Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
nightingale preview

nightingale

GitHubccfos/nightingale

Open-source alerting engine for time-series monitoring data. Connects to Prometheus, VictoriaMetrics, ElasticSearch, and other data sources. Supports…

devsecopsincident-response
13.3k16h 12m ago
LOLDrivers preview

LOLDrivers

GitHubmagicsword-io/loldrivers

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

curated-resourceseducationforensics+5
1.8k2 days ago
BTPS-SecPack preview

BTPS-SecPack

GitHubosbornepro/btps-secpack

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

configuration-auditingdefensive-toolseducation+3
525 days ago
Honeypot-Project preview

Honeypot-Project

GitHubowasp/honeypot-project

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

defensive-toolseducationincident-response+5
10811 days ago
PhantomFS preview

PhantomFS

GitHuballoysecuregroup/phantomfs

Windows honeypot using ProjFS to project decoy files that trigger Event Log and desktop alerts when accessed, with SMB remote session logging for…

defensive-toolsincident-responseintrusion-detection
7126 days ago
printnightmare-detection-lab preview

printnightmare-detection-lab

GitHubjoertx07/printnightmare-detection-lab

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

adversarial-attackeducationexploitation+6
1 month ago
kratosminifilter preview

kratosminifilter

GitHubmukendi/kratosminifilter

Kratos is a high-performance Windows File System Minifilter driver designed to detect, block, and permanently immunize

anomaly-detectiondefensive-toolsincident-response+2
41 month ago
CVE-2026-8838-Mitigation-and-Detection preview

CVE-2026-8838-Mitigation-and-Detection

GitHubsana-404/cve-2026-8838-mitigation-and-detection

Detection and mitigation scripts for CVE-2026-8838, providing vulnerability scanning, configuration auditing, and incident response guidance to…

configuration-auditingincident-responseintrusion-detection+3
1 month ago
Sigma-Rules preview

Sigma-Rules

GitHubthe-dfir-report/sigma-rules

Rules generated from our investigations.

curated-resourcesdefensive-toolsincident-response+3
2142 months ago
jvmxray preview

jvmxray

GitHubspoofzu/jvmxray

Externalize Java application access to protected resources as log messages.

code-analysisdynamic-analysis-sandboxingincident-response+1
472 months ago
Mobile-Drop-Device-SOC-Detection preview

Mobile-Drop-Device-SOC-Detection

GitHubv3ng4mxv1p3r/mobile-drop-device-soc-detection

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

educationexploitationincident-response+6
14 months ago
azure-vulnerability-remediation-project preview

azure-vulnerability-remediation-project

GitHubdawnsmithcyber/azure-vulnerability-remediation-project

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+6
15 months ago
Zero-Click-RCE-Incident-Response-CVE-2025-21298 preview

Zero-Click-RCE-Incident-Response-CVE-2025-21298

GitHubtarunbharathe/zero-click-rce-incident-response-cve-2025-21298

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

command-and-controldigital-forensicseducation+6
5 months ago
Leaktopus preview
Archived

Leaktopus

GitHubplaytikaoss/leaktopus

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

code-analysisdevsecopsincident-response+6
295 months ago
MOVEit-Transfer-Data-Breach-Analysis. preview

MOVEit-Transfer-Data-Breach-Analysis.

GitHubtubaaiftikhar-ui/moveit-transfer-data-breach-analysis.

​Detailed analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362) for CS50 Cybersecurity. This project explores the technical impact of…

database-securityeducationincident-response+3
5 months ago
watcher preview

watcher

GitHubthemoonsir/watcher

Detection reverse shell and kill it before trying shell.

binary-analysisdefensive-toolsincident-response+5
26 months ago
androidqf preview

androidqf

GitHubbotherder/androidqf

Portable forensic acquisition tool for Android devices that collects relevant data via USB debugging to identify potential spyware or compromise…

android-securitydigital-forensicsforensics+2
3087 months ago
xz-cve-2024-3094 preview

xz-cve-2024-3094

GitHubhackura/xz-cve-2024-3094

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

digital-forensicseducationforensics+6
7 months ago
Previous12Next