The toolkit

Everything a defender needs. One console.

A professional-grade toolkit organized into four areas - discover, investigate, operate and report.

🌐 Network

Discover & watch your network

🛰

Live discovery & inventory

Every device, service and open port on your network - mapped and monitored in real time.

📊

Device risk scoring

Each host profiled and ranked, with OS/vendor fingerprinting and alerts on fingerprint drift or spoofing.

🌐

DNS live & dashboard

Real-time DNS and browsing visibility, with an optional built-in local DNS server for blocking and insight.

🧬

Traffic capture & PCAP

Browsing capture and full offline PCAP / packet analysis.

📡

Top talkers + geo

The busiest hosts on the wire and exactly where their outbound traffic is going.

🔒

TLS & DNS hygiene

Per-device TLS/JA4 fingerprints and encrypted-DNS posture, so weak or rogue crypto stands out.

🛡 Threats & Defense

Detect, investigate, defend

🎯

Threat Picture

One ranked, unified view of every device, service and anomaly - so you know what matters in seconds.

🔬

Investigation console

Paste any IP, domain, hash, URL, email or certificate → one combined case with a verdict and pivots.

🦠

Malware triage

Static PE/DLL analysis, macro & document inspection, YARA matching and multi-layer deobfuscation.

🧾

Forensics toolbox

Email, file and link investigators, EXIF/metadata, JWT and X.509 certificate inspectors - mostly offline.

🌍

OSINT suite

WHOIS, breach checks, reputation, email & phone intelligence and username footprint in one place.

🛡

Live defenses

MITM, ARP and rogue-DHCP guards plus endpoint hardening checks.

🎯 SOC & Cyber Ops

Run operations like a SOC

🚨

SOC console

A live alert and case queue for the whole environment, with acknowledge/triage workflow.

🕵

Threat hunting

Prebuilt hunting hypotheses, beaconing/C2 detection and lateral-movement analysis.

🗺

Live maps & ATT&CK

Global threat map, a live MITRE ATT&CK heatmap and attack-path (link-analysis) graphs.

⏱

Incident replay

A visual timeline that replays an incident end to end for review and handover.

📈

Exposure intelligence

Your external attack surface and an internet-exposure scorecard, prioritized by risk.

⚙

Playbooks & SOAR-lite

Incident-response runbooks and rule-driven automation - every action stays under your control.

📊 Reporting & Governance

Prove it to the board

🏛

CISO executive briefing

A board-ready posture report - overall score, top business risks and a prioritized action plan.

🎓

Executive scorecard

One graded number for leadership, tracked over time so progress is measurable.

✅

Compliance mapping

CIS Controls · NIST CSF · ISO 27001 mapping generated straight from your findings.

📄

Client-ready reports

Branded, PDF-ready reports for clients and MSSP engagements - generated, not copy-pasted.

🔗

SIEM export & alerting

Export as CEF / JSON / syslog and push alerts to Slack, Teams, webhook or email.

🎯

Risk prioritization

Third-party (vendor) risk tiering and severity-ranked findings, so you fix what matters first.

Unlock full access with Business.

Start a 14-day free trial of live network discovery & device inventory - no card required. Pro unlocks the analyst toolkit - investigation, threat-hunting, SOC console, forensics & OSINT. Business gives you full access - every tool, plus CISO briefings, risk & vendor risk, SIEM export, compliance mapping and multi-client management.