Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Defensive Tools

Tools for blue team, defensive security, and threat protection.

Kitploit recommended

Top tools

10 selected
wazuh preview#1

wazuh

GitHubwazuh/wazuh
16.5k9h 17m ago
suricata preview#2

suricata

GitHuboisf/suricata
6.5k18 days ago
zeek preview#3

zeek

GitHubzeek/zeek
7.8k5h 37m ago
osquery preview#4

osquery

GitHubosquery/osquery
23.4k4 days ago
falco preview#5

falco

GitHubfalcosecurity/falco
9.4k5 days ago
securityonion preview#6

securityonion

GitHubsecurity-onion-solutions/securityonion
4.9k10 days ago
crowdsec preview#7

crowdsec

GitHubcrowdsecurity/crowdsec
14.5k5 days ago
trivy preview#8

trivy

GitHubaquasecurity/trivy
37.4k11h 42m ago
sigma preview#9

sigma

GitHubsigmahq/sigma
10.9k6 days ago
velociraptor preview#10

velociraptor

GitHubvelocidex/velociraptor
4.2k12h 56m ago
NewestRelevanceMost popularRecently updated
1234 results
CVE-2022-30190-ASR-Senintel-Process-Pickup preview

CVE-2022-30190-ASR-Senintel-Process-Pickup

GitHubdov3y/cve-2022-30190-asr-senintel-process-pickup

Picking up processes that have triggered ASR related to CVE-2022-30190

defensive-toolsvulnerability-analysisexploitation+1
4 years ago
cve-2019-15107-lab preview

cve-2019-15107-lab

GitHubshambhavim18/cve-2019-15107-lab

Docker-based lab demonstrating CVE-2019-15107, the Webmin unauthenticated RCE, covering deployment, exploitation, detection, and remediation.

defensive-toolscontainer-securityvulnerability-analysis+5
1 day ago
CVE-2023-43804 preview

CVE-2023-43804

GitHubdeepanshu-khurana/cve-2023-43804

Containerized three-tier lab reproducing CVE-2023-43804 urllib3 cookie leak via cross-origin redirects, with exploit script and patch verification.

defensive-toolscontainer-securityvulnerability-analysis+5
1 day ago
CVE-2023-27163-lab preview

CVE-2023-27163-lab

GitHubamulyakaushik/cve-2023-27163-lab

Docker-based lab reproducing CVE-2023-27163 SSRF in Request-Baskets, with exploitation verification, detection script, and network-isolation…

defensive-toolscontainer-securityvulnerability-analysis+6
1 day ago
hol-guard preview

hol-guard

GitHubhashgraph-online/hol-guard

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

defensive-toolsstatic-analysisvulnerability-scanners+7
6341 day ago
CVE-2025-23134_fixes_code preview

CVE-2025-23134_fixes_code

GitHubthrilokh-q123/cve-2025-23134_fixes_code

The ASN1_STRING_set() function takes an `int` length, make sure the argument is not inadvertently truncated when it is called from asn1_ex_c2i().

defensive-toolsstatic-code-analysisvulnerability-analysis+2
1 day ago
CVE-2026-53266 preview

CVE-2026-53266

GitHubsuominen/cve-2026-53266

Single-page tracker recording which Linux distributions have shipped fixes for the CVE-2026-53266 netfilter ebtables SNAT ARP-rewrite page-cache…

defensive-toolsioc-managementvulnerability-analysis+1
1 day ago
async-http-client-check preview

async-http-client-check

GitHubxiaoqimikko/async-http-client-check

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

defensive-toolsstatic-analysisvulnerability-scanners+4
2 days ago
adnullenum preview

adnullenum

GitHubcrypt0p3g/adnullenum

One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.

defensive-toolsosintreconnaissance+5
374 days ago
irdoc-app preview

irdoc-app

GitHubsoc-irdoc/irdoc-app

Incident Response Documentation Platform

defensive-toolsioc-managementscripting-automation+5
32 days ago
CVE-2024-37054-PoC preview

CVE-2024-37054-PoC

GitHubclearlotus-git/cve-2024-37054-poc

Proof-of-concept and research repository for CVE-2024-37054, an unsafe deserialization flaw in MLflow PyFunc model loading that can lead to remote…

defensive-toolsvulnerability-analysisexploitation+4
2 days ago
news-8.6.0-cve-2026-8726-backport preview

news-8.6.0-cve-2026-8726-backport

GitHubshentao83/news-8.6.0-cve-2026-8726-backport

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

defensive-toolsstatic-code-analysisvulnerability-analysis+3
2 days ago
libhtp preview
Archived

libhtp

GitHuboisf/libhtp

Security-aware HTTP protocol parser library used by IDS/IPS engines to inspect and normalize HTTP traffic for threat detection.

defensive-toolspacket-sniffing-analysisvulnerability-analysis+3
3091 month ago
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

defensive-toolsstatic-analysisvulnerability-scanners+4
91 year ago
log4shell-audit preview

log4shell-audit

GitHubmcpmark-eval-liuhezi/log4shell-audit

Log4Shell (CVE-2021-44228) security review documentation and advisory triage

defensive-toolsvulnerability-analysisthreat-intelligence+2
3 days ago
CVE-2026-4282-Scanner preview

CVE-2026-4282-Scanner

GitHubhex0user/cve-2026-4282-scanner

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

defensive-toolsvulnerability-scannersvulnerability-analysis+4
21 month ago
CVE-2026-1731 preview

CVE-2026-1731

GitHubhex0user/cve-2026-1731

Python scanner that passively fingerprints exposed BeyondTrust Remote Support and Privileged Remote Access services to detect potential CVE-2026-1731…

defensive-toolsreconnaissancevulnerability-scanners+5
7 months ago
CVE-2026-18464 preview

CVE-2026-18464

GitHubghoxtbyte/cve-2026-18464

Security advisory and technical research notes for CVE-2026-18464, an unauthenticated denial-of-service flaw in the WP Maps Pro WordPress plugin…

defensive-toolsvulnerability-analysisweb-security+3
3 days ago
Previous1…626364…69Next