Cyber Toolkit by DMNZ
Right-click lookups for CVEs, IPs, domains, URLs, file hashes, and email addresses straight from selected text.
Extension Metadata
Screenshots
About this extension
Cyber Toolkit adds right-click lookups for the indicators security professionals check most often — CVE IDs, IP addresses, domains, URLs, file hashes, email addresses, system/database error codes, Windows Security event IDs, and MITRE ATT&CK techniques.
Highlight text (or right-click a link), choose a lookup and the extension either fetches a result directly and shows a clean summary in its own results tab, or opens the right public page for you — whichever the target service supports. Defanged text is automatically 'refanged' for the lookup.
Vulnerability and threat intelligence
Look up a CVE and get its NVD description, CVSS score, and references. Check an IP, domain, URL, or file hash against multiple reputation and threat-intel sources at once, with results merged into a single summary. Pull domain registration data, certificate transparency history, TLS/SSL configuration grade, exposed-service data, and historical snapshots.
Email checks
Run an email address through a domain blacklist/MX check, or get a reputation summary, straight from your selection.
Error code and security operations reference
Look up Windows system error codes, HTTP status codes, Linux/POSIX errno constants, and Oracle or PostgreSQL database error codes, resolved to their exact name and description rather than a generic search. Also look up Windows Security event IDs and MITRE ATT&CK technique IDs — handy for anyone triaging logs or alerts in Sentinel, Defender, or any other SIEM.
Text utilities
Decode Base64, URL-encoded, or hex-encoded text straight from a selection — useful for obfuscated strings in logs or phishing content. Defang a real indicator (turning http://evil.com into hxxp://evil[.]com) so it's safe to paste into a ticket or report without becoming a live link.
Your data, your keys
Several reputation and threat-intel services support an optional free API key for richer results. Keys are entered once in the Options page, stored only in your browser's local extension storage, never logged, and never sent anywhere except the one service each key belongs to. Every visible lookup works without a key too — it just opens that service's own public page instead of an in-extension summary.
Nothing you look up is ever sent to us. Cyber Toolkit has no server, no analytics, and no tracking of any kind.
Highlight text (or right-click a link), choose a lookup and the extension either fetches a result directly and shows a clean summary in its own results tab, or opens the right public page for you — whichever the target service supports. Defanged text is automatically 'refanged' for the lookup.
Vulnerability and threat intelligence
Look up a CVE and get its NVD description, CVSS score, and references. Check an IP, domain, URL, or file hash against multiple reputation and threat-intel sources at once, with results merged into a single summary. Pull domain registration data, certificate transparency history, TLS/SSL configuration grade, exposed-service data, and historical snapshots.
Email checks
Run an email address through a domain blacklist/MX check, or get a reputation summary, straight from your selection.
Error code and security operations reference
Look up Windows system error codes, HTTP status codes, Linux/POSIX errno constants, and Oracle or PostgreSQL database error codes, resolved to their exact name and description rather than a generic search. Also look up Windows Security event IDs and MITRE ATT&CK technique IDs — handy for anyone triaging logs or alerts in Sentinel, Defender, or any other SIEM.
Text utilities
Decode Base64, URL-encoded, or hex-encoded text straight from a selection — useful for obfuscated strings in logs or phishing content. Defang a real indicator (turning http://evil.com into hxxp://evil[.]com) so it's safe to paste into a ticket or report without becoming a live link.
Your data, your keys
Several reputation and threat-intel services support an optional free API key for richer results. Keys are entered once in the Options page, stored only in your browser's local extension storage, never logged, and never sent anywhere except the one service each key belongs to. Every visible lookup works without a key too — it just opens that service's own public page instead of an in-extension summary.
Nothing you look up is ever sent to us. Cyber Toolkit has no server, no analytics, and no tracking of any kind.
Rated 0 by 0 reviewers
Permissions and data
Optional permissions:
- Access your data for services.nvd.nist.gov
- Access your data for rdap.org
- Access your data for ipwho.is
- Access your data for www.virustotal.com
- Access your data for api.abuseipdb.com
- Access your data for api.greynoise.io
- Access your data for urlhaus-api.abuse.ch
- Access your data for threatfox-api.abuse.ch
- Access your data for mb-api.abuse.ch
- Access your data for cloudflare-dns.com
- Access your data for emailrep.io
- Access your data for urlscan.io
- Access your data for api.ssllabs.com
- Access your data for internetdb.shodan.io
- Access your data for archive.org
- Access your data for man7.org
- Access your data for learn.microsoft.com
- Access your data for www.postgresql.org
- Access your data for api.certspotter.com
- Access your data for attack.mitre.org
Data collection:
- The developer says this extension doesn't require data collection.
More information
- Add-on Links
- Version
- 1.2.0
- Size
- 62.45 KB
- Last updated
- 4 days ago (Sep 3, 2026)
- Related Categories
- License
- Mozilla Public License 2.0
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection