Post Title
Post summary description...
The Unyielding Digital Defense Shield
Real-Time Threat Hunting & Incident Response
Empowering SOC analysts, incident responders, and threat hunters with an unyielding security suite: neutralize weaponized IOCs, inspect TLS trust chains, compute cryptographic hashes, audit security headers, calculate CIDR ranges, parse security logs, and forge Sigma & YARA detection rules.
Drop security file to load
Evaluate web server security posture (HSTS, CSP, XFO) and dissect User-Agent strings.
Inspect TLS certificates, validity countdowns, SANs, full certificate chains, cipher suites, and diagnose self-signed or invalid OT certs.
Performing TLS handshake with target socket & extracting X.509 peer state...
Expires in -- days
Standard Root Store
TLS_AES_128_GCM_SHA256
⚡ 0.00 ms handshake
SHA256-RSA
Hierarchical chain presented by the server during TLS handshake (Leaf → Intermediate CAs → Root CA).
Run this command on your terminal or jumpbox to verify the TLS handshake manually during an outage:
Lightning-fast offline IEEE OUI lookup and OT rogue device detector for air-gapped industrial enclaves, SCADA segments, and SOC incident triage.
| Triage / Risk | MAC Address & OUI | Manufacturer / Vendor | Device Classification | Security Assessment / Reason | Actions |
|---|
Convert open Sigma detection rules into native Splunk SPL, KQL, Elastic DSL/Lucene/EQL, QRadar AQL, and craft verified YARA rules.
Synthesize production-ready YARA rules from string signatures, hex byte patterns, or extracted threat IOCs.
| Type | Defanged Value | Original Fanged Value | Logged Date | Copy |
|---|---|---|---|---|
| Loading IOC database records... | ||||
Targeted bitwise decoding and endianness alignment for DNP3 48-bit Time Sync, Modbus 32-bit register pairs (ABCD/CDAB/BADC/DCBA), and IEC 60870-5-104 / IEC 61850 CP56Time2a substation standards.
The CP56Time2a IV (Invalid) bit is set to 1 in byte 3. This proves the RTU, protective relay, or substation clock was unsynchronized / free-running when this timestamp was generated. Incident response chronologies must account for local crystal oscillator drift.
Parse Cisco, Fortinet, Palo Alto, Juniper, HP/Aruba, Netgear, and TP-Link rulebases. Simulate live 5-tuple traffic flows, evaluate first-match and LPM routing, and detect shadowed, redundant, and overlapping anomalies.
| # | Line | Vendor | Source Subnet | Destination Subnet | Proto | Dst Port | Action | Raw Text |
|---|---|---|---|---|---|---|---|---|
| No parsed rules loaded yet. | ||||||||
Pure-Go & WebAssembly extraction engine for Modbus TCP, DNP3, DNS, HTTP, and secret payload carving.
Drop .pcap or .pcapng capture to analyze
100% processed locally in your browser memory
| # | Protocol | Source -> Destination | Function | Addresses / Unit | Payload Summary | OT Safety Risk |
|---|---|---|---|---|---|---|
| No Modbus or DNP3 frames detected. | ||||||
Air-gapped substation & triage engine: factory defaults, protocol ports, and reverse credential lookup
Enter an observed default username and password pair from a triage session, packet capture, or banner grab. The engine will query the embedded index to identify all candidate industrial and enterprise devices that ship with matching factory accounts.
Resolve a TCP/UDP port number to its canonical industrial automation / IT protocol standard (Modbus, DNP3, EtherNet/IP, S7comm, IPMI, BACnet) and explore all default hardware profiles listening on that port.
Dual-execution decoupled decoder, vulnerability scanner (alg: none, key confusion, header injections), cryptographic verifier & offline dictionary cracker.
High-throughput Go worker pool dictionary attack
Modifies Header & Payload in real-time and resigns with a designated key or strips signature.
Live DNS resolver and offline static RFC validator for SPF, DMARC, and DKIM public keys. Evaluates lookup limits, key strengths, alignment policies, and generates an automated phishing spoofability assessment matrix.
Copy and publish these hardened DNS TXT records to achieve DMARC enforcement (p=reject) and prevent domain spoofing.
Team Cymru DNS inversion, RPKI origin validation (ROA), deep RIR RDAP, PeeringDB topology, and infrastructure threat attribution
Cloudflare, Inc.
AWS Elastic Compute Cloud & Infrastructure. Traffic represents customer cloud workloads or reverse proxies.
Cryptographically verified ROA matches origin ASN and max prefix length.
# iptables drop rule
{}
Paste mixed IPs, CIDRs, and ASNs (one per line). Processed concurrently via Go worker pools.
| Query | ASN | AS Name & Org | Prefix | CC | RPKI | Classification | Action |
|---|
Client-side WebAssembly triage: Shannon entropy profiling, 100+ magic byte carving, extension masquerading & PE cryptor detection.
Dual-engine security auditor: Offline multi-vendor static analysis (Cisco, Fortinet, PAN-OS, SolarWinds Orion) and active UDP 161 network prober with CoPP protection.
Active sweeps validate unauthenticated SNMPv3 USM engine discovery, cipher negotiation, and v1/v2c fallback. To avoid saturating device Route Processors or triggering Control Plane Policing (CoPP), this engine applies a token-bucket rate limiter (5 pps/host). Enable Safe Mode when scanning industrial OT subnets containing legacy RTUs or PLCs.
| Severity | Rule ID | Finding Description | Location / Target | Standard Reference | Remediation |
|---|
Automated NIDS signature synthesis: Reassembles TCP streams, scores Shannon entropy anchors, isolates fast patterns, and transpiles to Suricata 7, Snort 3, and Snort 2.9 with sandboxed verification.
# Output will be generated upon dissection...
Multi-factor confidence scoring across header/footer magic bytes, SQLite FTS5 ransom note full-text search, and normalized extension heuristics.
Supports standard extensions, multi-extension ransomware masks (.id[...].[email].ext), and dynamic 5-10 character victim extensions.
Enter an encrypted file extension, paste a ransom note, supply byte markers, or drop an encrypted file to begin multi-factor attribution.
Reads first 512 bytes (Header) and last 4096 bytes (Footer) directly in browser and queries offline database.
| CANONICAL NAME | KNOWN ALIASES | ENCRYPTION DETAILS | DECRYPTOR AVAILABILITY | MITRE ID |
|---|---|---|---|---|
| Loading catalog... | ||||
Analysis summary and verdict description.
| # | Label / Filename | Magic Type | Payload Size | SHA-256 Digest | Actions |
|---|
| Path / Name | Size | Entropy | MIME Type | Header Preview | Action |
|---|
Magen (Hebrew for Shield) is an advanced, unified cyber defense, threat intelligence, and digital forensics workstation. Built for Security Operations Center (SOC) analysts, incident responders, threat hunters, penetration testers, and Operational Technology (OT/ICS) plant engineers, Magen delivers instant, sub-millisecond security operations with zero data leakage, air-gapped readiness, and uncompromising cryptographic rigor.
Computationally heavy operations—such as PCAP packet dissection, Shannon binary entropy computation, and file signature carving—run client-side via compiled WebAssembly and Web Workers. Packet streams and proprietary binaries never leave your local browser sandbox.
Magen is engineered with an offline-first architecture. It features service-worker caching, local SQLite indexing via FTS5, and zero third-party telemetry, allowing full deployment in isolated nuclear plants, defense environments, or sea vessels.
When live network handshakes are required (e.g. SNI certificate inspection, BGP ASN RDAP resolution, Team Cymru DNS queries), our Go backend leverages goroutines and non-blocking sockets to complete audits in under 5 milliseconds.
Tools designed for active indicator extraction, rule compilation, and indicator vault management
Safely extracts, neutralizes (defangs), and restores (refangs) suspicious Indicators of Compromise (IOCs) across raw text, phishing emails, malware logs, and forensic artifacts. Defanging replaces live protocols and dots with harmless brackets (e.g., hxxps[://]malware[.]site) to prevent accidental execution, malicious web browser clicks, or automated link preview expansion in communication platforms.
http, https, ftp), and email addresses.Universal detection engineering studio that bridges the gap between generic Sigma detection rules and enterprise SIEM/EDR platforms. In addition, the integrated YARA Studio allows threat hunters to craft and generate custom binary and memory detection signatures using plain strings, hexadecimal sequences, wildcards, and compound boolean condition logic.
Centralized local SQLite repository and threat intelligence vault that indexes, stores, filters, and correlates all indicators extracted across your investigation sessions. Designed for persistent case management and rapid correlation across multi-day incident response engagements.
Offline database and reverse-lookup directory of factory default passwords, management ports, and service mappings for industrial automation hardware (PLCs, RTUs, SCADA human-machine interfaces), enterprise network switches, firewalls, and server Baseboard Management Controllers (iLO/iDRAC).
Automate NIDS signature generation from PCAP captures, hex streams, and PCRE with real-time AST transpilation between Suricata 7, Snort 3, and Snort 2.9. Features fast_pattern hardware acceleration, Shannon entropy payload scoring, and sandboxed test replay.
Tools for cryptographic hash generation, payload deobfuscation, and JWT vulnerability testing
Multi-algorithm cryptographic hashing utility, file digest calculator, and automated unknown hash identification engine with Shannon entropy scoring.
CyberChef-style payload transformation workbench for dissecting obfuscated malware commands, shellcode, and web exploit injection strings.
Dual-execution JSON Web Token security inspector, vulnerability scanner, cryptographic verifier, and offline secret key dictionary cracker.
alg:none (CVE-2015-9235), HMAC/RSA key confusion, weak secrets, and injection flaws.Tools for IP subnetting, BGP/ASN routing intelligence, multi-vendor firewall ACL audit, and rogue MAC detection
Comprehensive IPv4 and IPv6 subnetting workbench that calculates network boundaries, broadcast addresses, usable host ranges, binary representations, wildcard masks, and hierarchical subnet division trees.
Ultra-fast IP-to-Autonomous System Number (ASN) mapping and routing intelligence workbench. Integrates Team Cymru DNS resolutions, RPKI origin validation (ROA), Regional Internet Registry (RIR) RDAP records, PeeringDB facility peering, and automated firewall rule generation.
Multi-vendor firewall configuration parser, 5-tuple packet flow simulator, and policy anomaly detection engine. Dissects complex enterprise rulebases to identify security vulnerabilities, misconfigurations, and rule bloat.
Zero-allocation, in-memory MAC Organizationally Unique Identifier (OUI) lookup and rogue device detection engine tailored for air-gapped industrial automation networks (ICS/SCADA), smart grid substations, and enterprise SOC network triage.
Dual-engine offline configuration linter and active UDP 161 network auditor. Evaluates Cisco, Fortinet, Palo Alto, and SolarWinds SNMP configurations against NIST SP 800-41 and CIS controls, detecting plaintext SNMPv1/v2c fallback, weak MD5/DES ciphers, and unauthenticated engine exposure.
Tools for HTTP security header inspection, SSL/TLS certificate chain auditing, and email authentication linter
Audits HTTP response security headers for OWASP compliance and dissects User-Agent strings to flag web scrapers, bots, and vulnerability scanners.
Inspects live and offline X.509 TLS/SSL certificates, validity countdowns, Subject Alternative Names (SANs), trust chains, and cipher suite support.
Live DNS resolver and static RFC record linter for SPF (RFC 7208), DMARC (RFC 7489), and DKIM (RFC 6376) with automated spoofability risk scoring.
p=reject/quarantine/none and alignment modes (aspf, adkim).Tools for SCADA telemetry timestamps, in-browser PCAP dissection, and binary file entropy carving
Specialized ICS/SCADA telemetry timestamp converter for incident reconstruction across power grids, water treatment plants, and industrial substations.
Zero-dependency packet capture analysis and protocol dissector powered by client-side WebAssembly for safe inspection without Wireshark dependencies.
Client-side binary forensics analyzer running via WebAssembly and Web Workers to detect packed executables, ransomware payloads, and file masquerading.
Offline-first ransomware strain identification via multi-factor confidence scoring across header/footer byte markers, SQLite FTS5 ransom note full-text search, and normalized extension matching.
In-browser, zero-dependency malicious document extractor running inside an air-gapped WebAssembly sandbox. Decompresses OLE2/CFBF, OOXML, MS-OVBA VBA macros, BIFF8 Excel 4.0 XLM formulas, and carves \x01Ole10Native binaries.
Comprehensive operational manual, RFC standards, input specifications, security interpretation guides, and privacy guarantees for every tool in the Magen Defense Suite.
#tools/ioc-defanger
When sharing threat intelligence across ticketing platforms (Jira, ServiceNow), chat systems (Slack, Teams), email, or documentation, live malicious URLs and IP addresses can accidentally trigger automated crawlers, link prefetchers, or accidental analyst clicks. Defanging neutralizes active indicators into inert representations (e.g. replacing 'http://' with 'hxxp://' and '.' with '[.]'). Magen employs a ReDoS-safe linear regex engine that guarantees bounded-time parsing even against multi-megabyte adversarial payloads.
Subject: URGENT: Ransomware Delivery Detected From: billing@invoice-malicious-update.com We observed outbound C2 traffic to http://malicious-c2-server.evil.ru/payload.exe Originating IP: 185.220.101.5 and secondary gateway 192.168.1.100. Dropped binary SHA256: 2c54f6b53a4c0288b50d640b61d0b81333d66a6c500000000000000000000000 Related vulnerability: CVE-2024-3400.
Categorized IOCs: - URLs: hxxp://malicious-c2-server[.]evil[.]ru/payload[.]exe - Domains: invoice-malicious-update[.]com, malicious-c2-server[.]evil[.]ru - IPv4: 185[.]220[.]101[.]5 (Public C2), 192[.]168[.]1[.]100 (RFC 1918 Private) - Emails: billing[@]invoice-malicious-update[.]com - Hashes: 2c54f6b53a4c0288b50d640b61d0b81333d66a6c500000000000000000000000 (SHA-256) - CVEs: CVE-2024-3400
Review extracted indicators against internal EDR and firewall logs. Use defanged representations in ticketing notes to prevent link detonation. Public IPs should be checked against threat intel feeds; private RFC 1918 IPs represent compromised internal hosts requiring immediate forensic isolation.
#tools/hash-tool
Digital forensics and incident response rely heavily on cryptographic checksums to establish evidence chain-of-custody, detect binary tampering, and correlate malware samples against threat intelligence repositories like VirusTotal. Identifying unknown hash formats (e.g. Bcrypt, NTLM, MD5, SHA-256) is vital during credential audits and memory dump triage.
admin@magen-defense-system-2026
- MD5: 5d41402abc4b2a76b9719d911017c592 - SHA-1: 7c4a8d09ca3762af61e59520943dc26494f8941b - SHA-256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 - SHA-512: cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e - NTLM: 31d6cfe0d16ae931b73c59d7e0c089c0 - Shannon Entropy: 4.12 bits/char
SHA-256 and SHA-512 are industry standards for malware correlation and code signing. MD5 and SHA-1 should not be used for cryptographic signatures due to collision attacks (RFC 6151), but remain common for legacy file indexing. NTLM hashes are vulnerable to pass-the-hash and offline cracking.
#tools/cidr-calculator
Network micro-segmentation, firewall rule authoring, and penetration test scope validation depend on precise subnet boundaries. Miscalculating a CIDR boundary can lead to unintentional scanning of out-of-scope production assets or creating overly permissive firewall rules allowing lateral movement.
10.240.0.0/21
- Network Address: 10.240.0.0 - Broadcast Address: 10.240.7.255 - Usable Host Range: 10.240.0.1 - 10.240.7.254 - Total Hosts: 2,048 - Usable Hosts: 2,046 - Subnet Mask: 255.255.248.0 - Wildcard Mask: 0.0.7.255 - Scope: RFC 1918 Private Network - Binary Mask: 11111111.11111111.11111000.00000000
Use the Usable Host Range to restrict automated vulnerability scanners. Use the Wildcard Mask directly in Cisco access-list commands. Notice that /31 subnets (RFC 3021) are designated for point-to-point links and have 2 usable addresses with no broadcast address.
#tools/encoder-decoder
Adversaries constantly obfuscate command-line arguments, PowerShell scripts, web shells, and C2 beacons using multi-layered encoding schemes (e.g. Base64 inside URL-encoding, or XOR with a static 1-byte key). Rapid deobfuscation is critical for security analysts decoding exploit payloads in proxy logs, web application firewalls (WAF), and endpoint telemetry.
cG93ZXJzaGVsbC5leGUgLW5vcCAtZSAgLVdjIFtoaWRkZW5d
powershell.exe -nop -e -Wc [hidden]
Look for secondary encoding inside the output (such as another Base64 blob following `-e` or `-EncodedCommand`). In PowerShell, encoded commands are UTF-16LE formatted. In XOR analysis, look for common plaintext markers such as 'MZ', 'HTTP', 'cmd.exe', or 'This program cannot be run in DOS mode'.
#tools/header-analyzer
Missing security headers expose web applications to Clickjacking, cross-site scripting (XSS), MIME-type confusion attacks, and insecure transport downgrade. Furthermore, web server access logs often contain spoofed or automated User-Agents from vulnerability scanners (Nmap, Nikto, Sqlmap, Burp Suite) that SOC analysts must identify quickly.
HTTP/1.1 200 OK Server: Apache/2.4.41 (Ubuntu) X-Powered-By: PHP/7.4.3 X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000; includeSubDomains Content-Type: text/html; charset=UTF-8
Security Grade: C+ (Moderate Risk) - HSTS: PASS (max-age=31536000, includeSubDomains) - X-Frame-Options: PASS (SAMEORIGIN) - Content-Security-Policy (CSP): FAIL (Missing - High XSS Exposure) - X-Content-Type-Options: FAIL (Missing 'nosniff') - Information Disclosure Warning: 'Server' and 'X-Powered-By' leak exact OS and PHP version.
Immediately add 'Content-Security-Policy' and 'X-Content-Type-Options: nosniff'. Strip the 'Server' and 'X-Powered-By' headers in your reverse proxy to prevent automated vulnerability scanners from targeting known PHP/Apache CVEs.
#tools/cert-checker
Expired or misconfigured TLS certificates cause catastrophic service outages, break encrypted telemetry pipelines, and expose users to man-in-the-middle (MITM) attacks. In industrial OT/SCADA environments, plant gateways often use self-signed certificates or private CAs that require specific certificate thumbprint validation.
magen-defense.internal:443
- Common Name (CN): magen-defense.internal - Issuer: Let's Encrypt Authority X3 / Private Root CA - Valid From: 2026-01-01 00:00:00 UTC - Valid To: 2026-12-31 23:59:59 UTC (130 days remaining) - Subject Alternative Names (SANs): magen-defense.internal, *.magen-defense.internal, api.magen-defense.internal - Key: RSA 2048-bit (SHA-256 with RSA) - SHA-256 Fingerprint: 3e9d8f... - Status: VALID / TRUSTED
Ensure certificates with under 30 days remaining are renewed immediately. Check SANs to uncover shadow infrastructure or unexpected aliases. For OT devices, compare the SHA-256 fingerprint with the factory-provisioned key to detect rogue rogue MITM proxies.
#tools/mac-lookup
Attackers or unauthorized contractors who connect unauthorized laptops, rogue Wi-Fi access points, or malicious Raspberry Pi drops to OT/SCADA control networks often use standard commercial NICs or randomized MAC addresses. Quickly mapping MAC addresses to vendors and spotting Locally Administered Addresses (LAAs) is essential for perimeter defense.
00:1B:1B:3A:45:67 02:42:AC:11:00:02 00:80:F4:11:22:33
1. 00:1B:1B:3A:45:67 -> Vendor: Siemens AG (OT/ICS Automation - SIMATIC S7 PLC) 2. 02:42:AC:11:00:02 -> Vendor: Locally Administered (Randomized / Virtual Container / Docker) 3. 00:80:F4:11:22:33 -> Vendor: Telemecanique / Schneider Electric (Modicon PLC)
If a commercial laptop NIC (e.g. Intel, Apple, Realtek) or a Locally Administered (Randomized) MAC appears on a strictly isolated SCADA Level 1/Level 2 control network (Purdue Model), trigger an immediate rogue device investigation.
#tools/sigma-converter
Sigma is the open generic signature format for SIEM detection rules. Threat intelligence reports often release detection engineering rules in Sigma YAML. SOC engineers must rapidly convert these generic rules into the specific query dialect used by their SIEM (Splunk, Microsoft Sentinel, Elasticsearch, QRadar) or build YARA signatures for endpoint file scanning.
title: Suspicious PowerShell Download
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- 'DownloadString'
- 'Net.WebClient'
condition: selection
// Microsoft Sentinel / Defender KQL:
DeviceProcessEvents
| where FolderPath endswith @"\powershell.exe" or ProcessCommandLine has_any ("DownloadString", "Net.WebClient")
// Splunk SPL:
index=* (Image="*\\powershell.exe" AND (CommandLine="*DownloadString*" OR CommandLine="*Net.WebClient*"))
Copy the compiled query directly into your SIEM hunt window or detection pipeline. Verify the field mappings (e.g. `Image` vs `FolderPath`) against your SIEM schema.
#tools/database
During incident response engagements, analysts process thousands of indicators across multiple tool runs. Having a unified, air-gapped local threat database allows SOC analysts to query past sightings, correlate recurring threat actors, and export clean blocklists for firewall and EDR deployment.
malware-c2-rat OR CVE-2024
14 Matching IOCs found: 4 Domains, 6 IPs, 3 Hashes, 1 CVE. Confidence: High (90%).
Exported indicators can be fed into firewall IP blocklists or SIEM lookup tables. Review First-Seen and Last-Seen dates to determine if an indicator is part of an ongoing active intrusion or historical campaign.
#tools/ot-time
In critical infrastructure (electric power grids, substations, water utilities, oil & gas pipelines), SCADA historians and RTUs record operational events using specialized binary timestamp formats. Investigating cyber-physical attacks (like Industroyer or BlackEnergy) requires reconstructing sequence-of-events (SOE) logs with sub-millisecond precision.
00 80 4D 5B 8D 01 (DNP3 48-bit Hex)
- Protocol: DNP3 48-Bit Timestamp - Raw Milliseconds: 1708688400000 ms - UTC Time: 2024-02-23 11:40:00.000 UTC - ISO 8601: 2024-02-23T11:40:00.000Z - Sync Quality: Synchronized (Internal clock valid)
Compare decoded SOE event timestamps between substation relays and the control center SCADA historian. If the CP56Time2a 'Invalid (IV)' flag is set, the RTU lost GPS time synchronization, indicating potential GPS spoofing or loss of NTP connectivity.
#tools/acl-checker
Enterprise and industrial firewalls accumulate thousands of rules over time. Shadowed rules (unreachable rules blocked by earlier broad rules), redundant rules, and overly permissive 'permit any any' rules weaken security postures and create compliance violations during NIST/NERC-CIP audits.
access-list 101 permit ip 10.0.0.0 0.255.255.255 192.168.1.0 0.0.0.255 access-list 101 deny tcp 10.10.10.0 0.0.0.255 192.168.1.0 0.0.0.255 eq 22 access-list 101 permit tcp any any eq 80 access-list 101 deny ip any any
Policy Audit Report:
- CRITICAL ANOMALY: Rule #2 ('deny tcp 10.10.10.0/24 to 192.168.1.0/24 eq 22') is SHADOWED by Rule #1 ('permit ip 10.0.0.0/8 to 192.168.1.0/24'). Rule #2 will NEVER be evaluated!
- Evaluation: SSH traffic from 10.10.10.5 will be PERMITTED by Rule #1 instead of denied.
Shadowed rules represent critical configuration mistakes where an intended deny policy is nullified by an earlier permissive rule. Reorder rules so that more specific subnet/port restrictions precede broader network permits.
#tools/pcap-extractor
Packet captures (PCAPs) contain raw network truth during cyber incidents. However, uploading proprietary PCAPs to external cloud analyzers leaks sensitive credentials, network architecture, and customer data. Magen provides an in-browser WebAssembly packet dissection engine that triages network traffic with zero server upload.
[Drop capture file: modbus_write_register_attack.pcap]
Dissected Packets (Sample): - Packet #14: Modbus TCP | Unit ID: 1 | Func: 0x06 (Write Single Register) | Register: 40001 | Value: 0x2710 (10000 RPM) - Packet #15: Modbus TCP | Response OK - Carved Secret: Basic YWRtaW46U2NhZGFQYXNzIQ== -> 'admin:ScadaPass!'
Look for unauthorized Modbus Write commands (Function 0x06 or 0x10) targeting safety-critical PLC registers. Check the Carved Secrets tab for plaintext basic authentication headers or Telnet credentials sent over unencrypted links.
#tools/default-creds
Factory default credentials are one of the most common Initial Access and Lateral Movement vectors (MITRE ATT&CK T1078). Equipment in industrial plants and server rooms (PLCs, smart switches, IPMI/iLO/iDRAC management controllers) frequently remain configured with factory passwords.
Vendor: 'Moxa' OR Port: '502'
Matching Entries: - Vendor: Moxa | Model: NPort 5110 / 5150 Device Server | User: admin | Pass: moxa | Protocol: HTTP / Telnet (Port 80/23) - Port 502: Modbus TCP (Industrial Automation Protocol - Typically unauthenticated)
Ensure any device discovered with factory credentials during an audit has its default password immediately replaced with a high-entropy credential stored in an enterprise PAM solution.
#tools/jwt-inspector
JSON Web Tokens (JWTs) are the de facto standard for stateless authentication in modern cloud microservices and APIs. Misconfigurations—such as accepting `alg: 'none'`, weak HMAC shared secrets, or vulnerability to RSA-to-HMAC key confusion attacks (CVE-2015-9235)—allow attackers to forge authentication tokens and escalate privileges to admin.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTYiLCJuYW1lIjoiQWRtaW4iLCJyb2xlIjoiYWRtaW4iLCJleHAiOjE3NzE4NDAwMDB9.k_b5gP...
- Algorithm: HS256 (HMAC-SHA256)
- Payload Claims: { "sub": "123456", "name": "Admin", "role": "admin", "exp": 1771840000 (Active) }
- Vulnerability Linter:
* Algorithm Integrity: SECURE (Uses HS256, not none)
* Expiration Check: VALID (Token expires in 142 days)
* Dangerous Headers: NONE (`jku`/`jwk` absent)
Ensure tokens use asymmetric RS256/ES256 signatures or strong, 256-bit+ random HMAC keys. Never accept tokens with `alg: none` or allow client-controlled `jku` header URLs without strict domain allowlisting.
#tools/email-auth
Business Email Compromise (BEC) and domain spoofing phishing attacks cost organizations billions of dollars annually. Proper configuration of SPF, DKIM, and DMARC is the foundation of domain reputational defense, ensuring that threat actors cannot forge emails claiming to originate from your organization.
example-defense.org
- Domain: example-defense.org - SPF Record: v=spf1 include:_spf.google.com ~all (PASS - 3 DNS lookups, SoftFail) - DMARC Record: v=DMARC1; p=reject; rua=mailto:dmarc-reports@example-defense.org; pct=100 (HARDENED) - MX Records: aspmx.l.google.com (Priority 1), alt1.aspmx.l.google.com (Priority 5) - Spoofability Risk: LOW (Protected against unauthorized sender domain spoofing)
Domains with `p=none` allow attackers to send spoofed emails that land directly in victim inboxes. Migrate policies through `p=quarantine` and ultimately enforce `p=reject` with 100% percentage rollout (`pct=100`).
#tools/bgp-mapper
Adversaries host bulletproof hosting infrastructure, C2 servers, and phishing nodes in specific Autonomous Systems (ASNs). Furthermore, BGP route hijacking and misconfigurations can reroute corporate traffic through hostile nations. Analyzing IP-to-ASN routes and verifying RPKI Route Origin Authorization (ROA) is vital for threat attribution and network perimeter defense.
185.220.101.5
- IP: 185.220.101.5 - Origin ASN: AS205100 (F3 Netze e.V.) - BGP Announced Prefix: 185.220.101.0/24 - Country: DE (Germany) - RIR: RIPE NCC (Allocated: 2017-09-12) - RPKI Status: VALID (Authorized ROA published) - Category: Known Bulletproof / Tor Exit Relay Node
Use the origin ASN to attribute threat actors and identify bulletproof hosting providers. Generate firewall rules blocking the entire ASN if the network is repeatedly used for malicious campaigns.
#tools/file-entropy
Malware authors use packers (UPX, Themida, VMProtect) and custom encrypters to obfuscate malicious executable code from static antivirus signatures. Packed and encrypted files exhibit abnormally high Shannon entropy ($H > 7.2$ bits/byte). Furthermore, phishing lures often disguise executable binaries with fake document extensions (`invoice.pdf.exe`).
[Drop sample: suspicious_invoice_downloader.exe]
- File Size: 1,248,512 bytes (1.19 MB) - Magic Header: 4D 5A 90 00 -> PE32 Executable (Windows GUI) - Overall Entropy: 7.78 / 8.00 bits/byte (VERY HIGH - Packed or Encrypted) - Packer Heuristic: POSITIVE (UPX / Section header '.upx1' detected) - Extension Match: MATCH (Executable file with .exe extension) - Assessment: SUSPICIOUS / MALICIOUS PACKER DETECTED
A Shannon entropy score exceeding $7.2$ in standard executables strongly suggests binary packing, encryption, or compressed payloads. In document formats (like PDF or Office), high entropy in isolated chunks may indicate embedded shellcode or encrypted exploits.
#tools/snmp-lint
SNMPv1 and SNMPv2c transmit community strings in cleartext plaintext across management networks, leaving switches, routers, and firewalls vulnerable to eavesdropping, network reconnaissance, and unauthorized reconfiguration. Even when SNMPv3 is deployed, misconfigurations—such as utilizing `noAuthNoPriv`, weak MD5 hashing, DES 56-bit encryption, or omitting Control Plane Policing (CoPP)—severely compromise network infrastructure.
snmp-server community public RO snmp-server group SECGROUP v3 priv snmp-server user netadmin SECGROUP v3 auth sha MyAuthPass123 priv des WeakPrivPass456
[CRITICAL] Plaintext SNMPv2c Community String Active Line 1: 'snmp-server community public RO' Remediation: 'no snmp-server community public' [HIGH] Insecure DES Encryption Algorithm Configured Line 3: User 'netadmin' utilizes DES (56-bit key length) Remediation: Upgrade privacy algorithm to AES-256: 'snmp-server user netadmin SECGROUP v3 auth sha ... priv aes 256 ...' [MEDIUM] Missing SNMP Access Control List (ACL) Remediation: Bind SNMP access to dedicated out-of-band management subnet ACL
All modern network security frameworks (including NIST SP 800-41 and CIS Controls) mandate disabling SNMPv1 and SNMPv2c entirely. Where SNMPv3 is deployed, authPriv mode with SHA-256 authentication and AES-128/256 encryption is the required cryptographic minimum.
#tools/rule-forge
Crafting high-fidelity NIDS rules during live incident triage requires balancing signature specificity against sensor performance. Sub-optimal rules cause packet drops, excessive CPU utilization, or catastrophic Regular Expression Denial of Service (ReDoS). Furthermore, enterprise SOCs frequently maintain mixed sensor fleets running Suricata 7 and Snort 3, necessitating error-free rule translation across dialect boundaries.
POST /api/v1/telemetry HTTP/1.1 Host: malware-c2-beacon.top User-Agent: WinHTTP-Direct/1.0 X-Session-Token: 0xDEADBEEF1337 Content-Length: 32 payload=encrypted_hex_stream_data
# Suricata 7 Signature alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC WinHTTP Beacon Observed"; flow:established,to_server; content:"POST"; http.method; content:"/api/v1/telemetry"; http.uri; fast_pattern; content:"Host|3a 20|malware-c2-beacon.top"; http.header; classtype:trojan-activity; sid:2048991; rev:1;) # Snort 3 Signature alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC WinHTTP Beacon Observed"; flow:established,to_server; content:"POST",http_method; content:"/api/v1/telemetry",http_uri,fast_pattern; content:"Host|3a 20|malware-c2-beacon.top",http_header; classtype:trojan-activity; sid:2048991; rev:1;)
Marking the lowest-entropy and most specific string with `fast_pattern` ensures the Hyperscan engine checks that substring first across multi-gigabit packet streams, avoiding expensive secondary option evaluations.
#tools/ransom-id
During active ransomware attacks, incident responders must immediately establish the ransomware strain, ascertain if public decryptors exist (e.g., from No More Ransom), identify threat actor TTPs, and execute containment procedures before offline backups or Active Directory domain controllers are destroyed.
Extension: .lockbit Note File: restore-my-files.txt Note Content: "All your files have been stolen and encrypted by LockBit 3.0. Decryption tool is available only through our Tor portal: http://lockbitapt...onion"
[CONFIDENCE: 98% MATCH] Family: LockBit 3.0 (Black) Threat Actor: FIN11 / LockBit Supporter Group Encryption: AES-256-CBC + Curve25519 (Hybrid) Decryptor Available: Partial / Key Recovery Tool (Free) MITRE ATT&CK: T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery) Immediate Action: 1. Disconnect all vSphere/Hyper-V hosts and ESXi management NICs. 2. Prevent lateral movement via SMB (Port 445) and WMI (Port 135). 3. Secure volume shadow copies and offline immutable backups.
Never negotiate or pay ransoms without consulting specialized legal and incident response counsel. Immediate network segmentation and snapshot preservation are paramount during the first 60 minutes of detection.
#tools/maldoc-extractor
Weaponized Office documents (`.doc`, `.docm`, `.xls`, `.xlsm`, `.rtf`) remain a premier initial access vector for targeted malware delivery. Threat actors evade standard scanners by hiding VBA macros inside OLE2 compound files, embedding legacy Excel 4.0 XLM macro sheets, or packing malicious `.exe` / `.dll` payloads inside embedded `\x01Ole10Native` compound streams.
[Drop file: invoice_mar_2026.docm (Size: 48,210 bytes)] Built-in synthetic test fixtures available: - Sample 1: OLE2 Legacy Word with VBA Macro (sample_ole2_vba.doc) - Sample 2: OOXML Macro-Enabled Document (sample_ooxml_macro.docm) - Sample 3: OLE10Native Embedded PE Dropper (sample_ole10native_pe.doc) - Sample 4: Excel 4.0 (XLM) Hidden Sheet Macro (sample_xlm_hidden.xls)
[THREAT LEVEL: HIGH - MALICIOUS HEURISTICS DETECTED] Document Type: Microsoft Word 97-2003 (OLE2 / CFBF) Streams Extracted: 6 (VBA project, Dir, Macros/ThisDocument) Suspicious APIs Detected: - AutoOpen() -> Automatic execution on document launch (MITRE T1204.002) - WScript.Shell -> Shell execution capability (MITRE T1059.005) - URLDownloadToFileA -> Remote stage 2 binary fetch (MITRE T1105) Embedded Objects: - \x01Ole10Native: Dropper payload carved (invoice_payload.exe, 18,432 bytes, PE32)
Decompressing macro streams without invoking the Office execution environment provides guaranteed safety against macro detonation, zero-day Office CVEs, and dropper execution.
Post summary description...
Explore articles in this domain
Zero raw data collection & local derived telemetry policy
We do not collect, store, or log any raw data submitted for analysis. We only collect and store the structured results, analytical artifacts, and telemetry derived from the processing of that data.
Any files, captures, credentials, or text submitted into the Magen tool suite are processed strictly in-memory or executed entirely client-side:
To provide incident response history, threat correlation, and compliance auditing, the platform stores only derived outcomes:
All derived indicators and audit metrics reside in your self-hosted SQLite repository or local browser IndexedDB cache. No telemetry is shared with external third parties. You may export or purge all records at any time via the Threat Database interface.
Data ownership warranty & terms of authorized usage
Magen Cybersecurity and its operators are NOT responsible for users submitting, uploading, or analyzing data, files, credentials, or telemetry that they do not own or are not legally authorized to possess and process.
You bear sole, exclusive responsibility for verifying that you hold full legal title, ownership, or express written authorization for all submitted payloads, captures, credentials, hashes, logs, and configurations.
By submitting data to any tool or API across the Magen suite, you represent and warrant that:
The platform is designed exclusively for authorized defensive cybersecurity operations:
Unlawful network disruption, weaponization of exploits, unauthorized reconnaissance against third parties, and submission of proprietary data without ownership are strictly prohibited. Users agree to indemnify and hold harmless Magen Cybersecurity from any third-party claims, liabilities, or regulatory actions resulting from unauthorized data submissions.
Incident response alert opt-in & communications consent form
Authorize Magen Cybersecurity to deliver high-priority security notifications, active incident response dispatches, critical threat advisories, and system verification tokens directly to your verified email and mobile device.
Consent active & logged in compliance store
Standard message & data rates may apply for SMS. Message frequency varies based on threat levels. You may revoke SMS authorization at any time by replying STOP. For email, click the Unsubscribe link at the bottom of any dispatch. No promotional spam is ever sent.
Instant on-demand compute credits via Stripe