A research catalogue, not a guarantee.
ThreatByt helps researchers find relevant public tools and investigation workflows. An entry means it passed the current review process; it does not certify that a third-party service is safe, accurate, legal in every jurisdiction, or suitable for every investigation.
Review standard
Pending entries receive automated evidence checks and a human makes the final decision. The checks are intentionally conservative.
The entry must provide a directly usable investigation capability. Lists, reports, news archives, and raw feeds are not treated as tools.
Input types describe what an investigator actually supplies, while categories describe the investigation discipline.
The official website and repository are checked without bypassing access controls. A blocked automated check is marked inconclusive, not healthy.
Repository activity is evidence, not proof. Hosted services without public source code require manual verification.
Descriptions avoid guarantees. Limitations, pricing boundaries, privacy risks, and authorization requirements should be disclosed.
Classification method
Navigation uses exact, reviewed taxonomy rules. Arbitrary tag fragments do not qualify a tool for an indicator category.
For example, mobile, cell and telephone are aliases for the phone input. Hash browsing covers MD5, SHA-1, SHA-256 and SHA-512. Category pages use explicit category names and input mappings. When a plain word could be either a username or a tool name, direct name and tag matches are also considered.
Health checks and dates
Each tool page shows the last automated check and whether manual review is advised.
A successful HTTP response only proves reachability at that moment. Repository activity does not prove the hosted tool works. Services that return 401, 403 or 429 are marked for manual review. Catalogue edits clear old research evidence so changed metadata must be checked again.
Vulnerability intelligence sources
CVE coverage prioritizes primary and authoritative public sources.
Corrections are welcome. If an entry is wrong or outdated, use the catalogue correction process. Reports should include evidence from an official website, repository, or documentation.