Free cyber defense workbench

Tools forged for defenders.

FORGE is a community-first analyst toolkit for quick triage, transformation, and investigation prep. Use it to inspect headers, extract indicators, generate hashes, decode payloads, test patterns, and stay oriented with a compact security watch board.

FORGE security watch LIVE
Moscow Mumbai FORGE
Workbench
Triage ready
Watch board
Moscow -> Mumbai

Security watch board

A clean situational dashboard for defenders: global signal view, rotating attacker feed, and high-priority vulnerability watchlist. It gives the page a living command-center feel while keeping the experience focused and practical.

Global attack radar
Cached signal
Signals today
--
Top origins
Defended regions
Exploit Malware Scanner Defended
Rotating signal
Live threat feed
Shodan + URLhaus 0 / 0
Loading threat signals...
Vulnerability intelligence
Cached watchlist
Preparing vulnerability watchlist...

Analyst workbench

Practical utilities for quick triage and investigation prep. The interface is intentionally large, readable, and built for repeated use on laptop and mobile.

Email Header Analyzer

Extract sender, auth status, real public source IP, hop timeline, and the hop causing the largest delay.

ReadyHeader triage

IOC Extractor

Pull IPs, domains, URLs, emails, hashes, and CVEs from pasted text or an uploaded file.

ReadyIndicator prep

Hash and Decode Lab

Generate common hashes, decode Base64/JWT/hex/URL data, and handle quick analyst transformations.

ReadyTransform

Email Header Analyzer

Paste full raw headers. FORGE unfolds multiline headers, walks the Received chain chronologically, skips private/loopback IPs, and calls out the largest delivery delay.

Private triage
Raw header input
Analysis output
Results will show source IP, authentication status, received delay, and hop-by-hop timeline.

IOC Extractor

Extract useful indicators from logs, tickets, alerts, malware notes, or copied incident chat text. File upload is processed locally in the browser.

Paste or upload
Text or file
Extracted indicators
Indicators will be grouped by type with one-click copy buttons.

Hash Lab

Generate MD5 for text and SHA family hashes for text or files. SHA uses the browser WebCrypto API.

Hashing
Input
Hashes
Hash output will appear here.

Decoder

Decode or encode Base64, URL encoding, hex, and JWT payloads without sending data outside the browser.

Private decode
Input
Decoded output
Output will appear here.

Subnet Calculator

Quick IPv4 CIDR math for analysts reviewing firewall logs, allowlists, alerts, or cloud network ranges.

IPv4 CIDR
CIDR input
Network result
Subnet details will appear here.

Regex Tester

Build and test log patterns quickly. Matches are shown with index, value, and captured groups.

Pattern lab
Pattern and text
Matches
Regex matches will appear here.

Coming soon

FORGE will keep expanding into a fuller analyst companion. Join the launch list if you want to know when the next intelligence modules go live.

AI Log Explainer

Paste noisy logs and receive a plain-English explanation, likely root cause, and suggested next actions.

Coming soonLog clarity

IP Reputation

One readable verdict for suspicious IPs, including abuse signals, exposed services, and risk context.

Coming soonRisk verdict

CVE Intelligence

Track high-priority vulnerabilities with severity, exploitability, patch status, and an analyst verdict.

Coming soonVuln watch

URL Reputation

Check suspicious URLs and domains with clear malware, phishing, and scanner context.

Coming soonURL triage

Global Attack Radar

A richer live-style operating picture of active campaigns, scanner activity, and regional signals.

Coming soonIntel view

Notify me

Join the FORGE launch list for the next set of security intelligence tools.

FORGE runs free. If it saves analyst time, support the next module build.