Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
Seatbelt preview

Seatbelt

GitHubghostpack/seatbelt

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

defensive-toolsinformation-gatheringpenetration-testing+6
4.7k
1 year ago
BloodHound preview

BloodHound

GitHubspecterops/bloodhound

Graph-based tool for mapping and analyzing identity and privilege relationships across Active Directory, Azure, and other identity platforms to…

defensive-toolsidentity-access-managementinformation-gathering+4
3.3k1 day ago
RedELK preview

RedELK

GitHuboutflanknl/redelk

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

defensive-toolsincident-responseinformation-gathering+4
2.7k9 months ago
AD-description-password-finder preview

AD-description-password-finder

GitHubassurancemaladiesec/ad-description-password-finder

Retrieve AD accounts description and search for password in it

authenticationdefensive-toolsinformation-gathering+5
814 years ago
DNSWatch preview

DNSWatch

GitHubhalildeniz/dnswatch

DNS traffic sniffer and analyzer for monitoring, filtering, and detecting anomalies in DNS queries. Features include PCAP export, DoH support, and a…

defensive-toolsdns-analysisinformation-gathering+2
2181 year ago
fapro preview

fapro

GitHubfofapro/fapro

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…

defensive-toolsfingerprint-spoofinginformation-gathering+3
1.6k1 year ago
slack-watchman preview

slack-watchman

GitHubpapermtn/slack-watchman

Slack enumeration and exposed secrets detection tool

defensive-toolsinformation-gatheringosint+3
4031 month ago
SharpEDRChecker preview

SharpEDRChecker

GitHubpwndexter/sharpedrchecker

C# tool that enumerates running processes, loaded DLLs, installed services, and drivers to detect the presence of AV, EDR, and logging products,…

defensive-toolsinformation-gatheringpenetration-testing+2
7556 months ago
bothan preview

bothan

GitHubaudibleblink/bothan

CLI tool to confirm if an IP:port hosts an Empire C2 server, with support for masscan output parsing and batch scanning from file or stdin.

command-and-controldefensive-toolsinformation-gathering+3
276 years ago
Metamorph preview

Metamorph

GitHubsynacktiv/metamorph

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

defensive-toolsincident-responseinformation-gathering+3
82 months ago
Kestrel preview

Kestrel

GitHubssteelfactor-oss/kestrel

Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast…

defensive-toolsinformation-gatheringpenetration-testing+5
1016 days ago
BadExclusionsNWBO preview

BadExclusionsNWBO

GitHubiamagarre/badexclusionsnwbo

Tool to identify custom or undocumented folder exclusions in AV/EDR by detecting userland hook count differences, enabling red teams to find blind…

defensive-toolsinformation-gatheringpenetration-testing+2
762 years ago
PatrowlHears preview

PatrowlHears

GitHubpatrowl/patrowlhears

Real-time vulnerability intelligence platform aggregating CVE, exploits, and threat news for SOC and threat hunting teams.

defensive-toolsexploitationinformation-gathering+3
1675 months ago
zeek-openvpn preview

zeek-openvpn

GitHubcorelight/zeek-openvpn

Zeek plugin for detecting and parsing OpenVPN traffic (UDP/TCP with TLS), extracting session and TLS handshake metadata for network security…

defensive-toolsinformation-gatheringintrusion-detection+3
73 years ago
Adrenaline preview

Adrenaline

GitHubatomiczsec/adrenaline

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

command-and-controldefensive-toolsinformation-gathering+7
3159 days ago
wordpot preview

wordpot

GitHubgbrindisi/wordpot

WordPress honeypot that detects probes for plugins, themes, and common fingerprinting files. Configurable via CLI or config file, with theme and…

defensive-toolsinformation-gatheringintrusion-detection+2
1897 years ago
Invoke-EDRChecker preview

Invoke-EDRChecker

GitHubpwndexter/invoke-edrchecker

PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

defensive-toolsinformation-gatheringpenetration-testing+2
2802 years ago
SSH-Honeypot preview

SSH-Honeypot

GitHubd4vinci/ssh-honeypot

Lightweight Python-based SSH honeypot that simulates a vulnerable SSH server to log attacker commands, credentials, and connection attempts for…

defensive-toolsinformation-gatheringnetwork-security+1
2910 years ago
Previous123Next