This page will include online tools for information gatherings and analysis from a blue team perspective.
Exchange Platform
- Secuirty StackExchange - Plateform to exchange on security issues
Malware analysis:
All the following online tools are public. All sample submitted might be accessible by anyone. Please make sure to consider this before submitting samples*.*
- VirusTotal - Compare sample analysis from multiple AV vendors. Note that the analysis are base on signature detection for most AV vendors. Also perform sample download from URL.
- Malwr.com - Cuckoo sandbox
- Hybrid-analysis - CrowdStrike sandbox. Also perform sample download from URL.
- Any Run - Interactive online sandbox. Also perform sample download from URL.
- PDF Examiner - Automate malware PDF analysis
- Quicksand.io - Office document malware analysis
- Valkyrie comodo - File verdict system
- IntezerAnalyze Community Edition - Malware analysis and classification by code DNA mapping
- Detux Linux Sandbox - Multiplatform Linux Sandbox for malware on x86, x86-64, ARM, MIPS and MIPSEL cpu architecture
- Joe Sandbox Cloud Community Edition - Sandbox for Windows, Android, Mac OS, and iOS for suspicious activities.Also perform sample download from URL.
- Pikker - Cuckoo sandbox. Also perform sample download from URL.
- MalwareConfig - Extract config information from RAT
- YaraRules Analyzer - Cloud base analysis of file base on Yara rules
- IRIS-H - automated static analysis of Object Linking and Embedding Compound Files
- CERT.ee - Cuckoo sandbox. Also perform sample download from URL.
URL/IP/Domain analysis:
- VirusTotal - Compare URL categorization from multiple URL filtering solutions vendors.
- URLquery - Detecting and analyzing web-based malware. It provides detailed information about the activities a browser does while visiting a site and presents the information for further analysis.
- DomainBigData - Big database of domains and whois records.
- MultiRBL - IP check for sending Mailservers
- Robtex - Gather public information about IP numbers, domain names, host names, Autonomous systems, routes, etc.
- SSL Blacklist - List of "bad" SSL certificates identified by abuse.ch to be associated with malware or botnet activities.
- URLscan.io - Analyses websites and the resources they request. It will let you take a look at the individual resources that are requested when a site is loaded.
- DNStrails - World's Largest Repository of historical DNS data.
- URLVoid - Analyzes a website through multiple blacklist engines and online reputation tools.
- IPVoid - IP address tools to discover details about IP addresses.
- Google Safe Browsing - Check site status in Google Safe browsing database.
- Shodan.io - The world's first search engine for Internet-connected devices.
- ThreatCrowd - Domain, IP, Email or Organization search engine for threats.
- ThreatMiner - Free analysts from data collection and provide intelligence analysts
- Centralops.net - Investigate domains and IP addresses. Get registrant information, DNS records, and more—all in one report.
- RegistryDB - Database to find domain information from domain name, IP address, owner name or email address.
- DNSDumpster - Domain research tool that can discover hosts related to a domain.
- Hackertarget.com - Domain research tool that find all Forward DNS (A) records for a domain and all subdomains associated with that domain.
- DNSlytics - Find out everything about a domain name, IP address or provider.
- [1] - McAfee domain reputation
Threat Intelligence:
- Cymon.io - largest open tracker of malware, phishing, botnets, spam, and more.
- C1fApp - Open Source Cyber intelligence threat feeds.
- RiskIQ Community Edition - Free access to comprehensive internet data to hunt digital threats against their organization, defend their digital footprint, and reduce their attack surface across web, mobile, and social channels.
- Open Threat Exchange - World’s First Truly Open Threat Intelligence Community.
- CriticalStack Intel Feed - Free threat intelligence, parsed for the Bro network security monitoring platform.
- IBM X-Force Exchange - Threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers
Phishing:
- MXToolBox - Headers parser
- Google G Suite Toolbox- Headers parser
- HTML Viewer - Real-time HTML Editor
- UnPHP - Free service for analyzing obfuscated and malicious PHP code
- Code Beautify - HTML viewer
Vulnerabilities:
- VulDB - Vulnerability database worldwide with more than 111000 entries available
- Exploit Database - Archive of Exploits, Shellcode, and Security Papers
Reconnaissance:
- Paste Site Search - Search 90+ paste sites. Filter by source & keyword.
Data/Conversion:
- CyberChef - A web app for encryption, encoding, compression and data analysis
In-Browser Cryptomining detection:
- URLscan.io - Analyses websites and the resources they request. It will let you take a look at the individual resources that are requested when a site is loaded.
- NotMining - Detecting and listing websites performing in-browser cryptomining.
**Malware directly from following: