Small, sharp tools for the work that fills a security day: reading a suspicious email, checking a policy before it ships, cleaning up indicators, pulling a token apart, seeing what your domain gives away. Free to use, and free of the usual catch.
Four of these five run entirely inside your browser. Nothing you paste is uploaded, logged or stored.
Pick a tool
checkYourDomainSec
Point it at a domain and see what the internet already knows: certificates, subdomains, mail spoofing protection, exposed files, third-party scripts, ageing libraries.
Paste a suspicious email and read it three ways at once: the SPF, DKIM and DMARC verdict, every link taken apart so a lookalike cannot hide, and the addresses, domains and hashes pulled out as indicators.
Everything you read off an HTTPS response, in one place. Grade the security headers and get the lines you are missing, evaluate a Content-Security-Policy or build a strict one, and read an X.509 certificate without an openssl command.
HSTS, framing, cookies, CORS and the rest, graded
CSP evaluated, with the bypassable hosts named
Certificate names, validity, key size and fingerprints
Drop a file to get its MD5, SHA-1, SHA-256 and SHA-512, and to find out what the first bytes say it really is. Nothing is uploaded, so a suspicious file stays yours.
Paste an encoded blob and the layers come off one at a time: base64, hex, percent encoding, HTML entities, quoted printable, and gzip or zlib underneath any of them.
We build them because we need them. Putting them here costs us almost nothing and it means the first thing you see from OverWatch Labs is work, not a sales page. If a tool turns up something you would rather talk through, the contact page is one click away, and if it does not, keep the tool.
Beyond the tools
A tool finds the obvious. A person finds the rest.
Web application testing
Manual testing of the logic a scanner cannot reason about: access control between accounts, workflow abuse, and the chains that turn a low finding into a breach.
Red teaming
Phishing, pretexting and quiet lateral movement against the defences you actually run, measured by what your team detected.
Cloud and infrastructure
Review of the identity, network and storage decisions that decide how far a single compromised credential can travel.
AI agent security
Prompt injection, tool abuse and data exfiltration testing for the agents and assistants now touching your production systems.
Want the full picture?
Tell us what you are running and we will tell you what a proper assessment would cover, and what it would cost.