
// COMMUNITY & RESEARCH
Tools for the community
Free · Privacy-first · No sign-up
Our contribution to a safer ecosystem
We believe stronger digital security starts with openly sharing knowledge. We build and offer free utilities to support analysts, developers and enthusiasts in their daily technical work — with no tracking and no data leaving your machine. Use them with full autonomy.
- Web
JWT / JOSE Attack Lab
Decode, edit and re-sign JWTs in the browser, with the classic attacks: alg:none, RS256→HS256 confusion, kid and jwk/jku injection.
Open tool → - Cheatsheet
SSTI cheatsheet
Server-Side Template Injection payloads by engine: detection, file read and RCE. Filter, search and copy.
Open tool → - Web
SSRF Helper
Generate every IP/host representation and allowlist-bypass payload, with an explanation of each technique.
Open tool → - Web
Report Generator
Turn a finding into a Markdown report with CVSS 4.0, ready for your pentest.
Open tool → - Web
Security Headers Analyzer
Paste the response headers and get an A+..F grade with per-stack fixes (Nginx/Apache/Node/Cloudflare).
Open tool → - Web
CVSS Calculator
Score severity in any CVSS version — 2.0, 3.0, 3.1 and 4.0 — with live vector and rating.
Open tool →

Need to go beyond the tools?
We offer a complete white-label offensive security stack with Pentest, Scan and Social Engineering, delivered under your brand with specialist support.
Hire Intruder