Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
detection-tool-cve-2019-13000 preview

detection-tool-cve-2019-13000

GitHubacinq/detection-tool-cve-2019-13000

A tool that detect if your node has been victim of the invalid funding tx attack.

cryptographyforensicsincident-response+1
6 years ago
RCLocals preview

RCLocals

GitHubyjesus/rclocals

Linux startup analyzer

defensive-toolsforensicshash-analysis+4
651 year ago
scan-shai-hulud preview

scan-shai-hulud

GitHubqi-scape/scan-shai-hulud

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

forensicsincident-responseioc-management+6
14 months ago
telfhash preview

telfhash

GitHubtrendmicro/telfhash

Symbol hash for ELF files

binary-analysisforensicshash-analysis+1
1174 years ago
regipy preview

regipy

GitHubmkorman90/regipy

Regipy is an os independent python library for parsing offline registry hives

digital-forensicsforensicsincident-response+1
27711 days ago
mquery preview

mquery

GitHubcert-polska/mquery

YARA malware query accelerator (web frontend)

database-securityforensicsmalware-analysis+1
4437 months ago
TrueTree preview

TrueTree

GitHubthemittenmac/truetree

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

digital-forensicsforensicsincident-response+1
2872 years ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubahmetramazank/cve-2024-4577

Demonstrates exploitation of CVE-2024-4577, a PHP CGI RCE on Windows, including attack steps, reverse shell deployment, and ransomware simulation…

educationexploitationforensics+5
1 year ago
damn-vulnerable-log4j-app preview

damn-vulnerable-log4j-app

GitHubsnapattack/damn-vulnerable-log4j-app

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

digital-forensicseducationexploitation+3
54 years ago
xz-backdoor-research preview

xz-backdoor-research

GitHubnnatsopoulos/xz-backdoor-research

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

educationforensicsincident-response+5
13 months ago
conti-ransomware-writeup preview

conti-ransomware-writeup

GitHubjustjeff211/conti-ransomware-writeup

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

digital-forensicseducationforensics+6
6 months ago
CVE-2025-66478 preview

CVE-2025-66478

GitHubexptechtw/cve-2025-66478

Real-world attack log analysis of CVE-2025-66478 (Next.js Server Actions RCE) with malware samples, attacker IP tracking, and container security…

container-securityeducationexploitation+6
29 months ago
hashdeep preview

hashdeep

GitHubjessek/hashdeep

Cross-platform hashing toolset for computing message digests (MD5, SHA-1, SHA-256, Tiger, Whirlpool) with recursive directory traversal and file…

data-recoverydigital-forensicsforensics+1
7899 years ago
creddump7 preview

creddump7

GitHubciscocxsecurity/creddump7

Offline Windows credential extractor that dumps LM/NT hashes, cached domain passwords, and LSA secrets from registry hives without relying on system…

forensicspassword-cracking
4125 years ago
FileWatchTower preview

FileWatchTower

GitHubiomoath/filewatchtower

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

digital-forensicsforensicshash-analysis+4
292 years ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubredscan/cve-2019-19781

CVE-2019-19781 Attack Triage Script

exploitationforensicsincident-response+2
16 years ago
CVE-2023-32784-password-combinator-fixer preview

CVE-2023-32784-password-combinator-fixer

GitHubg4sp4rcs/cve-2023-32784-password-combinator-fixer

After using the KeePass password dumper maybe some character parsed as ● is incorrect and you want to know the real character

data-recoveryexploitationforensics+2
1 year ago
hashID preview

hashID

GitHubpsypanda/hashid

Software to identify the different types of hashes -

forensicshash-analysisinformation-gathering+3
1.5k11 years ago
Previous1234Next