BlueTeam Toolkits.
The open defender workspace. Turn events, indicators, and exposures into evidence you can act on.
Log parsing stays in your browser. Live lookups contact public data sources.
01 / Investigation preview
From raw event to a clear signal.
The same deterministic analysis used by the Windows Event & Sysmon parser.
Preparing sample…
Analyzing · — events
Analyzing event pattern…
02 / Tool directory
Tools for the work at hand.
Go straight from an investigation question to the right analysis.
Host & Endpoint Logs 02
Understand execution, logons, and host activity.
Linux Auditd Log Parser
Group raw auditd or ausearch records into readable events with actor, command, file and outcome fields, an explainable risk score and ATT&CK mapping.
Local · ATT&CKWindows Event & Sysmon Log Parser
Parse Windows Event Log XML, Sysmon and Winlogbeat output into normalized logon, process and outcome fields with an explainable risk score and ATT&CK mapping.
Local · ATT&CKCloud Security 02
Trace identities and actions across cloud audit trails.
CloudTrail Event Parser
Parse AWS CloudTrail events into normalized actor, action, resource and auth fields with an explainable risk score and ATT&CK mapping.
Local · ATT&CKAzure Activity Log Parser
Parse Azure Activity and Entra ID sign-in / audit logs into normalized caller, operation, resource and auth fields with an explainable risk score and ATT&CK mapping.
Local · ATT&CKThreat Intel & Recon 04
Prioritize exposures and investigate internet-facing infrastructure.
DNS Lookup (dig)
Run A, AAAA, MX, NS, TXT and more DNS queries against public resolvers and read the raw dig-style response.
Live lookupIP Geolocation Lookup
Map any IP or domain to its country, city, coordinates, ISP and ASN, with hosting, proxy and CDN/anycast signals.
Live lookupSSL/TLS Certificate Analyzer
Review a domain's certificate: issuer, expiry countdown, every SAN domain, CT issuance history, CAA policy and HSTS hardening.
Live lookupCVE, KEV & EPSS Intelligence
Triage any CVE against NVD, CISA KEV and EPSS exploit probability with an explainable priority verdict, ransomware-use flags and bulk scanner-export triage.
Live lookupEmail Defense 04
Investigate message origins, authentication, and indicators.
Email Security Analyzer
Inspect SPF, DMARC, and DKIM records to spot email authentication weaknesses and improve deliverability.
Domain analysisEmail Header Analyzer
Paste raw message headers to trace the delivery path, measure hop delays, and review SPF, DKIM and DMARC verdicts.
Local analysisIOC Extractor
Extract IPs, domains, URLs, emails and file hashes from raw email or log text into a deduplicated, exportable IOC list.
Local analysisBIMI Checker & Generator
Validate BIMI records, SVG Tiny PS logos and VMC/CMC certificates, check DMARC readiness, and generate a publish-ready DNS record.
Domain analysisAnalyst Utilities 03
Decode, inspect, and transform investigation artifacts.
Decoder Lab
A CyberChef-style recipe builder for encoding, decoding, hashing, compression, ciphers and text transformations.
Local analysisJWT Analyzer
Decode JWT header and payload, inspect claims, issuer, audience and expiry, verify signatures and flag suspicious configuration.
Local analysisSAML Token Analyzer
Deflate and decode SAML requests and responses, read the assertion, attributes, conditions and certificate, and flag risky configuration.
Local analysis03 / Quick starts
Follow the evidence.
Suspicious email
Trace delivery, extract indicators, and investigate the source.
Endpoint alert
Understand the host event, then unpack suspicious content.
Vulnerability triage
Check confirmed exploitation and exploit likelihood before patching.