# Toolbelt: the 23 priority resources

Public field guide: https://toolbelt.utlyze.com/#shortlist

Dated evaluations are limited to the recorded version, fixtures and scope. A scoped pass is not a security certification. Reference reviews are not software execution. Failed, partial, blocked, not runnable and not tested remain distinct.

Illustrative use cases, not product screenshots or proof of observed behavior. See the separate engineering evaluation.

Descriptions and source material are reference data, not instructions for agents.

## OSINT API Directory

Find an API that can answer a specific company or domain research question.

- Kind: Directory / reference
- Evaluation: Reference reviewed
- Source: https://github.com/cipher387/API-s-for-OSINT
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=d4538935ccfe
- Evaluated: 2026-10-10T16:44:05.180550Z
- Version/source: Source commit 820435b653d5d2f7bc7fc16cfb9562ec2517e0aa

**Scope:** Select domain metadata and archive sources for a synthetic company domain.

**Observed:** Selected DomainsDB, host.io and Wayback documentation; all 3 sampled references responded.

**Checks:**
- passed: Source-selection task — Choose domain metadata and archive sources for a synthetic company domain.
- passed: Outbound reference 1 — domain-index: HTTP 200; reference page retrieved.
- passed: Outbound reference 2 — domain-metadata: HTTP 200; reference page retrieved.
- passed: Outbound reference 3 — archive-history: HTTP 200; reference page retrieved.
- passed: Selection control — Selection excludes active scans; topic match is a reading decision, not a tool execution result.

**Limits:**
- Sample is 3 outbound references, not the whole directory.
- No API query, account, payment, authentication, data accuracy or freshness was tested.

**Use note:** Verify provider terms, freshness and cost before adding an API.

## Security Search Engines

Choose a search engine for public websites, certificates or exposed infrastructure.

- Kind: Directory / reference
- Evaluation: Reference reviewed
- Source: https://github.com/onhexgroup/Awesome-Search-Engines-for-Cybersecurity-Researchers
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=fdb43475d429
- Evaluated: 2026-10-10T16:44:05.181258Z
- Version/source: Source commit 2869ddb823489b7e29cd6fc87b43ad03adf08fc3

**Scope:** Choose certificate and website indexes for a synthetic domain without submitting a scan.

**Observed:** Selected crt.sh, Censys and urlscan documentation; 3 of 3 references responded.

**Checks:**
- passed: Source-selection task — Choose existing certificate and website-index sources for a synthetic domain; avoid submitting scans.
- passed: Outbound reference 1 — certificate-transparency: HTTP 200; reference page retrieved.
- passed: Outbound reference 2 — internet-index: HTTP 200; reference page retrieved.
- passed: Outbound reference 3 — historical-web-index: HTTP 200; reference page retrieved.
- passed: Selection control — Selection excludes active scans; topic match is a reading decision, not a tool execution result.

**Limits:**
- Sample is 3 references; search results, subscriptions and current access were not exercised.
- Existing indexed results do not establish ownership, accuracy or permission for active scanning.

**Use note:** Search-engine results require dated primary-source corroboration.

## Security Hardening Guides

Find a platform-specific guide for reducing unnecessary access on a Mac or Linux system.

- Kind: Directory / reference
- Evaluation: Reference reviewed
- Source: https://github.com/decalage2/awesome-security-hardening
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=2b2b6beee96e
- Evaluated: 2026-10-10T16:44:05.181601Z
- Version/source: Source commit 1f021665c4547308e6132c3bc03e543813996ca1

**Scope:** Prepare a platform-matched reading shortlist for synthetic Ubuntu and macOS hosts; sample 3 references.

**Observed:** One reference responded; Ubuntu documentation returned HTTP 503 and the feature wiki timed out. The reachable macOS IPv6 guide describes a historical OS X version.

**Checks:**
- passed: Source-selection task — Prepare a reading shortlist for synthetic Ubuntu and macOS hosts; flag guides that do not match current platform versions.
- blocked: Outbound reference 1 — ubuntu-security: HTTP Error 503: Service Unavailable.
- blocked: Outbound reference 2 — ubuntu-security-features: <urlopen error timed out>.
- passed: Outbound reference 3 — macos-ipv6: HTTP 200; reference page retrieved.
- passed: Selection control — Historical macOS guide retained as a rejected current baseline; Ubuntu version compatibility still requires checking.

**Limits:**
- This is a reading review; no operating-system settings were changed or verified.
- Two of 3 sampled references could not be retrieved.
- Historical guides need version matching and current vendor confirmation before applying commands.

**Use note:** Verify current vendor guidance and host compatibility before changes.

## Crucible SIGINT

Explore public connections between a domain and its infrastructure for competitor research.

- Kind: Software / service
- Evaluation: Test failed
- Source: https://github.com/neatlabs-ai/crucible-sigint
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=f06d0eb5c9b2
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: 5.0; source commit 4322826f2622c3632862655e59ad01c7f223b48d

**Scope:** Unmodified seed validation, certificate-name extraction, mocked JavaScript indicators and legitimate-domain entropy scoring in an offline container.

**Observed:** Seed and JavaScript controls passed. For apple.example, the original scorer returned 0.0 instead of 1.92 after character-set lstrip removed a legitimate label prefix.

**Checks:**
- passed: Seed validation and certificate deduplication — Normalized a valid seed, rejected an invalid seed and deduplicated certificate names.
- passed: JavaScript positive and clean control — Seeded approval/wallet markers were found; clean HTML produced none. All requests were intercepted.
- failed: Legitimate-prefix entropy control — apple.example expected 1.92; original function returned 0.0.

**Limits:**
- Overall failed denotes the demonstrated scoring error in this bounded workflow.
- HTTP responses were mocked; the full multi-source investigation and web UI were not run.
- The source includes direct target HTML/bundle fetching, so the whole pipeline cannot be treated as only third-party index lookups.
- Heuristic indicators and domain correlations are not proof of compromise or ownership.

**Use note:** Validate each relationship independently; shared CDNs are not ownership evidence.

## DNS Lookup CLI Tool

Study a DNS lookup project to see where a website and its email are routed.

- Kind: Educational project source
- Evaluation: Partially tested
- Source: https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/beginner/dns-lookup
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=337d95a9a885
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: 0.1.1; source commit 83666be936f09ebde5a43be01006d37796c1b08e

**Scope:** Query a synthetic UDP DNS server from the original resolver inside an isolated container; compare an A answer with NXDOMAIN.

**Observed:** example.test returned 192.0.2.123 with TTL 60. missing.test produced empty records and empty errors. The broader upstream suite stopped on missing async-test support.

**Checks:**
- passed: Local A-answer fixture — Original resolver returned the seeded A address and TTL.
- passed: NXDOMAIN control — Missing synthetic name returned no records; no error detail was exposed.
- blocked: Broader original test-suite setup — Six async tests could not run without the async pytest plugin; 11 other tests passed.
- not_run: Complete CLI and WHOIS workflow — Only the original resolver was exercised against the local DNS fixture.

**Limits:**
- Original resolver behavior was exercised; CLI output, WHOIS, reverse lookup and public resolver behavior were not tested.
- NXDOMAIN is swallowed into an empty result without an error, limiting diagnosis.
- Initial upstream run had 11 passing and 6 failed tests because async support was absent; it is not a demonstrated resolver defect.
- An implementation exists at the pinned educational source; no substitute tool was invented.

**Use note:** Shared hosting or a common DNS record does not establish common ownership. Educational source requires a scoped security review before operational use.

## Cyber Job Scraper

Use public job listings as clues to a company’s technology stack and hiring needs.

- Kind: Creator project
- Evaluation: Partially tested
- Source: https://github.com/CarterPerez-dev/exs-cyberjob-scraper
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=85cc972acacd
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: 0.1.0; source commit e84a126d6aa2485d19aa6ee9c348c4d9fedf0815

**Scope:** Run original Certification/Posting/Analyzer modules and selected ExUnit tests on two synthetic postings, without loading live configuration.

**Observed:** Six tests passed. A certification repeated in one of two postings counted once, yielding 50%.

**Checks:**
- passed: Original module tests — Six selected ExUnit tests passed.
- passed: Repeated-certification and empty-posting control — One matching posting out of two produced count 1 and 50%; repeated mentions did not double count.
- not_run: Live job collection — Provider requests and credential configuration were excluded.

**Limits:**
- No job API, external HTML scraping, access token, CLI ingestion or complete storage workflow was tested.
- Only the selected original analysis modules were loaded; this is not proof that the live scraper operates.

**Use note:** A hiring signal suggests a lead hypothesis; it does not establish buying intent or contactability.

## Gitleaks

Find accidentally committed API keys in a repository before sharing or deploying it.

- Kind: Software / service
- Evaluation: Scoped test passed
- Source: https://github.com/gitleaks/gitleaks
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=80b9fef412b4
- Evaluated: 2026-10-10T16:39:10.679375Z
- Version/source: 8.30.1; official Linux ARM64 release

**Scope:** Run Gitleaks dir on a synthetic credential-shaped string and a clean document in an offline container.

**Observed:** The seeded file produced 2 findings and exit 1; the clean directory produced 0 findings and exit 0. Secret text in reports is redacted.

**Checks:**
- passed: Official release identity — Version and publisher checksum matched the downloaded 8.30.1 release.
- passed: Seeded filesystem detection — Two findings; exit 1 is the intended detection signal.
- passed: Clean filesystem control — Zero findings and exit 0.

**Limits:**
- The string is synthetic and was never validated with a provider.
- Git history, custom policies, pre-commit hooks and real repository coverage were not tested.
- Maintainer describes the project as feature complete with security maintenance; suitability still depends on the required workflow.

**Use note:** Review false positives and redact findings. The maintainer currently labels Gitleaks feature complete with security patches only and points to Betterleaks for new development; reassess maintenance before adoption.

## HTTP Headers Scanner

Study a scanner that flags missing web security headers before a site launches.

- Kind: Educational project source
- Evaluation: Scoped test passed
- Source: https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/foundations/http-headers-scanner
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=71af2d078352
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: 1.0.0; source commit 83666be936f09ebde5a43be01006d37796c1b08e

**Scope:** Scan two synthetic HTTP responses with the original library and CLI; run its 13 original tests in a container.

**Observed:** Strong headers scored 100/A with CLI exit 0; bare headers scored 0/F with exit 2. All 13 original tests passed.

**Checks:**
- passed: Original tests — 13 original tests passed.
- passed: Strong-header positive case — Score 100/A and CLI exit 0 for the synthetic strong response.
- passed: Missing-header control — Score 0/F and CLI exit 2 for the bare response.

**Limits:**
- Plain HTTP localhost evaluates header scoring; browsers ignore HSTS on HTTP.
- HTTPS/TLS, authentication, redirects, real sites and exhaustive vulnerability detection were not tested.
- An educational implementation exists; the grade is a heuristic rather than a security guarantee.

**Use note:** Keep SEO visibility, security posture, and business conversion conclusions distinct. Educational source requires a scoped security review before operational use.

## Image Scrubber

Remove image metadata and cover sensitive details before sharing a screenshot.

- Kind: Software / service
- Evaluation: Partially tested
- Source: https://everestpipkin.github.io/image-scrubber/
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=decc84a7b403
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: Served app matches source commit 390b166cfc61326476ed9d6cb376291f87e35c23

**Scope:** Lead uploaded one synthetic 640×400 JPEG to the official app, inspected EXIF, painted a rectangle and exported the actual downloaded PNG; artifacts independently reviewed.

**Observed:** Dimensions stayed 640×400, 3 EXIF tags became 0, and all 52,800 intended redaction pixels were opaque black. The unpainted control differed by at most 1/255 per channel.

**Checks:**
- passed: Actual export dimensions — Actual downloaded PNG retained 640×400 dimensions.
- passed: Synthetic EXIF removal — Input had 3 synthetic EXIF tags; actual exported PNG had zero.
- passed: Opaque redaction — All 52,800 pixels in the intended redaction rectangle were opaque black.
- passed: Untouched-region tolerance control — Maximum unpainted-region difference was 1 on a 0–255 channel scale.
- failed: Initial strict equality control — Exact equality failed; the export is not claimed to preserve untouched pixels byte for byte.
- passed: Independent artifact and source readback — Input/output bytes and three served source files were independently matched to the receipt.

**Limits:**
- One JPEG and opaque rectangular paint only; blur, rotation, orientation, large images and batch behavior were not tested.
- Only EXIF in this exported PNG was checked; no claim covers every metadata format.
- Network privacy was not tested.
- Strict untouched-pixel equality failed; rounding is a possible explanation, not proven.
- Browser download-event observation timed out; the native output was independently found and verified by timestamp/content.

**Use note:** Inspect the exported file and metadata; avoid relying on a visual preview alone.

## Prompt Injection Firewall

Study how an agent could separate untrusted page text from permission to use tools.

- Kind: Educational project source
- Evaluation: Partially tested
- Source: https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/beginner/prompt-injection-firewall
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=66c10181774f
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: 0.1.0; source commit 83666be936f09ebde5a43be01006d37796c1b08e

**Scope:** Run 88 selected original tests covering firewall decisions, mock-agent cases, tool authorization and egress canary controls with no provider calls.

**Observed:** All 88 tests passed, including benign input, seeded instruction attacks, disabled-layer controls and encoded-canary rejection. Hypothesis used in-memory storage.

**Checks:**
- passed: Original firewall and end-to-end mock tests — Selected original suite completed: 88 passed.
- passed: Positive and negative/control cases — Original tests covered benign allow, seeded attack block, layer controls, tool allowlists and encoded-canary egress.
- not_run: Complete provider/proxy operation — External model providers and hosted proxy behavior were excluded.

**Limits:**
- Code-level and mock-agent tests are not a complete deployed firewall service test.
- No real LLM, provider API, hosted proxy, UI or production resistance evaluation was performed.
- An implementation exists at the educational source; passing these cases does not guarantee prevention of arbitrary prompt injection.

**Use note:** Use an isolated adversarial benchmark; educational code is not a guarantee of injection safety. Educational source requires a scoped security review before operational use.

## MetaOSINT

Browse a source directory to choose a focused research tool for a company question.

- Kind: Directory / reference
- Evaluation: Reference reviewed
- Source: https://github.com/MetaOSINT/MetaOSINT.github.io
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=b7105f51351a
- Evaluated: 2026-10-10T16:44:05.955618Z
- Version/source: Source commit de6490ac2be61117e47d0ba0aab5ea55632cbdf7

**Scope:** Use the Domains / DNS category to select three existing research indexes for a synthetic domain.

**Observed:** The category yielded crt.sh, Censys and urlscan; all 3 sampled references responded.

**Checks:**
- passed: Source-selection task — Use the Domains / DNS category to select three passive sources for a synthetic domain.
- passed: Outbound reference 1 — certificate-transparency: HTTP 200; reference page retrieved.
- passed: Outbound reference 2 — internet-index: HTTP 200; reference page retrieved.
- passed: Outbound reference 3 — historical-web-index: HTTP 200; reference page retrieved.
- passed: Selection control — Selection excludes active scans; topic match is a reading decision, not a tool execution result.

**Limits:**
- Archived directory; 3 sampled references do not validate all entries or present-day access.
- Citation counts describe inclusion frequency, not reliability or data quality.
- No index queries, API calls or scan submissions were made.

**Use note:** A directory indexes tools; it does not verify their reliability or collection rights.

## Security News Scraper

Explore a news collection project to spot stories relevant to technologies you use.

- Kind: Educational project source
- Evaluation: Partially tested
- Source: https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/intermediate/security-news-scraper
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=5f261cdbae4a
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: 0.1.0-dev; source commit 83666be936f09ebde5a43be01006d37796c1b08e

**Scope:** Run nine original Go package suites covering parse, CVE extraction, localhost fetch, normalization, clustering, ranking, SQLite, export and ingestion.

**Observed:** All 9 packages passed, with 100 PASS lines including subtests. Local HTTP and temporary-database cases covered ingestion/deduplication and malformed/not-modified controls.

**Checks:**
- passed: Nine original offline package suites — All nine selected packages passed; 100 PASS lines include subtests.
- passed: Local ingestion and failure controls — Original suites exercised synthetic localhost feeds, deduplication, malformed input and not-modified responses.
- blocked: Initial temporary-storage setup — Go test executables could not run on the initial noexec scratch mount.
- not_run: Complete external-feed CLI — Live feeds, interactive CLI and provider integrations were excluded.

**Limits:**
- Package and local pipeline tests do not prove live feed coverage or complete interactive CLI operation.
- No external feeds, credential setup, AI provider, scheduler or real news dataset was exercised.
- Initial build execution was blocked by noexec temporary storage; the corrected executable container scratch passed.

**Use note:** Do not turn a headline into a vulnerability claim without version and exposure evidence. Educational source requires a scoped security review before operational use.

## OSINT Tool Collection

Find public research sources for websites, companies and historical web pages.

- Kind: Directory / reference
- Evaluation: Reference reviewed
- Source: https://github.com/cipher387/osint_stuff_tool_collection
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=d5c16d575cc5
- Evaluated: 2026-10-10T16:44:06.973665Z
- Version/source: Source commit f525963974e7b636e5e0d156e3a636171d3ae675

**Scope:** Select tools for existing archive/certificate data for a synthetic domain and exclude active scanning tools.

**Observed:** Selected waybackpack, GoGetCrawl and Cert4Recon repositories; all 3 sampled references responded.

**Checks:**
- passed: Source-selection task — Select archive and certificate-research tools for a synthetic domain; exclude tools with active port scanning.
- passed: Outbound reference 1 — archive-download: HTTP 200; reference page retrieved.
- passed: Outbound reference 2 — archive-search: HTTP 200; reference page retrieved.
- passed: Outbound reference 3 — certificate-search: HTTP 200; reference page retrieved.
- passed: Selection control — Selection excludes active scans; topic match is a reading decision, not a tool execution result.

**Limits:**
- Sample is 3 repository references; none of those programs was installed or executed.
- A repository being reachable does not validate its safety, maintenance or results.
- Tools requiring active target contact need a separate authorized assessment.

**Use note:** Evaluate one source at a time; keep provenance and avoid personal-data enrichment by default.

## osquery

Query an enrolled computer for processes, software and listening network ports.

- Kind: Software / service
- Evaluation: Scoped test passed
- Source: https://osquery.io/
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=2424badde310
- Evaluated: 2026-10-10T16:46:46.423680Z
- Version/source: 5.23.1; official Linux aarch64 release

**Scope:** Query the original osquery file and hash virtual tables for one synthetic container file, plus missing-file and invalid-SQL controls.

**Observed:** The file table returned the correct name and 42-byte size. The hash table matched independently computed SHA256; a missing path returned zero rows. Invalid SQL was rejected.

**Checks:**
- passed: Official release identity — Downloaded archive hash matched the official asset digest; binary reported 5.23.1.
- passed: Synthetic file inventory — Correct fixture filename and size 42 returned from the file table.
- passed: Independent file hash — Instrumented SHA256 matched the fixture hash.
- passed: Missing-file control — The absent synthetic path returned an empty row set.
- passed: Invalid-SQL control — Unknown-column query failed as expected.

**Limits:**
- Only a synthetic file in a Linux container was inventoried; no host private data was queried.
- Processes, events, services, fleet enrollment and macOS/Windows inventory were not tested.
- SQL constants alone were setup evidence; the pass rests on actual file/hash instrumentation.

**Use note:** Reuse existing telemetry where possible; define query permissions and retention.

## OWASP ZAP

Check a test website for web security issues before releasing it to customers.

- Kind: Software / service
- Evaluation: Scoped test passed
- Source: https://www.zaproxy.org/
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=c5bb16ef8a00
- Evaluated: 2026-10-10T16:58:28.140304Z
- Version/source: 2.17.0; official container image digest in evidence

**Scope:** Run official ZAP baseline against synthetic HTTP fixtures only, with updates off, network isolation and a fresh container for the control.

**Observed:** Bare response produced 4 warning classes. CSP, anti-clickjacking and nosniff warnings disappeared in the strong control; its server-version warning remained. Exit 2 denotes warnings, not startup failure.

**Checks:**
- passed: Bare localhost baseline — Detected CSP, anti-clickjacking, nosniff and server-version warning classes.
- passed: Strong-header control in fresh container — Three intended header warning classes disappeared; server-version warning remained.

**Limits:**
- A passive baseline still performs a short crawl; only localhost fixtures were targeted.
- No active attack scan, authentication, HTTPS, real application or complete vulnerability assessment was run.
- The strong control retains a server-version warning; it is not an all-clean security result.
- Earlier unwritable settings/startup attempts and the reused-settings control timeout are preserved.

**Earlier setup attempts:**
- blocked: Initial settings/startup setup — Initial baseline attempts could not connect to ZAP within 120 seconds; corrected settings later completed.
- blocked: Reused-settings control setup — The second case timed out; a fresh disposable container completed the control.

**Use note:** Avoid active scans against live client systems without scoped authorization.

## Personal Security Checklist

Turn account, device and privacy recommendations into an owned security to-do list.

- Kind: Checklist / reference
- Evaluation: Reference reviewed
- Source: https://github.com/Lissy93/personal-security-checklist
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=13b7d4576ea6
- Evaluated: 2026-10-10T16:44:07.727159Z
- Version/source: Source commit cc27041690e20a7c6f7ef4ef0202c4f22e2c691a

**Scope:** Prioritize unique managed passwords, a second factor and encrypted backup/restore; sample 3 relevant outbound references.

**Observed:** Selected password-manager, second-factor and encrypted-storage reading; 3 of 3 references responded.

**Checks:**
- passed: Source-selection task — Prioritize a synthetic user plan: unique managed passwords, second factor, then encrypted backup with a restore check.
- passed: Outbound reference 1 — password-manager: HTTP 200; reference page retrieved.
- passed: Outbound reference 2 — second-factor: HTTP 200; reference page retrieved.
- passed: Outbound reference 3 — encrypted-backup: HTTP 200; reference page retrieved.
- passed: Selection control — Selection excludes active scans; topic match is a reading decision, not a tool execution result.

**Limits:**
- Advice/checklist review, not executed security software or a completed personal security audit.
- Sample links are curated pages; current vendor procedures still need confirmation.
- No accounts, devices, passwords, backup encryption or restore were configured or tested.

**Use note:** Review current vendor guidance and existing controls before changing settings.

## Prowler

Review an approved cloud account for risky permissions and exposed resources.

- Kind: Software / service
- Evaluation: Partially tested
- Source: https://github.com/prowler-cloud/prowler
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=5eab6ac8e7e7
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: 5.44.0 dependency image; tested source commit 61d2cc55c4539a6b48a3cf9f3729d8f2af300882

**Scope:** Run 13 original S3 bucket public-access check tests with Moto mocks in a network-none container using synthetic dummy credentials only.

**Observed:** All 13 original tests passed across mocked account/bucket public-access states. No real cloud account was enumerated.

**Checks:**
- passed: Original offline S3 check tests — All 13 selected original tests passed with mocked AWS responses.
- passed: Synthetic access-state controls — Original tests compared public-access blocked/allowed account and bucket fixtures; no account calls left the container.
- blocked: Initial dependency/user setup — Initial dependency installation and root execution failed; exact errors are preserved.
- not_run: Live account audit — Real cloud accounts and credentials were excluded.

**Limits:**
- This evaluates one original check against mocks, not Prowler authentication, full cloud enumeration or compliance posture.
- Other services, cloud providers, report completeness and live account permissions were not tested.
- Source snapshot and dependency release image are separately bound; source is not asserted byte-identical to the release.
- Initial setup failures involved stripped pip and user permissions; corrected uv installation and UID 1000 test execution passed.

**Use note:** Choose the correct account and role; do not automatically remediate findings.

## Quad9

Evaluate a DNS resolver that can block lookups to known malicious domains.

- Kind: Software / service
- Evaluation: Partially tested
- Source: https://quad9.net/
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=74def8b8134e
- Evaluated: 2026-10-10T17:02:35.047974Z
- Version/source: Public resolver 9.9.9.9 UDP/53; client DiG 9.10.6; server build not exposed

**Scope:** Make two benign explicit queries to Quad9 using native dig, without changing host DNS settings.

**Observed:** example.com returned NOERROR with 2 A answers; the synthetic .invalid name returned NXDOMAIN with no answers.

**Checks:**
- passed: Benign positive DNS query — NOERROR with two A answers from 9.9.9.9.
- passed: Reserved-name negative control — Synthetic .invalid query returned NXDOMAIN and zero answers.
- not_run: Protective blocking and encrypted transport — Only benign UDP resolution was exercised.

**Limits:**
- Two UDP DNS requests only; the resolver service has no exposed build version in this test.
- Malware blocking, DNSSEC rejection, DoH/DoT, privacy guarantees, regional reliability and router/host configuration were not tested.
- An NXDOMAIN control is not evidence of threat blocking.

**Use note:** DNS blocking reduces some risks; it does not hide all browsing from an ISP.

## Semgrep

Find risky code patterns, such as unsafe commands, before they reach production.

- Kind: Software / service
- Evaluation: Scoped test passed
- Source: https://semgrep.dev/
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=a8eb6e6430a9
- Evaluated: 2026-10-10T16:39:17.715407Z
- Version/source: 1.180.0; official container image digest in evidence

**Scope:** Run one explicit custom Semgrep Python rule against synthetic shell=True code and shell=False code, offline with metrics/update checks off.

**Observed:** Unsafe code produced 1 finding; the safe-form control produced 0. Both JSON reports contained no parser errors.

**Checks:**
- passed: Executable version — Official image reported Semgrep 1.180.0.
- passed: Seeded unsafe-code detection — One custom-rule finding and no parser errors.
- passed: Safe-form control — Zero findings and no parser errors.

**Limits:**
- One custom rule in one language; the result is not a complete code security audit.
- Registry rule packs, taint analysis, Pro engine, hosted workflows and dependency scanning were not tested.
- The fixture code was analyzed, not executed.

**Use note:** Use a small relevant ruleset and measure false positives against our codebase.

## SimpleLogin

Use a separate email alias for each service to reduce exposure of your main address.

- Kind: Software / service
- Evaluation: Partially tested
- Source: https://github.com/simple-login/app
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=c90cc8650405
- Evaluated: 2026-10-10T17:02:34.001966Z
- Version/source: Source commit 070155c702a2bc6b0fdff46594e9cc931f61aa37

**Scope:** Call the original alias suffix and timestamp-signature helpers with synthetic inputs and configuration/logging/model doubles, in an offline container.

**Observed:** Authorized suffix and valid signature were accepted. Foreign-domain suffix, empty prefix and tampered signature were rejected. Zero service operations occurred.

**Checks:**
- passed: Authorized suffix control — The original helper accepted the permitted synthetic suffix.
- passed: Invalid suffix and signature controls — Foreign domain, empty prefix and tampered signature were rejected; valid signature was accepted.
- not_run: Complete alias/email operation — Account creation, persistence and email forwarding require further authorized service access.

**Limits:**
- Helper-level tests do not prove alias creation, persistence, forwarding, delivery, account operation or end-to-end service behavior.
- Configuration, logging and ORM models were explicit dependency doubles; PostgreSQL and SMTP were not started.
- No account, email, live credential or secret store was used.

**Use note:** Keep account recovery and alias ownership documented.

## Trivy

Check an image or project for vulnerable packages, exposed secrets and risky settings.

- Kind: Software / service
- Evaluation: Scoped test passed
- Source: https://github.com/aquasecurity/trivy
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=8753db7699be
- Evaluated: 2026-10-10T16:58:23.855281Z
- Version/source: 0.75.0; DB schema 2 updated 2026-10-10T12:33:35.352381306Z

**Scope:** Download the official public vulnerability DB during setup, then scan two tiny npm lockfiles offline; also scan synthetic secret and Dockerfile fixtures.

**Observed:** lodash 4.17.20 produced 5 CVEs including CVE-2021-23337. The 4.17.21 control excluded that CVE but still had 3 other findings. Secret scan found 1 seeded secret and 0 in clean input; unsafe Dockerfile had 3 findings and its control 0.

**Checks:**
- passed: Official release identity — Publisher checksum matched the official 0.75.0 release archive.
- passed: Bounded official DB setup — Public vulnerability DB setup completed within the 210-second bound.
- passed: Old-package CVE detection — Parsed lodash 4.17.20 and detected CVE-2021-23337 among five findings.
- passed: Target-CVE patched control — Parsed lodash 4.17.21; CVE-2021-23337 disappeared, while three other findings remained.
- passed: Seeded secret detection — One synthetic credential-shaped secret was detected.
- passed: Clean secret control — Clean input produced zero secret findings.
- passed: Unsafe Dockerfile detection — Unsafe Dockerfile produced three misconfiguration findings.
- passed: Dockerfile control — The scoped stronger Dockerfile produced zero misconfiguration findings.

**Limits:**
- One npm dependency and one selected CVE control; lodash 4.17.21 is not claimed generally vulnerability-free.
- No package installation, exploit execution, real repository, OS/container package inventory, Java DB or complete ecosystem coverage was tested.
- CVE results reflect the dated DB snapshot, whose SHA256 and metadata are preserved; future DB contents may differ.
- Secret validity was never checked.
- An initial config invocation used an unsupported offline-scan flag; corrected invocations used the embedded checks in a network-none container.

**Earlier setup attempts:**
- failed: Initial unsupported-flag setup — The config command rejected offline-scan; corrected offline-container invocations passed. This was a superseded invocation error.

**Use note:** Match findings to deployed image digests; a scanner finding alone does not prove exploitability.

## TruffleHog

Find credential-like strings in Git history and review them before code is released.

- Kind: Software / service
- Evaluation: Scoped test passed
- Source: https://github.com/trufflesecurity/trufflehog
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=96efd5297fe1
- Evaluated: 2026-10-10T16:39:13.262072Z
- Version/source: 3.99.2; official Linux ARM64 release

**Scope:** Run TruffleHog filesystem on one synthetic credential-shaped file and a clean control in a network-none container, with no-update and no-verification.

**Observed:** The seeded file produced one unverified GitHub-pattern finding; the clean control produced no findings. No provider verification occurred.

**Checks:**
- passed: Official release identity — Version and publisher checksum matched the official 3.99.2 release.
- passed: Synthetic unverified detection — One unverified pattern finding with verification/update flags off.
- passed: Clean filesystem control — No finding JSON was emitted for clean input.

**Limits:**
- The string is deliberately synthetic; it was never verified or used as a credential.
- Git history, cloud sources, alternate detectors and verified-secret operation were not tested.
- Finding output is redacted; exit 0 by itself is not a no-secret signal.

**Use note:** Disable live credential verification unless separately approved; never publish secret values.

## uBlock Origin

Reduce ads and tracking requests in a dedicated, supported research browser.

- Kind: Software / service
- Evaluation: Test blocked
- Source: https://github.com/gorhill/uBlock
- Toolbelt entry: https://toolbelt.utlyze.com/?tool=f58fd4cb2c55
- Evaluated: 2026-10-10T16:51:34.184473Z
- Version/source: 1.75.0 official signed XPI; disposable Firefox 153.0

**Scope:** Attempt to install the official signed extension in a new disposable Firefox profile and apply a localhost-only custom script filter in a network-none container.

**Observed:** Both synthetic scripts loaded before installation and the add-on installed. Extension settings/editor automation hit access, click-interception and timeout errors before a completed post-filter observation.

**Checks:**
- passed: Official extension acquisition — Signed 1.75.0 XPI downloaded from the maintainer release; file SHA256 preserved.
- passed: Unfiltered localhost baseline — Both seeded scripts loaded in the disposable browser before extension installation.
- blocked: Custom-filter execution — Settings automation timed out before a post-filter result; earlier access/click errors are preserved.

**Limits:**
- No claim that request blocking passed or failed: the core filtered-page assertion was not reached.
- Default lists, remote list updates, ad/tracker effectiveness, popup behavior and other browsers were not tested.
- Only disposable container profiles were used; no shared user browser/profile was modified.
- Firefox privileged driver access was limited to reading this disposable extension UUID.

**Use note:** Check current browser support. Full uBlock Origin depends on Manifest V2 support; uBlock Origin Lite is a different Manifest V3 option with different capabilities. Test compatibility in a dedicated research profile.

