Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
124 results
jsp-webshell-scanner preview

jsp-webshell-scanner

GitHubrespondiq/jsp-webshell-scanner

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

code-analysisdigital-forensicsforensics+6
1
2 months ago
netlas-cookbook preview

netlas-cookbook

GitHubnetlas-io/netlas-cookbook

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

curated-resourcesdigital-forensicseducation+9
8891 year ago
HAFNIUM-IOC preview
Archived

HAFNIUM-IOC

GitHubsoteria-security/hafnium-ioc

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

digital-forensicsforensicsincident-response+3
225 years ago
sysmon-config preview

sysmon-config

GitHubion-storm/sysmon-config

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

anomaly-detectiondefensive-toolsdigital-forensics+5
8282 years ago
reproducing-CVE-2025-1489 preview

reproducing-CVE-2025-1489

GitHubkhaifunglee/reproducing-cve-2025-1489

This repository is to demonstrate and practice my forensic/vulnerability analysis skills by reproducing a web-related CVE in a safe environment.

digital-forensicseducationexploitation+3
8 months ago
keycloak-cve-2026-18963-hunt preview

keycloak-cve-2026-18963-hunt

GitHubkyos-public/keycloak-cve-2026-18963-hunt

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

authenticationdatabase-securitydigital-forensics+3
149 days ago
CVE-2025-31702 preview

CVE-2025-31702

GitHubitres-labs/cve-2025-31702

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

digital-forensicsexploitationincident-response+3
108 months ago
PAN-OS-CVE-2024-3400-Command-Injection-Investigation preview

PAN-OS-CVE-2024-3400-Command-Injection-Investigation

GitHubzedocun/pan-os-cve-2024-3400-command-injection-investigation

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

digital-forensicsincident-responselog-analysis+3
14 months ago
ToolShellFinder preview

ToolShellFinder

GitHubzach115th/toolshellfinder

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

digital-forensicsforensicsincident-response+5
8 months ago
keepass-password-dumper preview

keepass-password-dumper

GitHubvdohney/keepass-password-dumper

Original PoC for CVE-2023-32784

digital-forensicsexploitationforensics+3
6533 years ago
ioc-scanner-CVE-2019-19781 preview

ioc-scanner-CVE-2019-19781

GitHubcitrix/ioc-scanner-cve-2019-19781

Indicator of Compromise Scanner for CVE-2019-19781

digital-forensicsforensicsincident-response+5
586 years ago
mongobleed-detector preview

mongobleed-detector

GitHubneo23x0/mongobleed-detector

Detection Script for MongoBleed Exploitation

database-securitydigital-forensicsforensics+5
818 months ago
keepass_dump preview

keepass_dump

GitHubz-jxy/keepass_dump

KeePass 2.X dumper (CVE-2023-32784)

digital-forensicsexploitationforensics+3
293 years ago
bw-dump preview

bw-dump

GitHubmarkuta/bw-dump

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

digital-forensicsexploitationforensics+4
422 years ago
xz-backdoor-github preview

xz-backdoor-github

GitHubemirkmo/xz-backdoor-github

History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.

curated-resourcesdigital-forensicseducation+3
112 years ago
ncentral-compromise-ioc-triage preview

ncentral-compromise-ioc-triage

GitHubcreamyg31337/ncentral-compromise-ioc-triage

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

defensive-toolsdigital-forensicsincident-response+4
28 days ago
SOC-Investigation-CVE-2024-49138 preview

SOC-Investigation-CVE-2024-49138

GitHubbasitsajidapply-stack/soc-investigation-cve-2024-49138

Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)

digital-forensicseducationincident-response+3
11 days ago
CVE-2026-68820-Mitigation-PoC- preview

CVE-2026-68820-Mitigation-PoC-

GitHubfevar54/cve-2026-68820-mitigation-poc-

Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.

curated-resourcesdigital-forensicseducation+5
9 days ago
Previous1234567Next