Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
406 results
cart preview

cart

GitHubcybercentrecanada/cart

Python implementation of the CaRT library for (un)inerting files.

cryptographydefensive-toolsdigital-forensics+2
54
1 year ago
CVE-2022-30190_Temporary_Fix_Source_Code preview
Archived

CVE-2022-30190_Temporary_Fix_Source_Code

GitHubjotaqc/cve-2022-30190_temporary_fix_source_code

These are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)

configuration-auditingdefensive-toolsexploitation+3
4 years ago
OpenTAXII preview

OpenTAXII

GitHubeclecticiq/opentaxii

TAXII server implementation in Python from EclecticIQ

defensive-toolsioc-managementthreat-feeds-aggregators+1
2148 months ago
CVE-2023-38831-Exploit-and-Detection preview

CVE-2023-38831-Exploit-and-Detection

GitHubml-k-eng/cve-2023-38831-exploit-and-detection

This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.

defensive-toolsexploitationincident-response+3
3 years ago
Spring4Shell-Python-Firewall-POC preview

Spring4Shell-Python-Firewall-POC

GitHubnickops87/spring4shell-python-firewall-poc

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

code-analysisdefensive-toolseducation+3
10 months ago
PatrowlHears preview

PatrowlHears

GitHubpatrowl/patrowlhears

PatrowlHears - Vulnerability Intelligence Center / Exploits

defensive-toolsexploitationinformation-gathering+3
1675 months ago
PolyDrop preview

PolyDrop

GitHubmalwaresupportgroup/polydrop

A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit

command-and-controldefensive-toolseducation+5
1252 years ago
qubes-core-admin preview

qubes-core-admin

GitHubqubesos/qubes-core-admin

Manages the core lifecycle of Qubes OS domains via a Python admin API, handling secure compartmentalization with Xen and exposing an event system for…

defensive-toolssecurity-virtualizationutilities-frameworks
1442 days ago
amun preview

amun

GitHubzeroq/amun

Amun Honeypot

defensive-toolsmalware-analysisnetwork-security+1
637 years ago
attack_monitor preview

attack_monitor

GitHubyarox24/attack_monitor

Endpoint detection & Malware analysis software

defensive-toolsdynamic-analysis-sandboxingincident-response+1
2336 years ago
HardeningMeter preview

HardeningMeter

GitHubofriouzan/hardeningmeter

HardeningMeter is an open-source Python tool carefully designed to comprehensively assess the security hardening of binaries and systems.

binary-analysisconfiguration-auditingdefensive-tools+3
661 year ago
Spring4Shell preview

Spring4Shell

GitHubjashan-lefty/spring4shell

In this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem…

defensive-toolseducationincident-response+3
1 year ago
dropengine preview

dropengine

GitHubs0lst1c3/dropengine

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

defensive-toolsexploit-frameworkspayload-development+5
2145 years ago
honeyLambda preview

honeyLambda

GitHub0x4d31/honeylambda

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

cloud-securitydefensive-toolsincident-response+2
5257 years ago
GoodHound preview

GoodHound

GitHubidnahacks/goodhound

Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

defensive-toolspenetration-testingreconnaissance+2
4882 years ago
briefr preview

briefr

GitHubsoldier0x0/briefr

Open Vulnerability Intelligence platform, aggregated intel in one dashboard, with correlation and IOC lookups, completely self hosted. All resources…

defensive-toolsioc-managementthreat-feeds-aggregators+2
31 day ago
ThreatSentry-AI preview

ThreatSentry-AI

GitHubeclipsemanic/threatsentry-ai

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

defensive-toolsincident-responseinformation-gathering+6
17 months ago
sysmon-modular preview

sysmon-modular

GitHubolafhartong/sysmon-modular

A repository of sysmon configuration modules

defensive-toolsdigital-forensicsincident-response+2
3.1k6 days ago
Previous12…23Next