JSON Web Token for weak settings.
Defensive SAST: find vulnerabilities in pasted code and how to fix them.
Quantum-vulnerable crypto inventory and NIST PQC migration plan.
Org-wide crypto inventory, phased NIST migration, PQC compliance score and AI playbook.
Paste a Dockerfile, nginx, .env, compose/K8s, Actions or Terraform for ranked misconfigs and fixes.
Paste nmap/nikto/ffuf output for de-duplicated, prioritized triage with false-positive filtering and remediation.
Describe your architecture for a STRIDE threat model: per-component threats, attack paths, MITRE mapping, controls, and residual-risk score.
Turn authorized scan output into a scored, correlated, client-ready pentest report.
Read-only viewer for a shared NeoPentest report — no account needed.
Incident & Response
A calm, tailored "I've been hacked, what now?" plan.
Paste a suspicious email for a verdict, red flags and defanged links.
Turn incident facts and findings into a structured report — summary, timeline, impact, MITRE mapping, remediation.
Analyze a single suspicious link for phishing signals.
Discover look-alike domains that could impersonate yours.
Static, no-execution binary triage: capability, IOCs, next step.
Paste any suspicious message — SMS, chat, marketplace, dating — and get a verdict.
Governance & Advisory
Generate a valid RFC 9116 security.txt, a disclosure policy, and a triage email in seconds.
Map your security posture to SOC 2, ISO 27001, Japan APPI and GDPR with per-control gap analysis and readiness scores.
Minimal, behavior-preserving secure refactors with before/after diffs.
Explainable CI/CD security gates with an aggregated release verdict.
On-demand security strategy, risk reviews and roadmaps.
Self-assess your resilience to a ransomware attack.
Compose hosted defensive micro-tools from vetted primitives.
Platform defence posture: blocklists, lockdown, honeypot and rate-limit controls.
Platform & Learning
A structured learning track: offensive technique taught for defence.
How everything works: sign-in, plans and quotas, every tool, SOC, the API, and the security model.
Zero-knowledge AES-256-GCM text encryption in your browser.
Installable agent for lightweight endpoint signals.
Hands-on SOC training with simulations and progression.