Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
120 results
mimicry preview

mimicry

GitHubchaitin/mimicry

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

defensive-toolsincident-responsered-teaming+1
625 months ago
Nemesis preview

Nemesis

GitHubzypherion-technologies/nemesis

.NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on disk binaries.

defensive-toolsdynamic-analysis-sandboxingmalware-analysis+2
421 month ago
BadExclusionsNWBO preview

BadExclusionsNWBO

GitHubiamagarre/badexclusionsnwbo

BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR

defensive-toolsinformation-gatheringpenetration-testing+2
762 years ago
mimikatz-detector-condrv preview

mimikatz-detector-condrv

GitHubnccgroup/mimikatz-detector-condrv

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

anomaly-detectiondefensive-toolsincident-response+3
423 years ago
HouseProxy preview

HouseProxy

GitHubmthbernardes/houseproxy

Protect your parents from phishing

defensive-toolseducationphishing+1
418 years ago
pisiguard preview

pisiguard

GitHubmohamed--abdel-maksoud/pisiguard

PISIGuard runs entirely in your browser. It spots names, email addresses, phone numbers, credit card numbers, passwords, API keys, and more, replaces…

ai-securitydefensive-toolsprivacy+1
2317 days ago
DDWPasteRecon preview

DDWPasteRecon

GitHubviralmaniar/ddwpasterecon

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

data-exfiltrationdefensive-toolsincident-response+4
454 years ago
conference_talks preview

conference_talks

GitHubyardenshafir/conference_talks

Slides from various conference talks

curated-resourcesdefensive-toolseducation+3
393 years ago
IMDShift preview

IMDShift

GitHubayushpriya10/imdshift

Automates migration of AWS workloads from IMDSv1 to IMDSv2 to mitigate SSRF attacks. Detects IMDSv1 usage across EC2, ECS, EKS, Lightsail, and more,…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
563 years ago
kprotect preview

kprotect

GitHubkhoinp1012/kprotect

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

authentication-authorizationcloud-securitydefensive-tools+4
365 months ago
certgraveyard_yara preview

certgraveyard_yara

GitHubtjnel/certgraveyard_yara

Automated YARA rule generation from the Cert Central compromised certificate database.

binary-analysisdefensive-toolsforensics+2
150 days ago
sigint-hombre preview

sigint-hombre

GitHubmalvuln/sigint-hombre

Dynamically generated Suricata rules from real-time threat feeds

defensive-toolsdns-analysisintrusion-detection+4
147 months ago
bordair-detector preview

bordair-detector

GitHubjosh-blythe/bordair-detector

Two-stage prompt-injection and jailbreak detector: regex gates plus a quantised DeBERTa-v3 ONNX classifier, with image, document, and audio support.…

adversarial-attackai-securitycode-analysis+5
1 month ago
insmod_block preview

insmod_block

GitHubnu11secur1ty/insmod_block

This is a "insmod" blocking tool module for Linux Kernel, protecting the user from the loading of malicious code in Linux Kernel - rootkits, for…

defensive-tools
73 years ago
CVE-2025-54253-Inside-the-Adobe-AEM-Forms-Zero-Day preview

CVE-2025-54253-Inside-the-Adobe-AEM-Forms-Zero-Day

GitHubadityabhatt3010/cve-2025-54253-inside-the-adobe-aem-forms-zero-day

Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.

defensive-toolseducationexploitation+3
109 months ago
redact preview

redact

GitLabphpboyscout/go/redact

Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. ·…

defensive-toolslog-analysisprivacy+1
6 days ago
fim-ebpf preview

fim-ebpf

GitHubharshavmb/fim-ebpf

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

defensive-toolsdigital-forensicsforensics+1
77 months ago
Ghost-CMS-Code-Injection-Audit-CVE-2026-26980 preview

Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

GitHubkulik-labs-development/ghost-cms-code-injection-audit-cve-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

code-analysisdefensive-toolsincident-response+3
3 months ago
Previous1234567Next