A new version of FORGE is available.
Free cyber defense workbench

Tools forged for defenders.

FORGE is a community-first analyst toolkit for quick triage, transformation, and investigation prep. Use it to inspect headers, extract indicators, generate hashes, decode payloads, test patterns, and stay oriented with a compact security watch board.

FORGE security watch CACHED
Moscow Mumbai FORGE
Workbench
Triage ready
Watch board
Moscow -> Mumbai

Security watch board

A clean situational dashboard for defenders: global signal view, rotating attacker feed, and high-priority vulnerability watchlist. It gives the page a living command-center feel while keeping the experience focused and practical.

Global attack radar
Cached signal
Signals today
--
Top origins
Defended regions
Exploit Malware Scanner Defended
Rotating signal
Live threat feed
Shodan + URLhaus 0 / 0
Loading threat signals...
Vulnerability intelligence
Cached watchlist
Preparing vulnerability watchlist...

Analyst workbench

Practical utilities for quick triage and investigation prep — extract indicators, check reputation, explain suspicious logs, and transform artifacts, all in the tabs below.

Why FORGE?

A forge takes raw material — unrefined, sometimes genuinely dangerous — and turns it into something useful through heat, pressure, and deliberate shaping. That's the actual daily work of a SOC analyst: raw logs, raw indicators, raw alerts, turned into something you can act on.

The name isn't decoration. It's the job, described plainly.

Email Header Analyzer

Paste full raw headers. FORGE unfolds multiline headers, walks the Received chain chronologically, skips private/loopback IPs, and calls out the largest delivery delay.

Private triage
Raw header input
Analysis output
Results will show source IP, authentication status, received delay, and hop-by-hop timeline.

IOC Extractor

Extract useful indicators from logs, tickets, alerts, malware notes, or copied incident chat text. Files and fetched URLs are processed locally in the browser wherever possible.

Text or file
Extracted indicators
Indicators will be grouped by type with one-click copy buttons.

Need a reputation check on an extracted IP, URL, or hash? Head to the tab.

Hash Lab

Generate MD5 for text and SHA family hashes for text or files. SHA uses the browser WebCrypto API.

Hashing
Input
Hashes
Hash output will appear here.

Looking to check a hash's reputation against VirusTotal instead of just generating one? Head to the tab.

Threat Intel Checker

Look up hash, IP, and URL reputation against VirusTotal in one place. Results are cached at the edge for an hour to stay within VirusTotal's free-tier quota — use Refresh on any single result if you need the latest data.

VirusTotal
Hash, IP, or URL reputation lookup

Paste any mix of MD5/SHA1/SHA256 hashes, IPv4 addresses, domains, and URLs (one per line, or jumbled together) — FORGE detects each indicator's type automatically and checks it against VirusTotal. Defanged formats like 27[.]207[.]73[.]215, evil[.]com, and hxxps:// are parsed automatically. Paced to respect the shared free-tier rate limit (~4 lookups/minute across all FORGE visitors, regardless of indicator type).

Results will appear here as each lookup completes. Click a result for full details.
Quick-lookup bookmarklet

Drag this button to your browser's bookmarks bar. Then, on any page, select an IP / hash / domain / URL and click it to open that indicator straight in FORGE.

🔎 Check on FORGE
Bulk IP enrichment (Country / Region / City / ISP / ASN)

Paste or upload a large list of public IPv4 addresses (thousands are fine) to enrich each with geolocation and network ownership in one pass — then export a single consolidated CSV. Defanged formats like 27[.]207[.]73[.]215 are handled. Built for bulk enrichment; this is geolocation/ASN data, not reputation (for malicious/clean verdicts use the reputation lookup above, which is rate-limited).

Enriched results (with a summary count) will appear here.

AI Log Explainer

Paste a raw log line, SIEM alert, command line, or script snippet and get a plain-English explanation of what it does, whether it looks suspicious, and what to check next. Runs on Cloudflare Workers AI — your input is processed by the model but never stored by FORGE.

Workers AI
Log entry, alert, or command

AI output can be wrong — treat it as a starting point for triage, not a verdict. Limited to one entry (max 4,000 characters) per request; usage is shared across all FORGE visitors.

Explanation
The plain-English breakdown will appear here.

Decoder

Decode or encode Base64, URL encoding, hex, and JWT payloads without sending data outside the browser.

Private decode
Input
Decoded output
Output will appear here.

Subnet Calculator

Quick IPv4 CIDR math for analysts reviewing firewall logs, allowlists, alerts, or cloud network ranges.

IPv4 CIDR
CIDR input
Network result
Subnet details will appear here.

Regex Tester

Build and test log patterns quickly. Matches are shown with index, value, and captured groups.

Pattern lab
Pattern and text
Matches
Regex matches will appear here.

Hear about new modules first

Everything announced so far is live in the toolkit above. Join the launch list and you'll get one short email when the next analyst module ships — nothing else.

Notify me

Join the FORGE launch list for the next set of security intelligence tools.

FORGE runs free. If it saves analyst time, support the next module build.