Zum Hauptinhalt springen
LIVE Intel Feed
← Academy
THE ARSENAL

Fifteen tools. Zero signups.

Every inline security tool you wish existed in one place. Nothing is stored. Nothing is tracked. Paste, run, copy the fix.

🩺
LIVE

Header Doctor

Security headers graded + specific fixes.

Paste any public URL. Get a per-header verdict, a score, and drop-in nginx/apache/express snippets for every gap.

🔬
LIVE

TLS X-Ray

Full TLS chain + protocol + cipher analysis.

Inspect live certificates: chain, SANs, key strength, expiry, negotiated protocol and cipher. No API keys, no third-party dependencies.

🧪
LIVE

Prompt Injection Sandbox

Stress-test your system prompt against 40+ payloads.

Paste your AI agent's system prompt. We run it against a curated library of known prompt-injection and jailbreak patterns and highlight likely bypasses.

LIVE

CVE Time Machine

A library's full CVE history, visualized.

Full CVE history timeline for any library with severity distribution and patched version ranges.

🔑
LIVE

Password Entropy Lab

Rainbow-table-grade entropy visualization.

Analyze password strength, entropy bits, cracking time estimates, and compliance with NIST guidelines.

🪪
LIVE

JWT Forensics

Decode + vulnerability scan + signature demo.

Decode JWTs, scan for algorithm confusion, weak keys, and verify signature mechanics.

🐳
LIVE

Docker Hardening Grader

Paste Dockerfile → score + auto-fix.

Grade Dockerfiles for security, detect base image vulnerabilities, analyze layers, and get remediation.

LIVE

K8s Policy Auditor

OPA-powered manifest audit.

Audit Kubernetes manifests for RBAC, network policies, resource quotas, and Pod security policies.

🕵️
LIVE

Nginx Config Scanner

Misconfig detector with explanations.

Detect Nginx misconfigurations, SSL/TLS issues, insecure upstreams, and path traversal risks.

🔎
LIVE

Secret Pattern Scanner

Find hardcoded credentials in pasted code.

Scan code for API keys, private keys, database credentials, and cloud tokens with severity ratings.

⚙️
LIVE

GitHub Actions Auditor

Workflow security grade.

Grade GitHub Actions workflows for action pinning, secrets, branch protection, and OIDC token usage.

🌐
LIVE

DNS Takeover Scanner

Subdomain hijack risk map.

Check DNS records for dangling CNAMEs, third-party service bindings, and subdomain hijack vectors.

📑
LIVE

NIS2/EUVD Gap Scanner

Compliance checklist + evidence.

Generate NIS2 Directive & EUVD compliance checklists with gap analysis and remediation roadmap.

📘
LIVE

Runbook Generator

Incident description → full Markdown runbook.

Generate incident response runbooks with escalation paths, communication templates, and review sections.

🤖
LIVE

AI Jailbreak Tester

EU AI Act bias + robustness testing.

Test AI models for EU AI Act compliance, bias, robustness, fairness, and harmful content boundaries.

Written and validated by Schwerti · ClawGuru
Last updated: · Published:
🔒 Quantum-Resistant Mycelium Architecture
🛡️ 3M+ Runbooks – täglich von SecOps-Experten geprüft
🌐 Zero Known Breaches – Powered by Living Intelligence
🏛️ SOC2 & ISO 27001 Aligned • GDPR 100 % compliant
⚡ Real-Time Global Mycelium Network – 347 Bedrohungen in 60 Minuten
🧬 Trusted by SecOps Leaders worldwide