Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
309 results
mini-shai-hulud-scanner preview

mini-shai-hulud-scanner

GitHubintrudify/mini-shai-hulud-scanner

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

forensicsincident-responseioc-management+6
2
3 months ago
nextjs-security-scanner preview

nextjs-security-scanner

GitHubaliksir/nextjs-security-scanner

Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.

code-analysisincident-responsesecret-detection+3
12 months ago
whodunit preview

whodunit

GitLabbontchev/whodunit

Recognizing the most likely APT groups responsible for an incident

digital-forensicsincident-responsethreat-intelligence
33 years ago
scan-shai-hulud preview

scan-shai-hulud

GitHubqi-scape/scan-shai-hulud

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

forensicsincident-responseioc-management+6
13 months ago
Zeek-CVE-Enrichment preview

Zeek-CVE-Enrichment

GitHubcorelight/zeek-cve-enrichment
incident-responseioc-managementlog-analysis+3
11 year ago
pulse-meter preview

pulse-meter

GitHubrxwx/pulse-meter

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and…

exploitationforensicsincident-response+3
11 year ago
SOARCA preview

SOARCA

GitLabcossas/soarca

SOARCA - The Open Source CACAO-based Security Orchestrator!

incident-responsethreat-intelligence
1 month ago
ToolShell-Honeypot preview

ToolShell-Honeypot

GitHubbitsalv/toolshell-honeypot

Honeypot for CVE-2025-53770 aka ToolShell

incident-responseintrusion-detectionioc-management+5
1 year ago
CYBERDUDEBIVASH-Cisco-AsyncOS-CVE-2025-20393-Scanner preview

CYBERDUDEBIVASH-Cisco-AsyncOS-CVE-2025-20393-Scanner

GitHubcyberdudebivash/cyberdudebivash-cisco-asyncos-cve-2025-20393-scanner

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

email-securityexploitationincident-response+4
7 months ago
Clickstudio-compromised-certificate preview

Clickstudio-compromised-certificate

GitHubb401/clickstudio-compromised-certificate

Repository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.

digital-forensicsforensicsincident-response+3
14 years ago
CVE-2022-26134-Exploit-Detection preview

CVE-2022-26134-Exploit-Detection

GitHubma1am/cve-2022-26134-exploit-detection

This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux…

forensicsincident-responseioc-management+3
14 years ago
keepass_CVE-2023-24055_yara_rule preview

keepass_CVE-2023-24055_yara_rule

GitHubcyb3rtus/keepass_cve-2023-24055_yara_rule

Contains a simple yara rule to hunt for possible compromised KeePass config files

forensicsincident-responseioc-management+3
13 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubnerium-security/cve-2025-55182

Host-based detection rules for the RCE vulnerability in the React JavaScript framework.

incident-responseintrusion-detectionthreat-intelligence+3
8 months ago
CVE-2023-34362-Defense-Package preview

CVE-2023-34362-Defense-Package

GitHubnaveenbana5250/cve-2023-34362-defense-package

Threat-Informed Detection & Mitigation Package for MOVEit Transfer Vulnerability

defensive-toolsincident-responsemisconfiguration+3
1 year ago
CVE-2022-22972- preview

CVE-2022-22972-

GitHubbengisugun/cve-2022-22972-

IOC List

forensicsincident-responseioc-management+3
4 years ago
CVE-2021-1675_CarbonBlack_HuntingQuery preview

CVE-2021-1675_CarbonBlack_HuntingQuery

GitHubmrezqi/cve-2021-1675_carbonblack_huntingquery
defensive-toolsincident-responseioc-management+3
5 years ago
CVE-2019-19781_IOCs preview

CVE-2019-19781_IOCs

GitHubdigitalshadows/cve-2019-19781_iocs

IOCs for CVE-2019-19781

incident-responseioc-managementnetwork-security+2
6 years ago
CVE-2022-28672 preview

CVE-2022-28672

GitHubfastmo/cve-2022-28672

CVE-2022-28672 Vulnerabilidad Foxit PDF Reader - UaF - RCE - JIT Spraying

command-and-controlexploitationincident-response+6
3 years ago
Previous1…15161718Next