Free browser-based tools for SOC analysts and detection engineers
SecOps Tools is a small, focused collection of security-operations utilities that run entirely in your browser — no account, no API key, and nothing sent to a server. They are built for the day-to-day work of SOC analysts, detection engineers, and blue teams: triaging alerts, writing hunting queries, parsing logs, and inspecting tokens.
The Windows Event ID Lookup is a searchable reference for 220+ Security, Sysmon, PowerShell, System, and Application event IDs, each mapped to MITRE ATT&CK techniques with attack context, detection notes, and Sigma rule stubs. The KQL Query Builder assembles valid Kusto queries for Microsoft Sentinel and Defender XDR Advanced Hunting, with the right schema and time column per product and ATT&CK-tagged starter templates.
The RegEx Lab is a regex tester built for logs and secrets — live match highlighting, capture-group inspection, substitution, flavor-aware portability linting, and a ReDoS (catastrophic backtracking) detector that runs matching in a sandboxed worker. The TokenDecoder decodes and inspects JWT, SAML, and OIDC tokens, flags expiry and security risks, and verifies RS256/ES256 signatures against the issuer JWKS.
Looking for related tooling? Explore the companion OSINT Tools, GRC Tools, and IT Ops Tools suites on theadminstack.com.
Also see: OSINT Tools (SquatWatch typosquatting scanner, Email Header Analyzer) · GRC Tools · IT Ops Tools · theadminstack.com