Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
27 results
Triage-CVE-2017-0144 preview

Triage-CVE-2017-0144

GitHubprobablysecure/triage-cve-2017-0144

Goal is to triage well known attacks and learn how security teams quickly respond.

educationincident-responselabs-practice+1
2 months ago
netwatch preview

netwatch

GitHubmatthart1983/netwatch

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.

defensive-toolsdigital-forensicsdns-analysis+8
3.1k22h 42m ago
windows-malware-behavioral-analysis preview

windows-malware-behavioral-analysis

GitHub0x0allenace/windows-malware-behavioral-analysis

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

digital-forensicsdynamic-analysis-sandboxingeducation+8
1 month ago
CVE-2025-68616-Detecting-and-Patching-an-SSRF-in-WeasyPrint-with-Wazuh preview

CVE-2025-68616-Detecting-and-Patching-an-SSRF-in-WeasyPrint-with-Wazuh

GitHubrauljvc8/cve-2025-68616-detecting-and-patching-an-ssrf-in-weasyprint-with-wazuh

Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.

educationincident-responseintrusion-detection+3
1 month ago
nah preview

nah

GitHubmanuelschipper/nah

a guard that blocks catastrophic agent actions

ai-securitycode-analysiscommand-and-control+8
4822 days ago
rekall preview
Archived

rekall

GitHubgoogle/rekall

Rekall Memory Forensic Framework

digital-forensicsforensicsincident-response+3
2.0k5 years ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubdevtint/cve-2026-41940

Technical analysis and educational resource for CVE-2026-41940, covering root cause, scanner behavior, prevention, mitigation, IOC hunting, and VaPT…

curated-resourceseducationincident-response+3
4 months ago
cve-mcp-server preview

cve-mcp-server

GitHubmukul975/cve-mcp-server

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

api-securitydevsecopsincident-response+6
1.6k2 months ago
hawk preview

hawk

GitHubt0pcyber/hawk

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

cloud-infrastructure-securitycloud-securitydigital-forensics+3
9551 year ago
printnightmare-detection-mitigation-lab preview

printnightmare-detection-mitigation-lab

GitHubkaritamw/printnightmare-detection-mitigation-lab

Sanitised Windows security lab demonstrating Active Directory administration, host and network detection, and layered mitigation of CVE-2021-34527.

digital-forensicseducationidentity-access-management+5
1 month ago
Cortex preview

Cortex

GitHubthehive-project/cortex

Cortex: a Powerful Observable Analysis and Active Response Engine

digital-forensicsincident-responseinformation-gathering+5
1.6k2 months ago
YourMemory preview

YourMemory

GitHubsachitrafa/yourmemory

Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.

ai-securityauthentication-authorizationforensics+5
2672 months ago
Umbrella_android preview

Umbrella_android

GitHubsecurityfirst/umbrella_android

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

digital-forensicseducationencryption-decryption-tools+6
2922 years ago
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover preview

Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover

GitHubmrk336/cluster-chaos-exploiting-cve-2025-59359-for-kubernetes-takeover

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

cloud-securitycommand-and-controlcontainer-security+8
11 months ago
Adversarial-Detection-Engineering-Framework preview

Adversarial-Detection-Engineering-Framework

GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

curated-resourcesdefensive-toolseducation+7
616 months ago
pike-agent preview

pike-agent

GitHubsynacktiv/pike-agent

Experimental Linux strace LLM agent

ai-securitydebuggersdynamic-analysis-sandboxing+5
204 months ago
Mobile-Drop-Device-SOC-Detection preview

Mobile-Drop-Device-SOC-Detection

GitHubv3ng4mxv1p3r/mobile-drop-device-soc-detection

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

educationexploitationincident-response+6
14 months ago
cloudpanel-2.4.2-CVE-2024-44765-recovery preview

cloudpanel-2.4.2-CVE-2024-44765-recovery

GitHubjosephgodwinkimani/cloudpanel-2.4.2-cve-2024-44765-recovery

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

cloud-securityincident-responsemisconfiguration+3
11 year ago
Previous12Next