// the toolkit
NeoShield Security Tools
Every defensive tool on the platform, in one place. Start free with no account: grade a website, analyze a suspicious email, audit a token, or check whether your accounts are exposed. AI-assisted tools turn raw signals into ranked, explainable, standards-mapped action. Most tools process your input on NeoShield without storing it; some save results to your account or use an AI provider — each tool's processing label tells you exactly what happens.
Find a tool by what you need to do
Nine categories, grouped by intent. Every card states the plan, the input it expects, and how that input is processed — before you use it.
Website & API security
AI Vulnerability Scanner
Find misconfigurations and exposed surface on a site you own.
Open tool →HTTP Security Header Checker
Grade response headers and get copy-paste fixes.
Open tool →Exposure Check
See breach exposure and domain spoofability for an identity.
Open tool →Typosquat Domain Finder
Find look-alike domains that could impersonate yours.
Open tool →Code & configuration
AI Security Code Reviewer
Find injection, broken authorization and leaked secrets in pasted code.
Open tool →AI Config & IaC Auditor
Audit Dockerfiles, nginx, .env, compose/K8s or Terraform.
Open tool →AI Patch Generator
Minimal, behaviour-preserving secure refactors with before/after diffs.
Open tool →AI DevSecOps Automation
Explainable CI/CD gates with an aggregated release verdict.
Open tool →Email & phishing
AI Scam & Message Checker
Decide whether a text, email or DM is a scam, and what to do next.
Open tool →AI Phishing Email Analyzer
Header, link and homograph analysis with a verdict and defanged links.
Open tool →Phishing URL Checker
Analyze a single suspicious link for phishing signals.
Open tool →Identity & secrets
JWT Security Auditor
Decode a token and flag alg=none, missing expiry and weak settings.
Open tool →Quantum Vault
AES-256-GCM encryption performed in server memory.
Open tool →Security Toolkit
Headers, DNS, TLS, IOC, hashing, JWT, CIDR and CSP in one place.
Open tool →Threat intelligence
Threat Intelligence
Search live CVE and CISA KEV data and see required action.
Open tool →Threat Live
A streaming feed of current threat indicators.
Open tool →IP Reputation Checker
Look up the reputation and risk of an IP address.
Open tool →Suspicious Pattern Analyzer
Score logs and payloads for unusual, signature-less patterns.
Open tool →Incident response
AI Incident Response
A calm, structured plan: scope, contain, eradicate, recover.
Open tool →AI SOC Copilot
Blue-team Q&A: triage, ATT&CK mapping, detection ideas.
Open tool →AI Incident Report Writer
Turn incident facts into a structured, shareable report.
Open tool →Ransomware Readiness
Self-assess your resilience to a ransomware attack.
Open tool →Security operations
Team Security Center
One organization-isolated view of posture, incidents, devices and seats.
Open tool →AI Detection-Engineering Studio
Turn a log sample into a Sigma rule, SIEM query and test cases.
Open tool →AI Vulnerability Triage
De-duplicate and prioritize scanner findings for analyst review.
Open tool →Factory Studio
Compose and host your own defensive micro-tools from vetted primitives.
Open tool →Cryptography & PQC
AI PQC Analyzer
Inventory quantum-vulnerable cryptography and get a NIST migration plan.
Open tool →PQC Migration Suite
Org-wide crypto inventory and a phased migration pipeline.
Open tool →Learning & readiness
AI-powered tools
AI SOC CopilotFree
Ask a Claude-powered SOC analyst for triage, MITRE mapping, and detections.
Suspicious Pattern AnalyzerFree + Pro
AI-assisted scoring of logs and payloads for suspicious, signature-less patterns.
AI Reverse EngineeringPro
Static, no-execution binary triage: capability, IOCs, next step.
AI Patch GeneratorPro
Minimal, behavior-preserving secure refactors with before/after diffs.
AI PQC AnalyzerPro
Quantum-vulnerable crypto inventory and NIST PQC migration plan.
PQC Migration SuitePro
Org-wide crypto inventory, phased NIST migration pipeline, post-quantum migration-readiness score, and an AI executive playbook.
AI DevSecOps AutomationPro
Explainable CI/CD security gates with an aggregated release verdict.
AI Security AdvisorPro
On-demand strategy, risk reviews, and roadmaps.
AI Vulnerability ScannerFree + Pro
Passively scan a site you own for misconfigurations, with AI countermeasures.
Account & Exposure CheckFree + Pro
Check breached passwords/emails and domain spoofability.
AI Incident ResponseFree + Pro
A calm, tailored "I've been hacked, what now?" plan.
AI Phishing Email AnalyzerFree
Paste a suspicious email for a verdict, red flags, and defanged links.
AI Security Code ReviewerFree
Defensive SAST: find vulnerabilities in pasted code and how to fix them.
Factory StudioPro
Compose hosted defensive micro-tools from vetted primitives.
AI Detection-Engineering StudioPro
Turn a threat or log sample into a Sigma detection rule, SIEM query, and test cases.
AI Threat-Model & Attack-Surface AnalyzerPro
STRIDE threat model from your architecture: threats, attack paths, MITRE mapping, controls, residual risk.
AI Vulnerability TriagePro
De-duplicate and prioritize nmap/nikto/ffuf findings, flagging possible duplicates and potential false positives for analyst review, with remediation.
AI Config & IaC AuditorFree
Audit Dockerfiles, nginx, .env, compose/K8s, Actions, or Terraform for misconfigurations.
AI Firewall & Exposure AuditorFree
Find internet-exposed services and risky ports in iptables/ufw/AWS security-group rules.
AI Network Traffic AnalyzerPro
Identify traffic patterns that may be consistent with C2 beaconing, port scans, and possible exfiltration in connection logs.
AI Compliance MapperPro
Gap-analysis against SOC 2, ISO 27001, Japan APPI, and GDPR with a readiness score.
AI Incident Report WriterPro
Turn incident facts into a structured report: summary, timeline, MITRE, remediation.
security.txt GeneratorFree
Generate a valid RFC 9116 security.txt, disclosure policy, and triage email.
Platform & consoles
SOC OperationsTeam
Unified console: alerts, ATT&CK/UEBA analytics, and device fleet (mobile, PC, network, IP, IoT) in one place.
Quantum VaultFree
AES-256-GCM text encryption processed in server memory — not stored or logged.
Device Agent (PWA)Free
Installable agent for lightweight endpoint signals.
Security ToolkitFree
Headers, DNS, TLS, IOC, hashing, JWT, CIDR, CSP — all in one.
Threat LiveFree
A live, streaming feed of current threat indicators.
Security AcademyFree
Hands-on SOC training with simulations and progression.
Free single-purpose checkers
HTTP Security Header Checker
Grade a site's response headers and get copy-paste fixes.
JWT Security Auditor
Decode and audit a JSON Web Token for weak settings.
Phishing URL Checker
Analyze a single suspicious link for phishing signals.
IP Reputation Checker
Look up the reputation and risk of an IP address.
Typosquat Domain Finder
Discover look-alike domains that could impersonate yours.
Ransomware Readiness
Self-assess your resilience to a ransomware attack.
Compare the tools
Honest side-by-side comparisons to pick the right tool for the job — including when another option fits better.
NeoShield Exposure Check vs Have I Been Pwned
Run a free exposure check →
Free JWT Security Auditor vs a JWT Decoder
Audit a JWT free →
Free Post-Quantum Crypto Inventory Tool (vs a Manual Audit)
Scan your crypto free →
SARIF Release Gate: NeoShield DevSecOps vs Custom CI Scripts
Evaluate a report free →
Static Binary Triage Online (No-Execution) vs a Sandbox Upload
Triage a file free →
Frequently asked questions
Are these security tools free?
Most tools are free to use with no account. Some AI-heavy tools are freemium — typically one free run per month with higher limits on Pro — and a few advanced consoles are part of paid tiers.
Do you store the data I submit?
For these tools, no — they analyze your input on NeoShield in server memory for that request only and do not store it. Password checks use k-anonymity (only a 5-character hash prefix leaves the server). Quantum Vault encryption runs on our server in memory; your text is not stored or logged. Some tools save results to your account or use an AI provider — each tool's processing label tells you which.
Which tool should I start with?
For a quick site health check, run the HTTP Security Header Checker or the AI Vulnerability Scanner. To investigate a suspicious message, use the Phishing Email Analyzer. To plan after an incident, use AI Incident Response.
Can I use these tools commercially?
Yes, within fair-use limits. For higher volumes, history, and exports, the Pro tier raises per-tool quotas.