Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
118 results
ASM-Obfuscator preview

ASM-Obfuscator

GitHubgmh5225/asm-obfuscator

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

binary-analysisdebuggersdefensive-tools+1
7
2 years ago
azure-security-auditor preview

azure-security-auditor

GitHubneelkotnis/azure-security-auditor

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

cloud-infrastructure-securitycloud-securityconfiguration-auditing+5
122 days ago
CVE-2026-64638-PoC-XSS2Shell- preview

CVE-2026-64638-PoC-XSS2Shell-

GitHubboreas37/cve-2026-64638-poc-xss2shell-

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

configuration-auditingdefensive-toolsexploitation+6
3911 days ago
MacShellSwift preview

MacShellSwift

GitHubcedowens/macshellswift

Proof of concept MacOS post exploitation tool written in Swift. Designed as a POC for blue teams to build macOS detections. Author: Cedric Owens

defensive-toolspenetration-testingpost-exploitation+2
1245 years ago
dfir-orc preview

dfir-orc

GitHubdfir-orc/dfir-orc

Forensics artefact collection tool for systems running Microsoft Windows

defensive-toolsdigital-forensicsforensics+2
44623 days ago
AD-description-password-finder preview

AD-description-password-finder

GitHubassurancemaladiesec/ad-description-password-finder

Retrieve AD accounts description and search for password in it

authenticationdefensive-toolsinformation-gathering+5
814 years ago
drawio-threatmodeling preview

drawio-threatmodeling

GitHubmichenriksen/drawio-threatmodeling

Draw.io libraries for threat modeling diagrams

curated-resourcesdefensive-toolsdevsecops+1
8005 years ago
safetext preview

safetext

GitHubgoogle/safetext

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.

defensive-toolsdevsecopsscripting-automation+1
1514 months ago
sysmon-parser preview

sysmon-parser

GitHubolafhartong/sysmon-parser

Generates and maintains Azure Sentinel parser for Sysmon events, normalizing all Windows endpoint telemetry into a searchable log schema via…

cloud-securitydefensive-toolslog-analysis+1
187 months ago
text4shell-tools preview

text4shell-tools

GitHubjfrog/text4shell-tools
binary-analysiscode-analysisdefensive-tools+3
1043 years ago
ScubaGear preview

ScubaGear

GitHubcisagov/scubagear

Automation to assess the state of your M365 tenant against CISA's baselines

cloud-securityconfiguration-auditingdefensive-tools+3
2.6k10 days ago
YARA_Rules preview

YARA_Rules

GitHubmalgamy/yara_rules
curated-resourcesdefensive-toolsincident-response+3
653 years ago
untitledgoosetool preview

untitledgoosetool

GitHubcisagov/untitledgoosetool

Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to…

cloud-securitydefensive-toolsdigital-forensics+4
9626 months ago
Hunt-Weird-ImageLoads preview

Hunt-Weird-ImageLoads

GitHubtheflink/hunt-weird-imageloads

Small tool to play with IOCs caused by Imageload events

anomaly-detectiondefensive-toolsincident-response+2
473 years ago
detection-validation preview

detection-validation

GitHubalwashali/detection-validation

Detection rule validation

adversarial-attackdefensive-toolsintrusion-detection+1
422 years ago
slack-watchman preview

slack-watchman

GitHubpapermtn/slack-watchman

Slack enumeration and exposed secrets detection tool

defensive-toolsinformation-gatheringosint+3
4023 months ago
BlockOpenHandle preview

BlockOpenHandle

GitHubsaadahla/blockopenhandle

Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory…

authentication-authorizationdefensive-toolsprivacy
1713 years ago
pySigma preview

pySigma

GitHubsigmahq/pysigma

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

defensive-toolsintrusion-detectionlog-analysis+2
5875 days ago
Previous1234567Next