Security Lab

26 tools for governance, analysis, investigation and learning. Choose a tab to find a tool.

38 ECC-2 controls crosswalked to ISO 27001, 37 to SAMA CSF 114 ECC-1 → ECC-2 lineage rows mapped 4 incident tabletop scenarios

Analysers

Everything runs in your browser. Nothing you paste leaves this page.

Certificate & Chain Checker Paste a PEM certificate or chain. A custom DER decoder reads the fields; WebCrypto checks supported signatures. Checks internal consistency and supported signatures in the pasted chain, not platform trust. No root trust store, hostname check, online revocation check or AIA fetch.

Sample: malyahya.com's own certificate chain, captured 2026-09-10. It is a snapshot, not a live fetch.

Email Header Analyser Paste raw email headers to trace message hops, read recorded SPF/DKIM/DMARC results and spot identity mismatches. Reads the receiving server's recorded results; trusts the Authentication-Results header. Does not recheck DKIM, query DNS or inspect the message body.
Email DNS Record Checker Paste TXT records in dig or zone-file format to grade SPF, DKIM key strength and DMARC policy. Use Email Header Analyser for receiver-recorded results. Checks pasted records only, not live DNS. Makes no queries and does not follow include: targets. The lookup count covers top-level terms only.
Classical Cipher Solver Paste ciphertext to remove common encodings and try Caesar, Vigenère and XOR solutions. Vigenère analysis uses repeated sequences (Kasiski) and the index of coincidence. Handles Base64, hex and ROT encodings; attempts Caesar, Atbash, Vigenère, XOR and transposition ciphers. Scores candidates against English only. No modern-cipher analysis or other languages.
Security Header & CSP Checker Paste response headers for a grade using this tool's published rubric and suggested directive changes. The same input gets the same grade. Checks pasted headers only, not the live site. Fetches nothing and does not check allowed hosts for known CSP bypasses.

Sample: malyahya.com's own response headers, captured 2026-09-10. It is a snapshot, not a live fetch.

Nmap Output Analyser Paste Nmap output to review reported exposure, potentially risky services, possible end-of-support flags and suggested NCA ECC-2:2024 references. No scan runs here. Reads pasted output only. Uses reported versions and bundled support-status rules; does not verify versions or establish CVEs. Framework references are suggestions, not compliance findings.
JWT Decoder Paste a JWT to decode its header and payload and inspect alg: none, expiry, issuer and audience claims. Does not verify the signature, key strength, issuer match or audience match. Signature verification requires the relevant HMAC secret or issuer's public key.
Subnet Calculator Enter an IPv4 address/CIDR, such as 192.168.1.0/24, and press Enter for network details, masks and the binary split. Calculates one IPv4 address/CIDR locally. The type label classifies the range using the IANA special-purpose registry, not the entered host.
Log Pattern Checker Paste server logs or choose a sample to flag possible brute force, SQL injection, path traversal, XSS probes and sensitive-file access. Includes activity by IP address. Uses patterns and per-IP timing rules on the first 2 KB of each line. No reputation or location lookups. No matches does not mean safe; unmatched or unrecognised lines remain unchecked.

Also in the lab: Governance (8) Investigate (4) Demos (5)

Investigations

Four browser-based tools for data you paste or import, with fictional samples to start. Each one states its limits.

Also in the lab: Governance (8) Analysers (9) Demos (5)

Learning demos

Five local tools and scripted walkthroughs I use in awareness sessions and mentoring. No live network queries; pasted markup stays inert.

XSS Rendering Demo

A side-by-side of how the same input renders through innerHTML versus textContent. The left pane is an inert parse (DOMParser): nothing on this page executes. Note that innerHTML does not execute <script> elements it inserts; what runs is event-handler attributes (onerror, ontoggle) and javascript: URLs. I use this to explain to engineers why sanitization is a rendering-layer decision, not a validation decision.

WHAT innerHTML WOULD BUILD (inert parse)
SAFE SINK (textContent)

Password Strength Estimator

> Waiting for input...

Hashing & Encoding

> Enter text above to see hashes and encodings

DNS Lookup Demo

💻
Browser
🔍
Recursive
Resolver
🌐
Root
Server
🏢
TLD
Server
📋
Authoritative
Server

TCP/TLS Handshake Demo

CLIENT
SERVER

Also in the lab: Governance (8) Analysers (9) Investigate (4)

Hiring for a security role, or scoping an engagement?

Replies within two business days, in English or Arabic.