Tools · Category 03

Defense & SOC

Investigate alerts, pull apart suspicious artefacts and drive an incident from detection through to recovery. These are the blue team tools for the people who have to respond.

12 tools Blue team Browser based
📧

Email Header Analyser

Parse raw email headers to trace the real sender, the hop path and the SPF, DKIM and DMARC results behind a message.

Open →
🔗

Phishing URL Analyser

Break a suspicious link into its parts and flag the tricks phishers use to disguise where it really points.

Open →
🔬

IOC Extractor

Pull IPs, domains, hashes and URLs out of a block of text and get back a clean, defanged list of indicators.

Open →
🔎

CVE Search and Reference

Look up a CVE by its ID and read the description, severity and references pulled from public vulnerability data.

Open →
🎯

MITRE ATT&CK Reference

Browse ATT&CK tactics and techniques and map observed adversary behaviour to the framework.

Open →
📋

SOC Triage Checklist

Work an alert through a structured triage flow so nothing gets missed before you escalate or close it out.

Open →
📝

Incident Response Playbook

Step through containment, eradication and recovery actions for the common incident types a small team faces.

Open →
🛡

Firewall Rule Generator

Build clean firewall rules from source, destination, port and action, with a readable summary of what each one does.

Open →
🔧

Defang and Refang Tool

Defang a URL or IP so it cannot be clicked in a report, or refang one back to its live form for analysis.

Open →

Epoch and Timestamp Converter

Convert between Unix epoch time and human readable dates across time zones, in both directions.

Open →
📑

Log Highlighter and Parser

Paste raw log lines and get IPs, timestamps and key fields highlighted and pulled into a readable view.

Open →
🖥

Windows Event ID Reference

Search Windows Security and System event IDs and read what each one means for detection and response.

Open →

Reference tools last reviewed June 2026. Detection content is checked quarterly.