Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

anomaly-detectionanti-botdefensive-tools+11
8.6k
15h 12m ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k18h 45m ago
burner-net preview

burner-net

GitHubkrixx1337/burner-net

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻

anti-botauthenticationdata-exfiltration+7
312 days ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.8k3 days ago
crowdsec preview

crowdsec

GitHubcrowdsecurity/crowdsec

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

anti-botdefensive-toolsids-ips-evasion+6
14.8k4 days ago
py preview

py

GitHubantiwar3/py

飘云ark(pyark)

defensive-toolsdigital-forensicsincident-response+3
53110 days ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.0k21 days ago
CVE-2026-17543-PHP-Exposure-Validator preview

CVE-2026-17543-PHP-Exposure-Validator

GitHubpratham220/cve-2026-17543-php-exposure-validator

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

defensive-toolsinformation-gatheringpenetration-testing+5
1 month ago
zeek-mercury-npf preview

zeek-mercury-npf

GitHubcorelight/zeek-mercury-npf

Zeek plugin generating Mercury NPF fingerprints for TCP, TLS/DTLS, QUIC, HTTP, SSH, OpenVPN, and STUN to support network security monitoring.

defensive-toolsnetwork-securitypacket-sniffing-analysis
1 month ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

anti-botapi-securitydefensive-tools+7
9.8k2 months ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubhnytgl/cve-2026-34197

这是一个面向防守和内网排查的 Apache ActiveMQ Classic 暴露面检测工具,用于辅助评估 CVE-2026-34197 相关风险。

configuration-auditingdefensive-toolsinformation-gathering+3
13 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubhnytgl/cve-2026-42945

这是一个面向防守和内网排查的 CVE-2026-42945 静态检测工具,用于检查 NGINX ngx_http_rewrite_module 相关配置是否存在高风险 rewrite 组合。

configuration-auditingdefensive-toolsdevsecops+3
13 months ago
apache_audit_cve-2026-23918 preview

apache_audit_cve-2026-23918

GitHubsibersan/apache_audit_cve-2026-23918

Python toolkit to audit Apache HTTP Server against CVE-2026-23918 (HTTP/2 double-free RCE) and 4 related CVEs. Passive scanner with ALPN verification…

configuration-auditingdefensive-toolsincident-response+3
3 months ago
wazuh-nginx-cve-2026-42945-sca-lab preview

wazuh-nginx-cve-2026-42945-sca-lab

GitHubsoksofos/wazuh-nginx-cve-2026-42945-sca-lab

Centralized Wazuh SCA Assessment for CVE-2026-42945 on NGINX Servers

configuration-auditingdefensive-toolseducation+3
3 months ago
AMSI.fail preview

AMSI.fail

GitHubflangvik/amsi.fail

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

defensive-toolsexploitationids-ips-evasion+2
4626 months ago
SharePointDumper preview

SharePointDumper

GitHubzh54321/sharepointdumper

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

authenticationcloud-securitydata-exfiltration+7
1677 months ago
h2t preview

h2t

GitHubgildasio/h2t

h2t (HTTP Hardening Tool) scans a website and suggests security headers to apply

configuration-auditingdefensive-toolsvulnerability-scanners+1
4118 months ago
HellPot preview

HellPot

GitHubyunginnanet/hellpot

HellPot is a cross-platform portal to endless suffering meant to punish unruly HTTP bots.

defensive-toolsweb-security
1.2k8 months ago
Previous12Next