Attack Surface Area Calculator
Calculate your application attack surface from endpoints, weighting by exposure type. Public (3x), authenticated (2x), internal (1x) scoring.
Password entropy, risk assessment, and threat tools. Browse our free security tools below — no sign-up required.
Calculate your application attack surface from endpoints, weighting by exposure type. Public (3x), authenticated (2x), internal (1x) scoring.
Calculate brute-force attack time for any keyspace. Compare online, offline, and GPU attack speeds to assess password and key security.
Calculate bug bounty program ROI from bounty payouts, management costs, and estimated breach prevention value. Justify your bounty budget.
Calculate days remaining until SSL/TLS certificate expiration. Get urgency status and renewal reminders based on your cert dates.
Estimate annual SSL/TLS certificate costs including cert price, domain count, and IT management hours. Plan your certificate budget.
Calculate vulnerability density as defects per 1,000 lines of code. Classify severity by industry thresholds and track code quality.
Calculate CVSS v3.1 Base Score from attack vector, complexity, privileges, user interaction, scope, and CIA impact metrics.
Estimate dynamic application security testing scan duration from page count, average test time per page, and crawl depth factor.
Estimate total data breach cost from record count, per-record cost ($164 avg), notification, legal, and remediation expenses.
Calculate data loss prevention implementation costs from license fees, deployment hours, policy tuning, and ongoing management expenses.
Estimate insider threat incident costs from investigation, data loss, remediation, legal expenses, and productivity impact factors.
Configure JWT access and refresh token lifetimes. See timestamps for issued, expiry, and refresh schedule with recommended TTL ranges.
Calculate risk reduction from MFA deployment. See how adoption rate and MFA effectiveness (99.9%) reduce account compromise probability.
Estimate how long it takes to crack a password using brute force. Compare GPU attack speeds for different password lengths and charsets.
Calculate password entropy in bits based on length and character set size. Evaluate password strength tiers from weak to very strong.
Score password strength from 0–4 based on length, charset diversity, dictionary patterns, and entropy. Get actionable improvement tips.
Calculate organizational phishing risk score from training coverage, click rates, MFA adoption, and exposure. Score 0-100 with risk level.
Calculate risk score from likelihood and impact ratings (1-5 scale). Visualize results in a risk matrix heatmap with severity levels.
Calculate static analysis finding rate and false positive rate from SAST scan results. Track true vs false positive trends over time.
Calculate ROI of security awareness training from incidents prevented, average incident cost, and total training investment per employee.
Calculate re-authentication frequency from session and timeout durations. Estimate annual re-auth events and productivity impact.
Score threats using the STRIDE model. Rate Spoofing, Tampering, Repudiation, Info Disclosure, DoS, and Elevation for aggregate risk.
Calculate token expiration time from issue timestamp and TTL. See remaining seconds, minutes, and hours until your auth token expires.