Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
HashSiphon preview

HashSiphon

GitHubivancabrera02/hashsiphon

Extracts the current user's NetNTLMv2 hash via HTTP authentication proxying, avoiding direct SSPI calls; v2 delegates auth to the BITS service to…

defensive-toolsinformation-gatheringpassword-attacks+3
32
8 days ago
cve-2026-22732-poc preview

cve-2026-22732-poc

GitHubdylan-chainguard/cve-2026-22732-poc

Proof-of-concept demonstrating CVE-2026-22732, a Spring Security flaw where setIntHeader("Content-Length") drops all security headers, with…

defensive-toolseducationexploitation+3
4 days ago
py preview

py

GitHubantiwar3/py

飘云ark(pyark)

defensive-toolsdigital-forensicsincident-response+3
53118 days ago
CVE-2026-17543-PHP-Exposure-Validator preview

CVE-2026-17543-PHP-Exposure-Validator

GitHubpratham220/cve-2026-17543-php-exposure-validator

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

defensive-toolsinformation-gatheringpenetration-testing+5
1 month ago
http-stalling-detector preview

http-stalling-detector

GitHubcorelight/http-stalling-detector

Detect HTTP stalling attacks like slowloris with Bro

anomaly-detectiondefensive-toolsintrusion-detection+2
198 years ago
zeek-mercury-npf preview

zeek-mercury-npf

GitHubcorelight/zeek-mercury-npf

Zeek plugin generating Mercury NPF fingerprints for TCP, TLS/DTLS, QUIC, HTTP, SSH, OpenVPN, and STUN to support network security monitoring.

defensive-toolsnetwork-securitypacket-sniffing-analysis
1 month ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

anti-botapi-securitydefensive-tools+7
9.8k2 months ago
wazuh-nginx-cve-2026-42945-sca-lab preview

wazuh-nginx-cve-2026-42945-sca-lab

GitHubsoksofos/wazuh-nginx-cve-2026-42945-sca-lab

Centralized Wazuh SCA Assessment for CVE-2026-42945 on NGINX Servers

configuration-auditingdefensive-toolseducation+3
4 months ago
fire-wall-server preview

fire-wall-server

GitHubnosie12/fire-wall-server

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

defensive-toolseducationintrusion-detection+3
1 year ago
apache_audit_cve-2026-23918 preview

apache_audit_cve-2026-23918

GitHubsibersan/apache_audit_cve-2026-23918

Python toolkit to audit Apache HTTP Server against CVE-2026-23918 (HTTP/2 double-free RCE) and 4 related CVEs. Passive scanner with ALPN verification…

configuration-auditingdefensive-toolsincident-response+3
4 months ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.1k1 day ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k1 day ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubhnytgl/cve-2026-42945

这是一个面向防守和内网排查的 CVE-2026-42945 静态检测工具,用于检查 NGINX ngx_http_rewrite_module 相关配置是否存在高风险 rewrite 组合。

configuration-auditingdefensive-toolsdevsecops+3
13 months ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubhnytgl/cve-2026-34197

这是一个面向防守和内网排查的 Apache ActiveMQ Classic 暴露面检测工具,用于辅助评估 CVE-2026-34197 相关风险。

configuration-auditingdefensive-toolsinformation-gathering+3
13 months ago
SharePointDumper preview

SharePointDumper

GitHubzh54321/sharepointdumper

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

authenticationcloud-securitydata-exfiltration+7
1917 months ago
burner-net preview

burner-net

GitHubkrixx1337/burner-net

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻

anti-botauthenticationdata-exfiltration+7
3110 days ago
macnoise preview

macnoise

GitHub0xv1n/macnoise

Extensible MacOS system telemetry generator.

defensive-toolseducationincident-response+4
6716 hours ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.8k11 days ago
Previous12Next