Privacy-first · runs in your browser For practitioners, by practitioners

Practical security tooling. Pick your stack.

Free, browser-based security tools and no-fluff guides — built by a working engineer, grouped by discipline. No accounts, no paywalls.

Browse all 24 tools ↓ Read the guides
No accounts, ever
Data stays client-side
No paywalls or trials
Maintained by an engineer
All Tools

Every tool, one page — filter by discipline

24 tools

ISO 27001 Control Reference Search all 93 ISO 27001:2022 and 114 ISO 27001:2013 Annex A controls with audit evidence and 2013 ↔ 2022 mapping. GRC Open → SOC 2 Criteria Reference Search all 61 SOC 2 Trust Services Criteria with audit evidence and ISO 27001 mapping. GRC Open → NIST CSF 2.0 Reference Search all 106 NIST CSF 2.0 subcategories with evidence examples and ISO 27001 mapping. GRC Open → Control Mapper + Gap Assessment Crosswalk ISO 27001:2022, NIST CSF 2.0 and SOC 2, then run a CMMI-style maturity gap assessment. GRC Open → Risk Register + Matrix Generator ISO 27005 / NIST SP 800-30 aligned risk register with likelihood × impact scoring and a heatmap. GRC Open → Vendor Risk Assessment Assess new and existing vendors with a weighted questionnaire and tiered risk ratings. GRCSecOps Open → NetSegmenter — CIDR / Subnet Calculator Subnet, supernet and plan address space: CIDR maths, VLSM splits and segmentation planning. IT Ops Open → ReverseDNS — PTR Lookup Resolve IPs to PTR records and forward-confirm reverse DNS for ranges, fast. IT OpsOSINT Open → PropCheck — DNS Propagation Check how a DNS record has propagated across global resolvers in real time. IT Ops Open → SPF / DKIM / DMARC Checker Validate email authentication — parse SPF, DKIM and DMARC and flag misconfigurations. IT OpsSecOps Open → ScopeForge — DNS & DHCP Planner Plan DHCP scopes, reservations and DNS zones for a network build or migration. IT Ops Open → AppLocker Studio Read, build and beautify Windows AppLocker policy XML and generate Intune OMA-URI. IT OpsSecOps Open → Windows Event ID Lookup Look up Windows Security event IDs with meaning, fields and detection notes for triage. SecOpsIT Ops Open → KQL Query Builder Build Microsoft Sentinel / Defender KQL hunting queries from guided building blocks. SecOps Open → RegEx Lab Build and test regular expressions against sample data with a security pattern library. SecOpsIT Ops Open → TokenDecoder — JWT Decode and inspect JWTs and OAuth tokens — header, claims and signature — client-side. SecOpsIT Ops Open → AuthMethods Readiness Analyzer Score Entra MFA / passkey readiness from an authentication-methods registration export. SecOpsGRC Open → SquatWatch — Typosquat Scanner Generate and check look-alike / typosquatted domains for brand-abuse and phishing prep. OSINTSecOps Open → NetRecon — IP / Domain / ASN Pull IP, domain and ASN intelligence for external recon and attack-surface mapping. OSINTIT Ops Open → Email Header Analyzer Parse raw email headers for SOC-grade sender, routing and authentication intelligence. OSINTSecOps Open → TenantRecon — Tenant Attack Surface Map the SaaS and cloud tenant attack surface for a domain — Microsoft 365 and beyond. OSINTSecOps Open → Subdomain Takeover Scanner Scan subdomains for dangling records vulnerable to takeover across common providers. OSINTSecOps Open → CertScout — Certificate Transparency Discover subdomains and infrastructure through certificate-transparency logs. OSINTSecOps Open → TechDetect — Technology Profiler Fingerprint the technology stack behind any website — frameworks, servers and services. OSINT Open →

Frequently asked questions

What is TheAdminStack?

TheAdminStack is a free collection of browser-based cybersecurity and infrastructure tools, plus practical guides, built and maintained by a working security engineer. Every tool lives on one page and can be filtered by discipline: Governance Risk & Compliance (GRC), IT Operations, Security Operations (SecOps) and OSINT.

Are the tools really free?

Yes. Every tool on TheAdminStack is free to use with no account, no sign-up and no paywall. They are built for practitioners who just need to get the job done.

Does my data leave my browser?

The tools are privacy-first. Most run entirely client-side, so the data you enter is not stored or sent to a server. Tools that must query an external source (for example DNS or certificate lookups) only send the minimum needed for that lookup.

How are the tools organised?

All tools are listed on the homepage and tagged by discipline. Use the filter to narrow to GRC, IT Operations, SecOps or OSINT — a tool can appear under more than one discipline where it applies (for example, the SPF/DKIM/DMARC checker is both IT Ops and SecOps).

Who builds TheAdminStack?

TheAdminStack is built by a cybersecurity engineer and systems administrator with 10+ years securing enterprise environments. The site also offers practical guides and is available for security consulting.