SOC status: Operational/Continuous monitoring active

Acronis MDR / XDR available +230 5254 7558

Home/Threat Intelligence/Free Security Tools

Tools

Free Security Check Tools

A short, checked list of free tools you can run yourself — no sales call, no trial, no lead form. Every link below was loaded and verified before it was published here.

Most of what an attacker learns about you is available to anyone who cares to look, and most of what you would want to know about your own exposure can be checked for nothing. These are the tools we actually use, grouped by the question they answer.

Two of them we support directly: Acronis VSS Doctor, because a broken Volume Shadow Copy Service is the most common reason a Windows backup restores badly, and CERT-MU, because knowing the national reporting route before an incident saves hours during one.

Two things to read before you start

Active scan Tools with this mark send traffic to whatever you point them at. Run them only against systems you own or have written authorisation to test — testing someone else's systems without permission is an offence under the Cybersecurity and Cybercrime Act 2021.

Submissions may be public Tools with this mark may share or publish what you submit. Never upload a document containing client data, credentials or anything confidential.

Backup and recovery diagnostics

A backup that has never been restored is a forecast, not a control. These check the machinery underneath it.

CSET and the Ransomware Readiness Assessment

CISA and Idaho National Laboratory

A self-hosted desktop assessment that walks you through structured questions and scores the answers against recognised standards. The bundled Ransomware Readiness Assessment concentrates on backup integrity, offline and immutable copies, restore testing and recovery planning.

Why it matters
It converts "we have backups" into an honest account of whether those backups would survive an intrusion and actually restore.
Cost
Free and open source.
Before you run it
A questionnaire rather than a scanner — the output is only as good as the honesty of the answers. Installed locally; nothing is transmitted. Some framework references are US-centric.
Open the tool

CrystalDiskInfo

Crystal Dew World

Reads S.M.A.R.T. health data straight off HDDs, SSDs and NVMe drives — reallocated and pending sectors, wear levelling, power-on hours, temperature — and warns as a drive degrades.

Why it matters
Backup targets and NAS disks fail silently, and a dying backup disk usually announces itself on the day you need the restore.
Cost
Free.
Before you run it
Windows only. Support for drives behind USB bridges and hardware RAID controllers is partial, so a healthy reading on a RAID array is not conclusive. Check the licence before deploying it across a fleet.
Open the tool

Email and domain security

Business email compromise is the main revenue technique of the networks targeting this region. These tell you whether your domain can be impersonated.

Email Security Check

NCSC (United Kingdom)

Enter a domain and it reports on the anti-spoofing and transport records behind its mail — SPF, DKIM, the strength of the DMARC policy, TLS and MTA-STS.

Why it matters
A weak or missing DMARC policy lets anyone send invoices and bank-detail changes that appear to come from your own domain.
Cost
Free, no registration.
Before you run it
A passive DNS lookup — nothing is sent to your servers. Built for UK organisations, though the checks themselves are universal.
Open the tool

Check MX

Google Admin Toolbox

Validates a domain's mail DNS — MX records, SPF, DKIM where you supply the selector, and DMARC — and flags the misconfigurations that break delivery or authentication.

Why it matters
Broken MX and SPF records cost you mail in both directions: legitimate messages lost, fraudulent ones accepted.
Cost
Free, no account.
Before you run it
Passive. Some guidance assumes Google Workspace as the mail host.
Open the tool

Internet.nl mail test

Dutch Internet Standards Platform

Submissions may be public

A strict standards-conformance test covering SPF, DKIM, DMARC, DNSSEC, STARTTLS, DANE, RPKI and IPv6 reachability.

Why it matters
It exposes the transport-layer gaps that allow mail to be intercepted, not merely spoofed.
Cost
Free, no account, vendor-neutral and government-backed.
Before you run it
Each result gets a shareable permalink and the site publishes a hall of fame, so treat results as discoverable. The scoring is standards-maximalist — a low score is not automatically a live vulnerability.
Open the tool

TLS and web server configuration

The findings that turn up in every customer security questionnaire, and the ones a browser will eventually refuse outright.

SSL Server Test

Qualys SSL Labs

Active scan

Connects to a public HTTPS server and grades its certificate chain, protocol versions, cipher suites, key exchange and exposure to known TLS weaknesses, from A+ down to F.

Why it matters
Expired chains, legacy TLS and weak ciphers are the classic finding when a client or insurer audits you.
Cost
Free, no account.
Before you run it
Tick "do not show the results on the boards" unless you are content for the result to be listed publicly. Public-facing hosts only.
Open the tool

Active scan

Scans a site's HTTP response headers and related configuration — Content Security Policy, HSTS, frame options, cookie flags, referrer policy — and returns a graded report with specific fixes.

Why it matters
Missing headers leave a site open to clickjacking, cross-site scripting and session-cookie theft.
Cost
Free, no account.
Before you run it
Judges configuration only; it will not find application vulnerabilities. Results are retrievable by URL.
Open the tool

What of yours is on the internet

Edge appliances and forgotten management interfaces remain the dominant ransomware on-ramp. Start by seeing what an attacker sees.

Check your cyber security

NCSC (United Kingdom)

Active scan

A short suite of non-intrusive checks aimed at smaller organisations — a website and IP check for exposed or vulnerable internet-facing systems, the email check above, and a browser check for out-of-date versions.

Why it matters
It surfaces the unpatched, internet-exposed services that ransomware crews scan for indiscriminately.
Cost
Free, no registration, nothing to install.
Before you run it
The website and IP check tests the address you supply, so only submit addresses you control.
Open the tool

Shodan

Shodan

A searchable index of internet-connected hosts built from continuous scanning. Look up your own public IP ranges to see which ports, services, software versions and banners are visible from outside.

Why it matters
It shows your exposure without touching your network — exposed RDP, forgotten NAS boxes, management interfaces, cameras.
Cost
Free with limits: a free account gives basic search with capped results, no advanced filters and no export.
Before you run it
You are querying Shodan's existing database, so no packets reach your network — but everything you can see, anyone else searching the same terms can see too. Data can be weeks old.
Open the tool

An independently built index of hosts, services and TLS certificates. Searching your domain surfaces certificates and subdomains for hosts you may have forgotten.

Why it matters
Certificate transparency data routinely exposes staging, VPN and admin hostnames that were never meant to be public.
Cost
Free with limits: free accounts receive a monthly credit allocation that does not roll over.
Before you run it
Passive lookups against Censys's own data. Worth running alongside Shodan, since the two index differently.
Open the tool

Credential and breach exposure

Reused credentials from someone else's breach are the most common route into business email.

Searches tens of billions of breached records. The domain search lists every address on a domain you control that has appeared in a breach and can monitor it going forward; the companion Pwned Passwords service tells you whether a specific password appears in breach corpora.

Why it matters
It tells you which of your staff already have credentials circulating, which is the first thing an attacker checks.
Cost
Free with limits: individual email search is free, and domain search and monitoring are free for domains with up to ten breached addresses.
Before you run it
You must prove control of the domain before you can search it. Do not paste live production passwords into any third-party site — the password lookup only sends a partial hash, but the habit is the risk.
Open the tool

Checking a suspicious file or link

For the moment someone forwards you an attachment and asks whether it is safe.

VirusTotal

VirusTotal (Google)

Submissions may be public

Submits a file, URL, domain or IP to more than seventy antivirus engines and reputation services at once and aggregates the verdicts, with static and behavioural detail.

Why it matters
A fast second opinion on a suspicious attachment or link before anyone opens it.
Cost
Free with limits: public web submissions are rate-limited with a file-size cap.
Before you run it
This is the important one. Files uploaded on the free tier are shared with VirusTotal's partners and become retrievable by paying subscribers. Never upload anything containing client data, credentials or confidential material — submit the file's hash instead wherever you can.
Open the tool

urlscan.io

urlscan GmbH

Submissions may be public

Opens a suspicious URL inside a sandboxed browser and records what actually happens — the redirect chain, domains contacted, resources loaded, a screenshot of the final page and any credential-harvesting form.

Why it matters
It lets staff establish whether a link is a phishing page without visiting it on a company machine.
Cost
Free for normal investigative use, including commercial work.
Before you run it
Choose the visibility setting deliberately. Public scans are searchable by anyone; unlisted scans are visible to vetted researchers and subscribers. Scanning a URL that contains a token or a personalised path can publish that token.
Open the tool

Testing your people

Four in five ransomware attacks now begin with an identity rather than a vulnerability.

Phishing Quiz

Jigsaw (Google)

An eight-question interactive quiz showing realistic messages and asking the user to judge phishing against legitimate, explaining the tell in each case.

Why it matters
The cheapest way to find out whether your staff can actually spot a spoofed sender.
Cost
Free, no account.
Before you run it
Awareness training rather than a measurable test — there is no per-employee reporting, so it will not evidence a training programme to an auditor. It asks for a name and email to personalise the samples; use placeholders.
Open the tool

Gophish

Open source (Jordan Wright)

Active scan

A self-hosted phishing simulation platform. You build a campaign, send it to your own staff, and it tracks who opened, who clicked and who submitted credentials.

Why it matters
It produces real click-rate data on your own workforce rather than an assumption about it.
Cost
Free and open source, self-hosted, no per-seat cost.
Before you run it
The heaviest caveat here. Only ever run this against your own employees, with documented written authorisation from management and HR consulted first. You host it, so you hold the collected credentials and the data protection duty that comes with them.
Open the tool

Knowing what to patch first

There are always more open vulnerabilities than hours. This narrows it to the ones being used against people right now.

An authoritative, continuously updated list of vulnerabilities confirmed to be exploited in the wild, filterable by vendor and product and downloadable as CSV or JSON.

Why it matters
It tells you which of the thousands of open CVEs are actually being used, so patching effort goes where the risk is.
Cost
Free, no account.
Before you run it
A reference list, not a scanner — it will not tell you what you are running, so cross-reference it against your own inventory. Absence from the catalogue does not make a vulnerability safe to ignore.
Open the tool

Closer to home

The national body you should know about before you need it.

CERT-MU

Ministry of Information Technology, Communication and Innovation

Mauritius's national computer emergency response team. Publishes vulnerability notes, advisories and security alerts, and operates incident reporting through MAUCORS alongside a cybersecurity hotline.

Why it matters
Local advisories reach you before international ones do, and knowing the reporting route before an incident saves hours during one.
Cost
Free public service.
Before you run it
Reporting an incident to CERT-MU does not discharge any separate duty you may have to notify the Data Protection Office within 72 hours.
Open the tool

Get in touch

Rather have someone run these for you?

We do this as a fixed-scope external exposure review — the same checks, plus the ones that need tooling you would not buy for a one-off, written up with what to fix first.