Interactive cybersecurity awareness platform powered by real data. Test password strength against billions of breached passwords, simulate email breach lookups, analyze phishing URLs, and test your knowledge.
Powered by the Have I Been Pwned API and live analysis engines. All processing happens in your browser — nothing is stored or sent to any server.
Checks passwords against 800M+ breached records using k-anonymity. Only the first 5 hex chars of the SHA-1 hash leave your browser.
Advanced analysis with entropy calculation, character diversity checks, and estimated cracking time at 10 billion guesses/sec.
Realistic breach simulation using historical breach data. Shows exposed data, severity, and impact. Get a free HIBP API key for live lookups.
Scans URLs against 16 phishing indicators: suspicious TLDs, IP hosts, @ symbols, keyword traps, missing HTTPS, excessive subdomains, and more.
Generates passwords using crypto.getRandomValues() — the same RNG used by browsers for TLS. Configurable length and character sets.
Generate cryptographic hashes using the Web Crypto API. All computation happens locally in your browser.
Encode text to Base64 or decode Base64 back to text. Useful for working with data URLs, tokens, and encoded payloads.
Decode JSON Web Tokens to inspect header and payload claims. Useful for debugging authentication flows.
Discover your public IP address along with geolocation, ISP, and timezone information using a public API.
Sources: Verizon DBIR, IBM Cost of a Breach, ITRC, OWASP
Real-time simulation of attack traffic across the globe
Based on 175,000+ CVEs across 2.8 million applications
Real-world scenarios from security professionals
Recommended by cybersecurity professionals worldwide