Protego field desk
PROTEGO / FIELD MANUALISSUE 08.26

Security instruments for the open web

16 practical instruments for security engineers, cloud operators, and developers. Passive, privacy-focused, free.

16 instruments
No registration required
Privacy focused
Free access
New issue

Recently commissioned instruments

01
New issue

Phishing Email Checker

Is this email phishing? Forward the suspicious message and receive a technical risk report covering authentication, look-alike domains, links, QR codes, attachments, and scam language. The original email is deleted after the check.

Open instrument
02
New issue

Document Sanitizer

Upload a PDF, Word, Excel, PowerPoint, or image file. We rebuild its visible pages as a flattened PDF, removing macros, embedded scripts, OLE objects, and clickable link behavior. Free, no login.

Open instrument
03
New issue

Conditional Access Gap Analyzer

Paste your exported Entra ID Conditional Access policies and get an A-F grade against 18 Microsoft best practice checks: MFA coverage, legacy auth, device code flow, break-glass exclusions. 100% client-side, nothing uploaded.

Open instrument
04
New issue

Agent Skill Validator

Scan any agent skill repository for prompt injection, malicious scripts, hardcoded secrets, and quality issues. Get a safety grade with detailed findings. Free, no login.

Open instrument
05
New issue

Password Breach Check

Check if a password appears in a known data breach, against the Have I Been Pwned database of 800M+ compromised passwords. Runs entirely in your browser via k-anonymity: your password is never sent or stored.

Open instrument
06
New issue

Cloud Security Recon

Passive cloud posture scan for Azure, AWS, GCP, Vercel, Netlify, and 8 more platforms. Detects Kudu exposure, S3 leaks, preview deploys, service account secrets, and WAF quality. No credentials needed.

Open instrument
07
New issue

CVE Lookup

Search any CVE by ID or keyword. Pull live severity, CVSS score, attack vector, and references from NIST NVD. No login required.

Open instrument
08
New issue

Prompt Injection Tester

Map your AI system prompt guardrails against 10 common injection patterns. Get a coverage score and exact hardening guidance. Free, no login.

Open instrument
09
New issue

Domain Security Report

Full passive security report for any domain: SSL, security headers, email security, technology stack, known CVEs, and subdomains. Nothing uploaded.

Open instrument
10
New issue

Email Security Checker

Test if your domain is vulnerable to email spoofing. Check SPF, DMARC, DKIM, and MTA-STS records instantly. Get a clear verdict and fix recommendations.

Open instrument
11
New issue

Cyber Trivia Game

Test your cybersecurity knowledge with 20 progressive questions on CIA Triad, OWASP Top 10, cryptography, malware, incident response, MITRE ATT&CK, and more. Beginner to Expert.

Open instrument
01 / DEFEND

Security & Reconnaissance

15 instruments

Scan, assess, and harden your domains and infrastructure: all passive, nothing uploaded.

01

Vulnerability Scanner

Scan any website for security headers, SSL issues, CORS misconfigs, and cookie vulnerabilities. Get an A-F grade with one-click fix code.

Open instrument
02
New issue

Phishing Email Checker

Is this email phishing? Forward the suspicious message and receive a technical risk report covering authentication, look-alike domains, links, QR codes, attachments, and scam language. The original email is deleted after the check.

Open instrument
03
New issue

Document Sanitizer

Upload a PDF, Word, Excel, PowerPoint, or image file. We rebuild its visible pages as a flattened PDF, removing macros, embedded scripts, OLE objects, and clickable link behavior. Free, no login.

Open instrument
04
New issue

Conditional Access Gap Analyzer

Paste your exported Entra ID Conditional Access policies and get an A-F grade against 18 Microsoft best practice checks: MFA coverage, legacy auth, device code flow, break-glass exclusions. 100% client-side, nothing uploaded.

Open instrument
05
New issue

Agent Skill Validator

Scan any agent skill repository for prompt injection, malicious scripts, hardcoded secrets, and quality issues. Get a safety grade with detailed findings. Free, no login.

Open instrument
06
New issue

Password Breach Check

Check if a password appears in a known data breach, against the Have I Been Pwned database of 800M+ compromised passwords. Runs entirely in your browser via k-anonymity: your password is never sent or stored.

Open instrument
07
New issue

Cloud Security Recon

Passive cloud posture scan for Azure, AWS, GCP, Vercel, Netlify, and 8 more platforms. Detects Kudu exposure, S3 leaks, preview deploys, service account secrets, and WAF quality. No credentials needed.

Open instrument
08
New issue

CVE Lookup

Search any CVE by ID or keyword. Pull live severity, CVSS score, attack vector, and references from NIST NVD. No login required.

Open instrument
09
New issue

Prompt Injection Tester

Map your AI system prompt guardrails against 10 common injection patterns. Get a coverage score and exact hardening guidance. Free, no login.

Open instrument
10
New issue

Domain Security Report

Full passive security report for any domain: SSL, security headers, email security, technology stack, known CVEs, and subdomains. Nothing uploaded.

Open instrument
11
New issue

Email Security Checker

Test if your domain is vulnerable to email spoofing. Check SPF, DMARC, DKIM, and MTA-STS records instantly. Get a clear verdict and fix recommendations.

Open instrument
12

SSL Certificate Monitor

Check SSL/TLS certificates for any domain. Certificate Transparency logs, subdomain discovery, bulk check up to 10 sites.

Open instrument
13

HTTP Header Checker

Analyze HTTP response headers for any URL. Check security headers, caching, CORS, and server configuration.

Open instrument
14

Password Generator

Generate cryptographically secure passwords with customizable length and character sets. Uses Web Crypto API for true randomness.

Open instrument
15

Hash Generator

Generate SHA-256, SHA-384, SHA-512, and SHA-1 cryptographic hashes for text and files.

Open instrument

Recommended Solutions

Vetted security products we recommend. Disclosure: these are affiliate links: we may earn a commission at no extra cost to you.

S

Sucuri

Partner

Website security platform with cloud-based WAF, malware scanning, DDoS protection, and incident response. Trusted by over 500,000 sites worldwide.

WAFWebsite SecurityMalware ProtectionDDoS
Bitdefender GravityZone logo

Bitdefender GravityZone

Partner

Endpoint protection built for lean IT teams: EDR, ransomware remediation, and patch management in one lightweight agent, without a full SOC to run it.

EDREndpoint ProtectionRansomware RemediationSMB SecurityAntivirus
Bitdefender Digital Identity Protection logo

Bitdefender Digital Identity Protection

Partner

Continuous monitoring for your accounts, personal data, and credentials across breach dumps and dark web marketplaces, with removal requests to data brokers.

Identity Theft ProtectionDark Web MonitoringData Broker RemovalCredential Monitoring
Acronis Cyber Protect logo

Acronis Cyber Protect

Partner

Backup, anti-ransomware, and disaster recovery in one agent: immutable backups, built-in ransomware detection, and one-click recovery when the identity plane itself is compromised.

BackupAnti-RansomwareDisaster RecoveryCyber Protection
Surfshark logo

Surfshark

Partner

Business VPN and network security suite: unlimited devices, dedicated IPs, and centralized team management.

VPNZero TrustNetwork SecurityBusiness VPN
N

NordPass

Partner

Store unique passwords and passkeys across devices, with breach monitoring and password-health checks.

Password managerPasskeysBreach monitoring

Paid plans and current billing terms are shown by NordPass.

N

NordPass Business

Partner

Business password management with secure credential sharing, admin controls, and team-wide security visibility.

Business passwordsCredential sharingAdmin controls
05 / OPERATING PRINCIPLES

Why Protego instruments?

Built from field work, with clear limits and no ornamental complexity.

01

Privacy First

All processing happens in your browser. Your data never leaves your device.

02

Instant Results

No waiting for servers. Get results instantly with client-side processing.

03

Professional Grade

Built using industry standards and best practices for accuracy.

04

100% Free

No subscriptions, no hidden fees. Free tools for the community.

06 / FIELD KITS

Instruments by operating role

Whether you are a security engineer, cloud ops engineer, or developer, these tools fit your workflow.

KIT / DEFEND

Security Engineers

  • +Generate a full passive attack surface report for any domain
  • +Check if a domain can be spoofed for phishing
  • +Discover subdomains via Certificate Transparency logs
  • +Scan for missing security headers and SSL issues
KIT / TRACE

Cloud Ops Engineers

  • +Query DNS and verify record propagation
  • +Look up ASN, ISP, and geolocation for any IP
  • +Calculate subnets and plan IP addressing
  • +Verify domain registration and nameservers
KIT / BUILD

Developers

  • +Decode and debug JWT tokens in API integrations
  • +Format and validate JSON payloads instantly
  • +Encode/decode Base64 for data transmission
  • +Translate CRON expressions to plain English

Frequently Asked Questions

Are these security tools really free?
Yes. Protego tools are free to use, with no paid tier required. Some server-side tools use reasonable daily limits to prevent automated abuse; signing in may provide a higher limit.
Is my data safe when using these tools?
Most tools run entirely in your browser: password generator, hash generator, Base64, JWT decoder, subnet calculator. Tools that query external data (DNS lookup, domain report, email security checker) only send the domain name you type. No sensitive data is ever uploaded.
What does the Domain Security Report check?
It runs 7 passive checks in parallel: SSL/TLS certificate, security headers, email security (SPF/DMARC/DKIM), technology fingerprinting, CVEs for detected technologies, subdomain discovery via CT logs, and WHOIS registration data. All from public sources: nothing is uploaded.
Can I use these tools for professional security audits?
Yes. The Domain Security Report, Email Security Checker, and Vulnerability Scanner use the same public data sources as professional tools (NVD, crt.sh, Cloudflare DNS). For comprehensive penetration testing, complement these with dedicated tools.
Do I need to install anything?
No. All tools run directly in your web browser on desktop, tablet, and mobile. No plugins, extensions, or software downloads required.
07 / REQUEST DESK

Missing an instrument?

Tell us what your workflow is missing. Useful requests are considered for the public field kit.

File a request