Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
crowdsec preview

crowdsec

GitHubcrowdsecurity/crowdsec

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

anti-botdefensive-toolsids-ips-evasion+6
15.0k
6h 16m ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.9k14h 36m ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.1k16h 27m ago
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

anomaly-detectionanti-botdefensive-tools+11
8.6k19h 6m ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k1 day ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

anti-botapi-securitydefensive-tools+7
9.8k1 day ago
async-http-client-check preview

async-http-client-check

GitHubxiaoqimikko/async-http-client-check

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

defensive-toolsdevsecopsstatic-analysis+4
13 days ago
macnoise preview

macnoise

GitHub0xv1n/macnoise

Extensible MacOS system telemetry generator.

defensive-toolseducationincident-response+4
7217 days ago
cve-2026-22732-poc preview

cve-2026-22732-poc

GitHubdylan-chainguard/cve-2026-22732-poc

Proof-of-concept demonstrating CVE-2026-22732, a Spring Security flaw where setIntHeader("Content-Length") drops all security headers, with…

defensive-toolseducationexploitation+3
21 days ago
HashSiphon preview

HashSiphon

GitHubivancabrera02/hashsiphon

Extracts the current user's NetNTLMv2 hash via HTTP authentication proxying, avoiding direct SSPI calls; v2 delegates auth to the BITS service to…

defensive-toolsinformation-gatheringpassword-attacks+3
3525 days ago
burner-net preview

burner-net

GitHubkrixx1337/burner-net

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻

anti-botauthenticationdata-exfiltration+7
3027 days ago
py preview

py

GitHubantiwar3/py

飘云ark(pyark)

defensive-toolsdigital-forensicsincident-response+3
5291 month ago
libhtp preview
Archived

libhtp

GitHuboisf/libhtp

Security-aware HTTP protocol parser library used by IDS/IPS engines to inspect and normalize HTTP traffic for threat detection.

defensive-toolsintrusion-detectionnetwork-security+3
3091 month ago
CVE-2026-17543-PHP-Exposure-Validator preview

CVE-2026-17543-PHP-Exposure-Validator

GitHubpratham220/cve-2026-17543-php-exposure-validator

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

defensive-toolsinformation-gatheringpenetration-testing+5
1 month ago
zeek-mercury-npf preview

zeek-mercury-npf

GitHubcorelight/zeek-mercury-npf

Zeek plugin generating Mercury NPF fingerprints for TCP, TLS/DTLS, QUIC, HTTP, SSH, OpenVPN, and STUN to support network security monitoring.

defensive-toolsnetwork-securitypacket-sniffing-analysis
2 months ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubhnytgl/cve-2026-34197

这是一个面向防守和内网排查的 Apache ActiveMQ Classic 暴露面检测工具,用于辅助评估 CVE-2026-34197 相关风险。

configuration-auditingdefensive-toolsinformation-gathering+3
13 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubhnytgl/cve-2026-42945

这是一个面向防守和内网排查的 CVE-2026-42945 静态检测工具,用于检查 NGINX ngx_http_rewrite_module 相关配置是否存在高风险 rewrite 组合。

configuration-auditingdefensive-toolsdevsecops+3
13 months ago
apache_audit_cve-2026-23918 preview

apache_audit_cve-2026-23918

GitHubsibersan/apache_audit_cve-2026-23918

Python toolkit to audit Apache HTTP Server against CVE-2026-23918 (HTTP/2 double-free RCE) and 4 related CVEs. Passive scanner with ALPN verification…

configuration-auditingdefensive-toolsincident-response+3
4 months ago
Previous12Next