Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
174 results
BadExclusionsNWBO preview

BadExclusionsNWBO

GitHubiamagarre/badexclusionsnwbo

BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR

defensive-toolsinformation-gatheringpenetration-testing+2
75
2 years ago
h0neytr4p preview

h0neytr4p

GitHubpbssubhash/h0neytr4p

Easy to configure Honeypot for Blue Team

defensive-toolsintrusion-detectionnetwork-security+2
441 year ago
Kage-DFIR-toolkit preview

Kage-DFIR-toolkit

GitHubkarim852/kage-dfir-toolkit

Windows host DFIR triage console that chains artefact collection, Sigma-correlated timelines, YARA scans, socket and account inspection, indicator…

defensive-toolsdigital-forensicsforensics+8
2010 days ago
ThreatLens preview

ThreatLens

GitHubabdaullahag/threatlens

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

defensive-toolsincident-responseinformation-gathering+7
2510 days ago
DDWPasteRecon preview

DDWPasteRecon

GitHubviralmaniar/ddwpasterecon

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

data-exfiltrationdefensive-toolsincident-response+4
464 years ago
SSH-Honeypot preview

SSH-Honeypot

GitHubd4vinci/ssh-honeypot

Create Basic SSH Honeypot With Python

defensive-toolsinformation-gatheringnetwork-security+1
2810 years ago
PureRAT-msbuild.exe--C2-Extraction--Net-Evasion-Analysis preview

PureRAT-msbuild.exe--C2-Extraction--Net-Evasion-Analysis

GitHubkaandemir993/purerat-msbuild.exe--c2-extraction--net-evasion-analysis

Reverse engineering analysis of PureRAT RAT abusing msbuild.exe, extracting C2 infrastructure, .NET evasion APIs, file system manipulation, and…

binary-analysiscommand-and-controldefensive-tools+6
167 days ago
scambuster preview

scambuster

GitHublaugiov/scambuster

Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

ai-securitydefensive-toolsemail-security+5
2328 days ago
bothan preview

bothan

GitHubaudibleblink/bothan

Is this IP a C2 server?

command-and-controldefensive-toolsinformation-gathering+3
276 years ago
Portforge preview

Portforge

GitHubbeyarz/portforge

Lightweight utility to fool port scanners

defensive-toolsids-ips-evasionnetwork-security+1
326 years ago
MysqlHoneypot preview

MysqlHoneypot

GitHubal1ex/mysqlhoneypot

MysqlHoneypot

defensive-toolsinformation-gatheringintrusion-detection+2
254 years ago
trappsec preview

trappsec

GitHubtrappsec-dev/trappsec

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

api-securitydefensive-toolsidentity-access-management+5
124 months ago
honeypot-auditor preview

honeypot-auditor

GitHubmziqudhd92/honeypot-auditor

Does This Look Like An Honeypot? (DTLLAH) Multi-protocol CLI that fingerprints whether a target IP behaves like an honeypot — using Honeyscore,…

defensive-toolsinformation-gatheringnetwork-security+3
114 days ago
Spip-Go preview

Spip-Go

GitHubhoneylabshq/spip-go

Spip network sensor written in Go

defensive-toolsincident-responseinformation-gathering+7
76 days ago
CitrixBleed-2-CVE-2025-5777-PoC- preview

CitrixBleed-2-CVE-2025-5777-PoC-

GitHubmingshenhk/citrixbleed-2-cve-2025-5777-poc-

详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件

defensive-toolseducationexploitation+7
171 year ago
Metamorph preview

Metamorph

GitHubsynacktiv/metamorph

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

defensive-toolsincident-responseinformation-gathering+3
83 months ago
socgholish_finder preview

socgholish_finder

GitHublasq88/socgholish_finder

Scans websites for SocGholish JavaScript injections, deobfuscates malicious payloads, and reports shadowing domain URLs used in malvertising…

defensive-toolsinformation-gatheringmalware-analysis+2
143 years ago
nmap-farewell preview

nmap-farewell

GitHubsynacktiv/nmap-farewell

Automated Network Security with Rust: Detecting and Blocking Port Scanners

defensive-toolsintrusion-detectionnetwork-access-control+2
101 year ago
Previous1…678…10Next