The Analyst Toolkit
Every tool on this page has been used or evaluated by Jen. No sponsorships, no affiliate links. Just the real ones.
TIPs
Ordered by ease of implementation (Jen's opinion).
Capability Reference
Quick-reference matrix for what each tool can handle. Great for bookmarking.
IOC Query & Enrichment
| Tool | Free | Hash | IP | Domain | URL | Sandbox | Passive DNS | Enrichment |
|---|---|---|---|---|---|---|---|---|
| VirusTotal ↗Malware and URL scanning and threat intelligence | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Pulsedive ↗Enrich and research IOCs and threats | ✓ | – | ✓ | ✓ | ✓ | – | ✓ | ✓ |
| Shodan ↗Search engine for internet-connected devices | ✓ | – | ✓ | ✓ | – | – | ✓ | ✓ |
| AlienVault OTX ↗Community-powered threat intel sharing. Noisy, proceed with caution. | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ | ✓ |
| GreyNoise ↗Context for IPs scanning the internet | ✓ | – | ✓ | – | – | – | ✓ | ✓ |
| AbuseIPDB ↗Inspect and report malicious IPs | ✓ | – | ✓ | ✓ | – | – | – | ✓ |
Capabilities may be limited on free versions
Want to go deeper on ASN data specifically? Jen contributed to Feedly's guide on using ASN data for threat detection.
Malware Analysis & Sandboxes
| Tool | Free | Hash | IP | Domain | URL | Sandbox | Passive DNS | Enrichment |
|---|---|---|---|---|---|---|---|---|
| Hybrid Analysis ↗Community malware analysis service | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ |
| Any.Run ↗Interactive malware sandbox | ? | ✓ | ✓ | ✓ | ✓ | ✓ | – | ✓ |
| Browserling ↗Run and test URLs in live browser sandboxes | ✓ | – | – | – | – | ✓ | – | – |
| Joe Sandbox ↗Advanced malware analysis and threat detection | – | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Cuckoo Sandbox ↗Open-source automated malware analysis | ✓ | – | ✓ | ✓ | ✓ | ✓ | – | ✓ |
Capabilities may be limited on free versions
More Tools Jen Uses Sometimes
| Tool | Free | Hash | IP | Domain | URL | Sandbox | Passive DNS | Enrichment |
|---|---|---|---|---|---|---|---|---|
| Maltego ↗Graph-based link analysis for OSINT investigations | ✓ | ✓ | – | ✓ | ✓ | – | – | ✓ |
| SpiderFoot ↗Automated OSINT collection and correlation | ✓ | ✓ | ✓ | ✓ | ✓ | – | – | ✓ |
| urlscan.io ↗Scan and visually inspect URLs for threats | ✓ | ✓ | – | ✓ | ✓ | ✓ | – | ✓ |
| Cisco Talos ↗Threat intelligence and reputation data | ✓ | – | ✓ | ✓ | ✓ | ✓ | – | ✓ |
| deobfuscate.relative.im ↗Lightweight tool to deobfuscate malicious JavaScript | ✓ | – | – | – | – | – | – | ✓ |
| MXToolbox ↗Domain/IP reputation, mail server checks, and DNS tools | ✓ | ✓ | – | ✓ | ✓ | – | ✓ | ✓ |
| Ghidra ↗NSA's open-source software reverse engineering framework | ✓ | – | ✓ | – | – | – | – | ✓ |
Capabilities may be limited on free versions
ATT&CK Mapping & Rule Writing
For turning intel into actual detections.
Visualize and annotate ATT&CK coverage: what techniques you detect, what you don't, and where the gaps are.
Pattern-matching rules for identifying and classifying malware samples. The standard for file-based detection.
A generic, tool-agnostic rule format for log-based detections, translatable into most major SIEM query languages.
Missing a tool that should be here? Jen's always looking to expand this list.
Suggest a tool →