Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
loki preview

loki

GitHubgrafana/loki

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

general-purpose-utilitiesincident-responselog-analysis+1
28.9k
14h 3m ago
douglas-042-HQ preview

douglas-042-HQ

GitHubdouglas-042/douglas-042-hq

Central console for Douglas-042 HEADQUARTERS collectors. Sweeps a fleet, correlates results across hosts, and manages IOC feeds and SIEM delivery…

defensive-toolsforensicsincident-response+5
1 month ago
GhostTrace preview

GhostTrace

GitHubdevzinh/ghosttrace

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

digital-forensicsforensicsincident-response+3
2 months ago
home_SOC_suite preview

home_SOC_suite

GitHubnate-ryan-7690/home_soc_suite

A personal Windows SOC suite built in PowerShell — monitors network connections, resource usage, scheduled tasks and power events with severity…

anomaly-detectiondefensive-toolsdns-analysis+7
13 months ago
agentwatch preview

agentwatch

GitHubfarjadahmed/agentwatch

Silent session recorder for Claude Code that logs every action, flags dangerous commands (rm -rf, sudo, curl|sh), and provides timeline review, risk…

forensicsincident-responselog-analysis+2
126 months ago
Trawler preview

Trawler

GitHubjoeavanzato/trawler

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

defensive-toolsdigital-forensicsforensics+2
3391 year ago
xz-backdoor-scan preview

xz-backdoor-scan

GitHubjuul/xz-backdoor-scan

Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)

binary-analysisforensicsgeneral-purpose-utilities+3
2 years ago
Telstra-Cybersecurity-Virtual-Experience- preview

Telstra-Cybersecurity-Virtual-Experience-

GitHubbl34chig0/telstra-cybersecurity-virtual-experience-

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

educationincident-responselabs-practice+2
22 years ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubtiktb8/cve-2022-29072

Powershell to mitigate CVE-2022-29072

defensive-toolsexploitationincident-response+2
64 years ago
log4jjndilookupremove preview

log4jjndilookupremove

GitHublukepasek/log4jjndilookupremove

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

incident-responsemisconfigurationscripting-automation+2
4 years ago
CVE-2021-3156-Mitigation-ShellScript-Build preview

CVE-2021-3156-Mitigation-ShellScript-Build

GitHubajtech-hue/cve-2021-3156-mitigation-shellscript-build

Shell script that monitors for a vulnerable sudo process and triggers authentication lockout to mitigate CVE-2021-3156.

authenticationdefensive-toolsincident-response+2
5 years ago
CVE-2019-17041 preview

CVE-2019-17041

GitHubresery/cve-2019-17041

Proof-of-concept exploit for CVE-2019-17041, a buffer overflow in rsyslog's parser, demonstrating remote code execution.

devsecopsgeneral-purpose-utilitiesincident-response+3
5 years ago
lazarus-sigma-rules preview

lazarus-sigma-rules

GitHubwithsecurelabs/lazarus-sigma-rules

Sigma rules for detecting Lazarus Group TTPs, covering malicious document execution, PowerShell abuse, scheduled tasks, and credential access,…

defensive-toolsincident-responseintrusion-detection+2
205 years ago