Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
406 results
yara-x preview

yara-x

GitHubvirustotal/yara-x

A rewrite of YARA in Rust.

binary-analysisdata-recoverydefensive-tools+14
1.3k9 days ago
bluemonday preview

bluemonday

GitHubmicrocosm-cc/bluemonday

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

api-securitycode-analysisdefensive-tools+3
3.7k1 year ago
hollows_hunter preview

hollows_hunter

GitHubhasherezade/hollows_hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory…

defensive-toolsforensicsincident-response+2
2.4k3 months ago
memguard preview

memguard

GitHubawnumar/memguard

Software sandbox for storage of sensitive information in memory.

cryptographydefensive-toolsencryption-decryption-tools+1
2.8k4 months ago
adversary_emulation_library preview

adversary_emulation_library

GitHubcenter-for-threat-informed-defense/adversary_emulation_library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

curated-resourcesdata-exfiltrationdefensive-tools+5
2.2k1 year ago
awesome-edr-bypass preview

awesome-edr-bypass

GitHubtkmru/awesome-edr-bypass

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

curated-resourcesdefensive-toolseducation+6
1.6k7 months ago
herpaderping preview

herpaderping

GitHubjxy-s/herpaderping

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

defensive-toolsexploitationpenetration-testing
1.2k3 years ago
365Inspect preview

365Inspect

GitHubsoteria-security/365inspect

A PowerShell script that automates the security assessment of Microsoft 365 environments.

cloud-securityconfiguration-auditingdefensive-tools+2
6611 year ago
sysmon-config preview

sysmon-config

GitHubion-storm/sysmon-config

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

anomaly-detectiondefensive-toolsdigital-forensics+5
8282 years ago
TelemetrySourcerer preview

TelemetrySourcerer

GitHubjthuraisamy/telemetrysourcerer

Enumerate and disable common sources of telemetry used by AV/EDR.

defensive-toolsred-teaming
8655 years ago
memhunter preview

memhunter

GitHubmarcosd4h/memhunter

Live hunting of code injection techniques

defensive-toolsincident-responsemalware-analysis+1
3847 years ago
GoPurple preview

GoPurple

GitHubsh4hin/gopurple

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

defensive-toolseducationexploitation+6
4975 years ago
DetectionLabELK preview

DetectionLabELK

GitHubcyberdefenders/detectionlabelk

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

configuration-auditingdefensive-toolsdigital-forensics+7
5765 years ago
Ares preview

Ares

GitHubcerbersec/ares

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

binary-analysisdefensive-toolsencryption-decryption-tools+7
3374 years ago
Hunt-Sleeping-Beacons preview

Hunt-Sleeping-Beacons

GitHubtheflink/hunt-sleeping-beacons

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

binary-analysisdefensive-toolsforensics+3
6817 months ago
FalconEye preview

FalconEye

GitHubrajiv2790/falconeye

Kernel-mode Windows driver for real-time detection of process injection techniques, including shellcode, DLL, and reflective injection, with syscall…

binary-analysisdefensive-toolsintrusion-detection+1
3105 years ago
smart-contract-attack-vectors preview

smart-contract-attack-vectors

GitHubharendra-shakya/smart-contract-attack-vectors

A curated list of smart contract attack vectors

ctfcurated-resourcesdefensive-tools+3
5232 years ago
Yara-rules preview

Yara-rules

GitHubbartblaze/yara-rules

Collection of private Yara rules.

defensive-toolsdigital-forensicsincident-response+3
3907 months ago
Previous1…678…23Next