Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
AA Discord Audit preview

AA Discord Audit

GitLabeveo7/aa-discord-audit

Reconciliation audit for Alliance Auth's Discord integration: finds guild members holding AA-managed roles that Auth never granted and strips or…

configuration-auditingdefensive-toolsidentity-access-management+1
10 days ago
CPLHF preview

CPLHF

GitHubwhereisxuezugi/cplhf

Modular Bash toolkit that hardens Debian/Ubuntu systems for CyberPatriot competitions, automating account, firewall, SSH, PAM, and service hardening…

configuration-auditingctfdefensive-tools+6
521 days ago
dfir-orc preview

dfir-orc

GitHubdfir-orc/dfir-orc

Forensics artefact collection tool for systems running Microsoft Windows

defensive-toolsdigital-forensicsforensics+2
4492 months ago
OffsetInspect preview

OffsetInspect

GitHubwarpedatom/offsetinspect

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA,…

binary-analysisdefensive-toolsexploitation+8
862 months ago
CVE-2026-48908-joomla-sp-page-builder-detection preview

CVE-2026-48908-joomla-sp-page-builder-detection

GitHubg0thamrabb1t/cve-2026-48908-joomla-sp-page-builder-detection

Validates CVE-2026-48908 in Joomla SP Page Builder with unauthorized icon upload leading to PHP code execution. Includes auditd/PCAP evidence, event…

educationexploitationforensics+6
2 months ago
CVE-2025-61155 preview

CVE-2025-61155

GitHubsf0rzin/cve-2025-61155

CVE-2025-61155 — arbitrary process termination in GameDriverX64.sys (Tower of Fantasy anti-cheat). Original IDA Pro teardown, PoC, YARA, IOCs,…

binary-analysiseducationexploitation+7
33 months ago
CTWall preview

CTWall

GitHubcybergabisoft/ctwall

CTWall (ChainThreatWall) platform helps Security, DevOps, and Product teams make risk decisions faster by using SBOM/BOM data to identify malware in…

cloud-securitycontainer-securitydevsecops+6
13 months ago
ExtendIntel preview

ExtendIntel

GitHubcorelight/extendintel

This package extends the Intel package to log more fields

incident-responseioc-managementlog-analysis+2
33 months ago
elastic-peak-dashboards preview

elastic-peak-dashboards

GitHubjconeby/elastic-peak-dashboards

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…

digital-forensicsdns-analysiseducation+6
33 months ago
HallWatch preview

HallWatch

GitHubzypherion-technologies/hallwatch

Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.

binary-analysisdefensive-toolsincident-response+2
903 months ago
SOC-L1-OSINT-Investigation-MikroTik-CVE-2018-1156 preview

SOC-L1-OSINT-Investigation-MikroTik-CVE-2018-1156

GitHubjonathaninfinity01/soc-l1-osint-investigation-mikrotik-cve-2018-1156

L1 SOC Analysis: OSINT detection and risk validation of publicly exposed MikroTik RouterOS vulnerable to RCE | Tools: Shodan, NIST NVD

educationincident-responseinformation-gathering+6
3 months ago
SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubabc1230940/soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

command-and-controleducationemail-security+9
4 months ago
kirjuri preview
Archived

kirjuri

GitHubanttikurittu/kirjuri

Kirjuri is a web application for managing cases and physical forensic evidence items.

digital-forensicsforensicsincident-response
1094 months ago
LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298 preview

LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

GitHubc-g-creator/letsdefend-soc336-windows-ole-zero-click-rce-exploitation-detected-cve-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

ctfeducationemail-security+6
5 months ago
CVE-2026-25769 preview

CVE-2026-25769

GitHub0xblackash/cve-2026-25769

CVE-2026-25769

educationexploitationincident-response+3
5 months ago
NORM-EDR preview

NORM-EDR

GitHubamberchalia/norm-edr

Experimental kernel-mode EDR research project focused on explainable detection of suspicious in-memory execution patterns, producing human-readable…

binary-analysisdefensive-toolseducation+4
117 months ago
CVE-2022-22965-Spring4Shell-Security-Operations-Analysis preview

CVE-2022-22965-Spring4Shell-Security-Operations-Analysis

GitHubshakur1314/cve-2022-22965-spring4shell-security-operations-analysis

A comprehensive Security Operations Centre (SOC) incident response simulation demonstrating threat detection, triage, analysis, and mitigation of the…

educationincident-responselog-analysis+3
7 months ago
React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web preview

React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web

GitHubadityabhatt3010/react2shell-cve-2025-55182-the-deserialization-bug-that-broke-the-web

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

ctfeducationexploitation+8
89 months ago
Previous12Next