Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
65 results
MemGuard preview

MemGuard

GitHubprox0959/memguard

Zero-dependency Windows EDR utility that detects and mitigates unauthorized LSASS memory access, handle duplication, and LOLBin credential dumping in…

defensive-toolsdigital-forensicsincident-response+4
16h 45m ago
cplt preview

cplt

GitHubnavikt/cplt

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

ai-securitycommand-and-controlconfiguration-auditing+7
1212 days ago
CVE-2026-41089-Netlogon-RCE-PoC preview

CVE-2026-41089-Netlogon-RCE-PoC

GitHubgillarchnganasan2735/cve-2026-41089-netlogon-rce-poc

Automate Netlogon CVE-2026-41089 validation and defensive testing through integrated AI security workflows, enabling rapid risk assessment and…

defensive-toolseducationexploitation+5
3 days ago
adnullenum preview

adnullenum

GitHubcrypt0p3g/adnullenum

One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.

defensive-toolsinformation-gatheringnetwork-security+5
377 days ago
Responsible-Alliance-Protocol preview

Responsible-Alliance-Protocol

GitHubphilippeabraxas-jpg/responsible-alliance-protocol

Safety cannot be a prompt instruction. TBP provides an external execution-layer boundary for autonomous agents, enforcing hard F/I/W invariants via…

ai-securityauthentication-authorizationconfiguration-auditing+7
10 days ago
OpenHunterAI preview

OpenHunterAI

GitHublumoslab-innovation/openhunterai

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

ai-securityapi-securityapi-security-testing+9
32410 days ago
ADRecon preview

ADRecon

GitHubadrecon/adrecon

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

defensive-toolsdigital-forensicsincident-response+6
9811 year ago
ThreatLens preview

ThreatLens

GitHubabdaullahag/threatlens

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

defensive-toolsincident-responseinformation-gathering+7
257 days ago
TryHackMe-Blue-MS17-010 preview

TryHackMe-Blue-MS17-010

GitHubporcumarcooo/tryhackme-blue-ms17-010

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

ctfdefensive-toolseducation+4
14 days ago
enhanced-iframe-protection preview

enhanced-iframe-protection

GitHubmalwarecube/enhanced-iframe-protection

A lightweight extension to automatically detect and provide verbose warnings for embedded iframe elements in order to protect against…

defensive-toolseducationphishing+1
503 years ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
27 days ago
CVE-2026-31431-detection-defense preview

CVE-2026-31431-detection-defense

GitHubdetect-defenselab/cve-2026-31431-detection-defense

Research and detection guidance for CVE-2026-31431, an io_uring-based bypass of syscall monitoring. Provides detection rules for Tetragon, Falco, and…

container-securitydefensive-toolsexploitation+2
4 months ago
AdGuardHome preview

AdGuardHome

GitHubadguardteam/adguardhome

Network-wide ads & trackers blocking DNS server

defensive-toolsdns-analysisnetwork-security+1
37.1k19h 2m ago
nginx-ultimate-bad-bot-blocker preview

nginx-ultimate-bad-bot-blocker

GitHubmitchellkrogza/nginx-ultimate-bad-bot-blocker

Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS,…

anti-botdefensive-toolsnetwork-security+1
4.8k14h 3m ago
parsedmarc preview

parsedmarc

GitHubdomainaware/parsedmarc

A Python package and CLI for parsing aggregate and forensic DMARC reports

authenticationdefensive-toolsdns-analysis+2
1.3k21h 33m ago
Guardrails preview

Guardrails

GitHubnvidia-nemo/guardrails

Programmable guardrails for LLM chat apps: enforce input/output rails, block jailbreaks and prompt injections, detect hallucination, and mask…

ai-securityanomaly-detectiondefensive-tools+3
7.2k3 days ago
Windows-Defender-Security-Auditor-CVE-2026-50656- preview

Windows-Defender-Security-Auditor-CVE-2026-50656-

GitHubeh-amish/windows-defender-security-auditor-cve-2026-50656-

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

configuration-auditingdefensive-toolsincident-response+8
1 month ago
HydraDragonAV-Mobile preview

HydraDragonAV-Mobile

GitHubhydradragonantivirus/hydradragonav-mobile

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

android-securitydefensive-toolsdynamic-analysis-sandboxing+6
1712 days ago
Previous1234Next