Home/Threat Intelligence/Free Security Tools
Tools
Free Security Check Tools
A short, checked list of free tools you can run yourself — no sales call, no trial, no lead form. Every link below was loaded and verified before it was published here.
Most of what an attacker learns about you is available to anyone who cares to look, and most of what you would want to know about your own exposure can be checked for nothing. These are the tools we actually use, grouped by the question they answer.
Two of them we support directly: Acronis VSS Doctor, because a broken Volume Shadow Copy Service is the most common reason a Windows backup restores badly, and CERT-MU, because knowing the national reporting route before an incident saves hours during one.
Two things to read before you start
Active scan Tools with this mark send traffic to whatever you point them at. Run them only against systems you own or have written authorisation to test — testing someone else's systems without permission is an offence under the Cybersecurity and Cybercrime Act 2021.
Submissions may be public Tools with this mark may share or publish what you submit. Never upload a document containing client data, credentials or anything confidential.
Backup and recovery diagnostics
A backup that has never been restored is a forecast, not a control. These check the machinery underneath it.
Acronis VSS Doctor
Acronis
A Windows diagnostic that inspects the Volume Shadow Copy Service end to end — service and start-up state, COM and DCOM registration, VSS provider registration, access rights, shadow storage allocation, free space, disk load, hidden partitions that block snapshots, and writers stuck in a failed state. It gathers the findings into a single report and offers a one-click fix where Acronis has a known remedy.
Open the toolCSET and the Ransomware Readiness Assessment
CISA and Idaho National Laboratory
A self-hosted desktop assessment that walks you through structured questions and scores the answers against recognised standards. The bundled Ransomware Readiness Assessment concentrates on backup integrity, offline and immutable copies, restore testing and recovery planning.
Open the toolCrystalDiskInfo
Crystal Dew World
Reads S.M.A.R.T. health data straight off HDDs, SSDs and NVMe drives — reallocated and pending sectors, wear levelling, power-on hours, temperature — and warns as a drive degrades.
Open the toolEmail and domain security
Business email compromise is the main revenue technique of the networks targeting this region. These tell you whether your domain can be impersonated.
Email Security Check
NCSC (United Kingdom)
Enter a domain and it reports on the anti-spoofing and transport records behind its mail — SPF, DKIM, the strength of the DMARC policy, TLS and MTA-STS.
Open the toolCheck MX
Google Admin Toolbox
Validates a domain's mail DNS — MX records, SPF, DKIM where you supply the selector, and DMARC — and flags the misconfigurations that break delivery or authentication.
Open the toolInternet.nl mail test
Dutch Internet Standards Platform
Submissions may be public
A strict standards-conformance test covering SPF, DKIM, DMARC, DNSSEC, STARTTLS, DANE, RPKI and IPv6 reachability.
Open the toolTLS and web server configuration
The findings that turn up in every customer security questionnaire, and the ones a browser will eventually refuse outright.
SSL Server Test
Qualys SSL Labs
Active scan
Connects to a public HTTPS server and grades its certificate chain, protocol versions, cipher suites, key exchange and exposure to known TLS weaknesses, from A+ down to F.
Open the toolHTTP Observatory
Mozilla
Active scan
Scans a site's HTTP response headers and related configuration — Content Security Policy, HSTS, frame options, cookie flags, referrer policy — and returns a graded report with specific fixes.
Open the toolWhat of yours is on the internet
Edge appliances and forgotten management interfaces remain the dominant ransomware on-ramp. Start by seeing what an attacker sees.
Check your cyber security
NCSC (United Kingdom)
Active scan
A short suite of non-intrusive checks aimed at smaller organisations — a website and IP check for exposed or vulnerable internet-facing systems, the email check above, and a browser check for out-of-date versions.
Open the toolShodan
Shodan
A searchable index of internet-connected hosts built from continuous scanning. Look up your own public IP ranges to see which ports, services, software versions and banners are visible from outside.
Open the toolCensys Search
Censys
An independently built index of hosts, services and TLS certificates. Searching your domain surfaces certificates and subdomains for hosts you may have forgotten.
Open the toolCredential and breach exposure
Reused credentials from someone else's breach are the most common route into business email.
Have I Been Pwned
Troy Hunt
Searches tens of billions of breached records. The domain search lists every address on a domain you control that has appeared in a breach and can monitor it going forward; the companion Pwned Passwords service tells you whether a specific password appears in breach corpora.
Open the toolChecking a suspicious file or link
For the moment someone forwards you an attachment and asks whether it is safe.
VirusTotal
VirusTotal (Google)
Submissions may be public
Submits a file, URL, domain or IP to more than seventy antivirus engines and reputation services at once and aggregates the verdicts, with static and behavioural detail.
Open the toolurlscan.io
urlscan GmbH
Submissions may be public
Opens a suspicious URL inside a sandboxed browser and records what actually happens — the redirect chain, domains contacted, resources loaded, a screenshot of the final page and any credential-harvesting form.
Open the toolTesting your people
Four in five ransomware attacks now begin with an identity rather than a vulnerability.
Phishing Quiz
Jigsaw (Google)
An eight-question interactive quiz showing realistic messages and asking the user to judge phishing against legitimate, explaining the tell in each case.
Open the toolGophish
Open source (Jordan Wright)
Active scan
A self-hosted phishing simulation platform. You build a campaign, send it to your own staff, and it tracks who opened, who clicked and who submitted credentials.
Open the toolKnowing what to patch first
There are always more open vulnerabilities than hours. This narrows it to the ones being used against people right now.
An authoritative, continuously updated list of vulnerabilities confirmed to be exploited in the wild, filterable by vendor and product and downloadable as CSV or JSON.
Open the toolCloser to home
The national body you should know about before you need it.
CERT-MU
Ministry of Information Technology, Communication and Innovation
Mauritius's national computer emergency response team. Publishes vulnerability notes, advisories and security alerts, and operates incident reporting through MAUCORS alongside a cybersecurity hotline.
Open the toolGet in touch
Rather have someone run these for you?
We do this as a fixed-scope external exposure review — the same checks, plus the ones that need tooling you would not buy for a one-off, written up with what to fix first.