← PACKETHUNT HOME

Help & Tool Guide

A quick reference for what each PacketHunt tool does, and why a few of them ask you to sign in first.

Why some tools ask you to sign in

The active scan tools reach out and send real traffic to whatever target you enter — from this server's IP address. Left wide open, that would let anyone use PacketHunt as a free, anonymous scanning relay against third parties. To keep that from happening, those tools require a one-time SMS verification:

On the home page a padlock marks the tools that need sign-in. Once you're verified it turns green and opens , and the header shows Signed in. Everything else is open to everyone, no account needed.

Network Tools

⌨️
Command Line Tests 🔒 Sign-in
Runs ping, dig, nmap, a TLS cipher scan and an MTR path trace against a host you specify — the classic terminal diagnostics, from the server, in one form.
🌐
DNS Checker
Resolves a name across six public resolvers (Google, Cloudflare, Quad9 and others) side by side, so you can spot split-horizon answers, propagation lag or filtering differences.
🛰️
BGP Lookup
For an IP, prefix or ASN: the origin AS, RPKI validity, the upstream transit chain, and the full prefix inventory an organisation announces.
Network Validation 🔒 Sign-in
Repeats connectivity checks (ping / HTTP / TLS) over several iterations to confirm a target is reliably reachable, not just up for one lucky packet.
📡
Basic Port Scan 🔒 Sign-in
A quick TCP port sweep of a single host or a small CIDR range to see what's listening.

Security Tools

🔎
IP Intelligence
Geolocation, ASN & ownership, reverse DNS, Shodan exposure and a composite IP-quality/risk score for up to 50 IPs or hostnames at once, with CSV export.
🔓
Exposure Tester 🔒 Sign-in
Opens the real protocol handshake for each service (not just a SYN), so it can tell a genuinely reachable service from a port an application firewall merely answers on.
📜
Certificate Scanner 🔒 Sign-in
Sweeps a subnet and collects the TLS certificate from every host that responds — handy for inventorying certs and spotting expiries across a range.
🏅
SSL Server Test 🔒 Sign-in
Grades a public server's TLS configuration — protocols, cipher strength, certificate, chain trust and HSTS — with an A+ to F score, in the spirit of SSL Labs.
🔧
SSL Certificate Tools
Decode a certificate to plain-English details, and convert between PEM, DER, P7B and PFX. Paste or upload — nothing leaves your browser except the bytes to convert.

Proxy & Web Tools

🛡️
Validate Proxy Enforcement
Opens iframes to known category test sites to show whether your Zscaler / Netskope (or other) web policy actually blocks them from where you're sitting.
📤
DLP Exfiltration Test
Attempts a sample upload of fake credit-card / SSN / medical data over HTTP and HTTPS to see whether your DLP blocks it. The sample content is discarded on arrival — never stored.
🏷️
Website Category Check
Looks up the content category and risk rating for up to 25 URLs at once.
📍
My IP Info
Your public IP, geolocation, request headers and proxy detection — exactly as the server sees you.
HTTP/2 vs HTTP/1.1
Detects the protocol your connection negotiates, then races HTTP/2 against HTTP/1.1 head to head — if HTTP/2 loses, a proxy is likely downgrading you.

Questions or something not behaving? Use the 💬 Feedback button on any page.
PacketHunt is a free diagnostics toolkit — please only scan hosts and networks you're authorised to test.