Articles
Special feature · Digital security

Cybersecurity tools: what you can check and what the results mean

Services can help investigate breaches, links and website settings. Choosing one means understanding what it examines, what data it receives and the limits of its findings.

A link that appears to come from a familiar company, an unexpected file and a data breach alert raise different questions. Online tools can help investigate them, but their reports need context: what was checked, when and within what scope.

This guide organises a selection of services into seven areas: data exposure, reputation, file and link analysis, threat intelligence, DNS, website security and asset discovery. It is a documentary review of their functions, rather than an effectiveness comparison or popularity ranking.

1. Data breaches: where your email appears

Have I Been Pwned provides a free check against the breaches in its database. Review the affected service and exposed data. A record can remain after a password change; an absent result does not rule out other breaches. Source: FAQ.

Mozilla Monitor continues to offer free breach monitoring. It should be distinguished from Monitor Plus, the data broker scanning and removal service that closed. Mozilla's documentation maintains that distinction: finding breach records and removing personal data are different services. Source: Mozilla.

Start with your own email address. The Have I Been Pwned email search form does not require your account password. If it finds a match, read the incident details before concluding that someone currently has access to your email account. Official form.

2. Reputation: an address's history

An IP address identifies a connection or resource on a network; a domain is a name such as a website address. Reputation checks help investigate past activity, but do not by themselves identify the person who sent you a message.

AbuseIPDB collects reports of abusive activity associated with IP addresses, including intrusion attempts and spam. It is particularly relevant to administrators and offers limited free access alongside additional plans. Our editorial recommendation is to read the reports' dates, categories and context before acting. Service description and plans.

For general readers, this becomes useful when an alert already supplies an IP address. It need not be the first step in checking an unfamiliar message. Copying a list of addresses and blocking them without understanding the consequences is also unwise.

3. Files and links: analysis has privacy implications

VirusTotal brings together file and URL analyses from different providers. Its basic service is free for end users for non-commercial use. Reports are shared, and submitted content may be accessible to qualified customers. Confidential documents therefore need a different review route. Source: how it works.

Even a query needs care: its documentation warns that submitted or queried indicators can enter its dataset. Avoid links containing recovery codes, private access or personal information. Looking for an existing report does not make the query confidential. Source: searching.

In results, undetected means that the engine has no assessment of that item. False positives also occur. Our editorial guidance is to avoid treating any particular alert count as a decision rule without context. URL categories and false positives.

urlscan.io visits a page using its infrastructure and records its behaviour. Reports are snapshots in time. Community access has conditions; public scans are visible and unlisted scans remain accessible to certain researchers and customers. It does not determine whether a downloaded file is malicious. Source: FAQ.

Consider a hypothetical unexpected invoice. Before uploading it, think about the information it contains. If it appears to come from a company you work with, checking through an established contact may resolve the question without sharing the document with another service.

4. Threat intelligence: understanding indicators of compromise

An indicator of compromise, or IOC, is a technical clue associated with malicious activity: a domain, IP address or file fingerprint, for example. Its usefulness depends on context and how current it is.

URLhaus, operated by abuse.ch and Spamhaus, collects and shares URLs associated with malware distribution. That scope distinguishes it from a general scam search engine. Its documentation describes different data channels; do not assume that every integration has identical conditions. Source: URLhaus.

ThreatFox supports searches for malware-related indicators. Its community platform and API have usage conditions; some commercial requirements may need a subscription. Since May 2025, indicators older than six months have been removed from its API and exports, while remaining searchable in the interface. Source: ThreatFox.

These resources help professionals investigate alerts. Readers can learn from their documentation and reports without downloading malware samples or visiting the flagged addresses.

5. DNS: protection that requires configuration

DNS translates domain names into network addresses. Filtering services can prevent certain lookups, but their protection depends on the device or network actually using them.

Quad9 offers a free DNS service. Its recommended profile includes malicious domain blocking; other profiles omit that feature. Choosing the appropriate profile is part of the setup. Source: Quad9 services.

Cloudflare distinguishes standard 1.1.1.1 from 1.1.1.1 for Families, which offers malware blocking and optional adult content filtering. Visiting the website does not activate filtering: setup instructions vary by device or router. Source: official setup guide.

This matters when services are described as tools you can use 'from your browser'. Looking up information and configuring DNS are different actions. On a managed work device, consult the person responsible before changing network settings.

6. Website security: examining specific settings

MDN HTTP Observatory, the successor to Mozilla Observatory, checks HTTP security measures. The current service launched on MDN on 2 July 2024. Each domain's scan history is public. A high grade does not cover issues such as poorly stored passwords or vulnerable plugins. Source: MDN.

Qualys SSL Labs provides a free analysis of the SSL/TLS configuration of public web servers. It is useful for reviewing encrypted connections; that scope does not amount to assessing the website owner's business conduct. Source: SSL Server Test.

If you manage a website, these checks can inform a discussion with its maintainer. Understand each recommendation before changing settings simply to improve a grade.

7. Asset discovery: what is exposed online

Shodan helps investigate services accessible from the internet. It is a specialist tool for reviewing exposure and assets. Access depends on the account and its credits; paid features and academic options exist. Finding a service does not grant permission to access it. Shodan, credits and accounts.

crt.sh is Sectigo's Certificate Transparency log search tool. It helps investigate certificates associated with domain names. The search service could not be opened during this review; its role was checked against Sectigo's documentation, without claiming an operational test. Source: Sectigo.

For your own review, define the domains and systems you administer. A historical record or certificate does not by itself establish that a service remains active or has a vulnerability.

Where to start

Choose the check that matches your question. For your email, review recorded breaches. For a link or file, first decide whether you can share it. If you manage a website, use configuration checks within their stated scope. Threat intelligence and asset discovery platforms become more useful when a technical investigation is already under way.

When a request seems questionable, you can pause and open the official app or contact the organisation through an established channel. You do not need to complete every check in this guide to decide that you lack enough information to trust it.

Official sources are linked throughout. Conditions may change. No comparative tests were performed and no personal data was used for this review.

Sources

Share this publication

You may share links, download the resources made available and republish my own material unchanged and for non-commercial purposes. Retain my credit and include a link to the original REDES publication. Third-party resources remain subject to their own terms. Terms of use.