Update · FORGE
FORGE, upgraded: faster triage, richer context — still free
23 July 2026
FORGE is my free, browser-first toolkit for SOC analysts and threat hunters — no login, no cost, nothing to install. It just picked up a round of upgrades aimed at cutting time-to-answer on an investigation.
What's new
- Unified threat-intel lookup — check an IP, domain, URL or hash across VirusTotal, AbuseIPDB, GreyNoise and AlienVault OTX in a single view, now with inline geo, ISP and ASN and WHOIS / RDAP registration data. Domains and URLs are resolved automatically so you see where they actually point.
- IOC extractor — pull indicators out of pasted text, PDFs or raw emails, with IPv6 support and automatic re-fanging of defanged IOCs (hxxp, 1[.]2[.]3[.]4).
- Bulk IP enrichment — turn thousands of IPs into Country / Region / City / ISP / ASN and export the lot as one CSV.
- AI log explainer — paste a noisy log line and get a plain-language read (clearly labelled AI-generated, verify before acting).
- Live vulnerability feed — CISA Known-Exploited-Vulnerabilities with CVSS severity and detail cards, so you see what's actually being exploited in the wild.
- Everyday analyst utilities — an email-header analyzer, a Hash Lab, a Base64 / URL decoder, a subnet & CIDR calculator, and a regex tester — the small tools you keep a dozen browser tabs open for, in one place.
- Install it as an app (PWA) — add FORGE to your desktop or phone home screen; it opens in its own window, launches fast, and keeps working through flaky connectivity.
- Share & speed — shareable case links and a one-click browser bookmarklet to send whatever you're looking at straight into FORGE.
- New: authenticated file-share — a private, per-recipient way to hand off a file quickly and securely.
Built privacy-first
FORGE never logs the indicators you look up. Traffic analytics are aggregate and cookieless. That's a deliberate design choice — an analyst tool shouldn't quietly become a record of what you were investigating.
Open FORGE →
It's free. If it saves you a few minutes on your next investigation, that's the whole point — and feedback is always welcome.