Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
fortileak-01-2025-Be preview

fortileak-01-2025-Be

GitHubniklasmato/fortileak-01-2025-be

Repository documenting the Fortigate firewall vulnerability CVE-2022-40684 and publicly disclosed affected data for security research and defensive…

incident-responseinformation-gatheringioc-management+3
1 year ago
BearFTP preview
Archived

BearFTP

GitHubkolya5544/bearftp

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

defensive-toolsincident-responseinformation-gathering+4
143 years ago
Cortex preview

Cortex

GitHubthehive-project/cortex

Automated observable analysis engine for threat intelligence, digital forensics, and incident response, integrating with diverse analyzers via a…

digital-forensicsincident-responseinformation-gathering+5
1.6k1 month ago
bumblebee preview

bumblebee

GitHubperplexityai/bumblebee

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

devsecopsincident-responseinformation-gathering+3
5.0k18 days ago
CVE-2026-0257 preview

CVE-2026-0257

GitHubgrayxploit/cve-2026-0257

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

authenticationincident-responseinformation-gathering+6
12 months ago
ThreatSentry-AI preview

ThreatSentry-AI

GitHubeclipsemanic/threatsentry-ai

ML-powered threat hunting dashboard that automates external asset discovery, enriches data via Shodan and NVD, and prioritizes risks using ensemble…

defensive-toolsincident-responseinformation-gathering+6
16 months ago
HoneyPy preview
Archived

HoneyPy

GitHubfoospidy/honeypy

Low to medium interaction honeypot for emulating UDP/TCP services, logging attacker activity, and posting threat data to HoneyDB and Twitter.…

defensive-toolsincident-responseinformation-gathering+2
4762 years ago
wp-user-registration-vuln-checker preview

wp-user-registration-vuln-checker

GitHublimo57640-crypto/wp-user-registration-vuln-checker

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

forensicsincident-responseinformation-gathering+3
2 months ago
threat_note preview
Archived

threat_note

GitHubdefensepointsecurity/threat_note

Lightweight investigation notebook for tracking threat intelligence, indicators of compromise (IOCs), and managing security incident response…

incident-responseinformation-gatheringioc-management+3
4352 years ago
CVE-2023-38831-KQL preview

CVE-2023-38831-KQL

GitHubpascalasch/cve-2023-38831-kql

KQL hunting query for Microsoft Defender for Endpoint to detect WinRAR file extension spoofing (CVE-2023-38831) using IOCs and file event analysis.

incident-responseinformation-gatheringioc-management+3
42 years ago
Credential-Hunting preview

Credential-Hunting

GitHubnecr00/credential-hunting

Read-only post-exploitation credential hunter that surfaces reusable passwords, keys, hashes, and credential files across Windows and Linux hosts…

forensicsincident-responseinformation-gathering+7
1756 days ago
Douglas-042 preview

Douglas-042

GitHubemrekybs/douglas-042

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

forensicsincident-responseinformation-gathering+1
441 day ago
shomon preview

shomon

GitHubkaansk/shomon

Shodan Monitoring integration for TheHive.

incident-responseinformation-gatheringosint+1
1304 years ago
thrunt-god preview

thrunt-god

GitHubbackbay-labs/thrunt-god

Threat hunting command system for agentic IDEs

incident-responseinformation-gatheringintrusion-detection+5
361 month ago
ZeroLogon-Exploitation-Check preview

ZeroLogon-Exploitation-Check

GitHubyossisassi/zerologon-exploitation-check

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

exploitationincident-responseinformation-gathering+3
75 years ago
fetch-broker-conf preview

fetch-broker-conf

GitHubvulncheck-oss/fetch-broker-conf

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

exploitationincident-responseinformation-gathering+3
52 years ago
thethe preview
Archived

thethe

GitHubelevenpaths/thethe

Centralized threat hunting platform that aggregates investigation data, caches API responses, and enables team collaboration with integrated CLI…

incident-responseinformation-gatheringlog-analysis+4
1155 years ago
log4shell_ioc_ips preview

log4shell_ioc_ips

GitHubhackinghippo/log4shell_ioc_ips

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

incident-responseinformation-gatheringioc-management+3
374 years ago
Previous123Next