Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
LOLRMM preview

LOLRMM

GitHubmagicsword-io/lolrmm

Curated catalog of Remote Monitoring and Management tools abused by threat actors, with YAML profiles, Sigma detection rules, and API access for…

curated-resourcesdefensive-toolseducation+6
396
5 days ago
log4shell-exploitation-detection preview

log4shell-exploitation-detection

GitHubkalidoulabghaly/log4shell-exploitation-detection

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…

container-securityeducationexploitation+5
19 days ago
SOC335-CVE-2024-49138-Investigation preview

SOC335-CVE-2024-49138-Investigation

GitHubnadineelliottcyber/soc335-cve-2024-49138-investigation

SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.

curated-resourcesdigital-forensicseducation+3
28 days ago
cve-2023-23397-detection-lab preview

cve-2023-23397-detection-lab

GitHubzhoucc-cpu/cve-2023-23397-detection-lab

Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.

educationincident-responsenetwork-security+2
16 days ago
Sigma-Rules preview

Sigma-Rules

GitHubthe-dfir-report/sigma-rules

Rules generated from our investigations.

curated-resourcesdefensive-toolsincident-response+3
2142 months ago
YARA_Rules preview

YARA_Rules

GitHubmalgamy/yara_rules

Curated signature-rule collection for detecting and classifying malicious files via pattern matching, with CLI instructions for scanning files and…

curated-resourcesdefensive-toolsincident-response+3
653 years ago
TheDefendersGuide preview

TheDefendersGuide

GitHubdefenders-guide/thedefendersguide

The Github project for The Defender's Guide by Luke Paine and Jonathan Johnson

curated-resourceseducationincident-response
1573 years ago
Hunt-Weird-ImageLoads preview

Hunt-Weird-ImageLoads

GitHubtheflink/hunt-weird-imageloads

Small tool to play with IOCs caused by Imageload events

anomaly-detectiondefensive-toolsincident-response+2
473 years ago
printnightmare-detection-lab preview

printnightmare-detection-lab

GitHubjoertx07/printnightmare-detection-lab

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

adversarial-attackeducationexploitation+6
1 month ago
Dirty-Frag-Research-CVE-2026-43284- preview

Dirty-Frag-Research-CVE-2026-43284-

GitHubnabhan-mohy/dirty-frag-research-cve-2026-43284-

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

container-securityincident-responseintrusion-detection+2
1 month ago
reactor preview

reactor

GitHubnccgroup/reactor

Runs custom filters on Elasticsearch and alerts on matches

anomaly-detectiondefensive-toolsincident-response+2
33 years ago
yaml2yara preview

yaml2yara

GitHubnccgroup/yaml2yara

Generate bulk YARA rules from YAML input

digital-forensicsincident-responseintrusion-detection+4
226 years ago
Honeypot-Project preview

Honeypot-Project

GitHubowasp/honeypot-project

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

defensive-toolseducationincident-response+5
10928 days ago
patriot preview

patriot

GitHubjoe-desimone/patriot

In-memory stealth detection tool that identifies process hollowing, module stomping, unbacked executable regions, and anomalous CONTEXT structures…

anomaly-detectionbinary-analysisdefensive-tools+3
1644 years ago
FileWatchTower preview

FileWatchTower

GitHubiomoath/filewatchtower

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

digital-forensicsforensicshash-analysis+4
292 years ago
firewall preview

firewall

GitHubsalo-404/firewall

🔒 Spring4Shell Firewall Defense — Cybersecurity Incident Simulation This project is part of a Cybersecurity Job Simulation I completed in August…

educationincident-responseintrusion-detection+3
11 year ago
Project-Vuln-Detection-N-Mitigation_101 preview

Project-Vuln-Detection-N-Mitigation_101

GitHubvaishnavucv/project-vuln-detection-n-mitigation_101

Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization…

educationexploitationincident-response+3
11 year ago
Multi-Stage-Exploitation-and-Detection-Engineering-Analysis-of-CVE-2023-34362-in-MOVEit-Transfer preview

Multi-Stage-Exploitation-and-Detection-Engineering-Analysis-of-CVE-2023-34362-in-MOVEit-Transfer

GitHubkarmanyat28/multi-stage-exploitation-and-detection-engineering-analysis-of-cve-2023-34362-in-moveit-transfer

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

educationincident-responselog-analysis+3
4 months ago
Previous1234Next