Cyber Essentials Assessment
Check identity, devices, patching, malware protection, backups, network exposure and data protection against Cyber Essentials-style controls.
Open ToolUse the free public tools to identify gaps, explore options and build plans. Assessment-heavy and managed-review platforms now sit under Aid+, which helps fund the free Security Aid mission for SMBs.
These tools stay free for public use and are designed to give SMBs practical value without needing a paid engagement.
Check identity, devices, patching, malware protection, backups, network exposure and data protection against Cyber Essentials-style controls.
Open ToolMap identity, endpoint, cloud, SaaS, network, email, server and detection controls to identify visibility gaps and maturity priorities.
Open ToolEstimate log ingestion, retention strategy and likely monthly or annual cost for Sentinel, Splunk and other SIEM platforms.
Open ToolTranslate common hunting queries between KQL, Splunk, OpenSearch, LogScale, SentinelOne-style syntax and other SIEM query languages.
Open ToolGenerate a structured incident response playbook with scenario-specific flow diagrams, procedures and stakeholder templates.
Open ToolAssess Defender XDR, Endpoint, ASR, Identity, Office 365, Cloud Apps, Servers, Cloud, IoT, mobile and KQL data coverage.
Open ToolAssess Microsoft Purview information protection, sensitivity labels, DLP coverage, alerting and governance controls.
Open ToolAssess Zscaler DLP inspection scope, policy attachment, match quality, incident handling and operational tuning.
Open ToolAssess BeyondTrust Password Safe, endpoint privilege management, session control and PAM governance coverage.
Open ToolReview Salesforce containment actions for both single-user and tenant-scale incidents, including bulk user scoping, session revocation, connected apps, OAuth, audit trails, Event Monitoring, jobs and export evidence.
Open ToolReview Okta containment actions for both single-user and mass compromise scenarios, including bulk user scoping, session revocation, MFA, admin role abuse, suspicious apps, OAuth grants, network zones and System Log evidence.
Open ToolReview Entra ID, Azure and Microsoft 365 containment actions for both targeted and mass compromise scenarios, including bulk user scoping, service principals, consent abuse, legacy auth, mailbox abuse and audit evidence.
Open ToolPaste encoded payloads, obfuscated code or suspicious snippets and get the best next CyberChef recipe to try without executing the sample.
Open ToolDrop in a HAR file to highlight suspicious requests, injected JavaScript patterns, external infrastructure pivots and investigation priorities.
Open ToolPaste suspicious or malicious code to auto-detect the language, reconstruct common obfuscation patterns, decode string resolvers and break down functions, strings, IOCs and deobfuscation priorities without executing it.
Open ToolPaste or upload suspicious JavaScript to statically deobfuscate it, explain what the functions do, identify likely malware behaviour, extract IOCs and enrich domains, URLs and IPs through the backend VirusTotal integration.
Open ToolUpload or paste suspicious package malware to recover targeted secret locations, environment variables, file paths, process targets and visible exfiltration indicators without scanning the visitor device.
Open ToolPaste or upload WordPress or Magento database exports to identify suspicious snippets, external script injections, admin users, active sessions and recently modified artefacts for web compromise hunting.
Open ToolGenerate a practical cyber security questionnaire to send to suppliers, SaaS providers and outsourced IT partners.
Open ToolStream large web access or error logs locally, flag suspicious requests, align activity to likely findings and review the output in filterable tables and timeline views.
Open ToolThese are the tools and assessments most suited to Aid+ because they usually involve consultancy-grade review, custom validation, reporting and follow-up work. The first 4 hours of advisory-led services are free; delivery after that funds the free service and managed security mission.
Critical external asset discovery for internet-facing domains, infrastructure, exposed admin surfaces and newly discovered public assets.
Paid Aid+ platform. Advisory scoping starts with 4 free hours; ongoing delivery, tuning and reporting are paid. Profit funds free SMB services and the managed service mission.
Open WorkspaceOne premium assessment platform where you choose the assessment you need and complete the relevant control review in one Aid+ workspace.
Paid Aid+ platform. First 4 advisory hours free, then assessment and reporting work is billed at discretionary standard rates.
Open WorkspacePremium containment and mass-compromise review delivery for Azure/M365, Okta and Salesforce environments.
Paid Aid+ platform. The first 4 hours are free for triage and scoping; deeper investigation, reporting and workflow design are paid.
Open Workspace