Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
ESXiArgs-Recover preview
Archived

ESXiArgs-Recover

GitHubcisagov/esxiargs-recover

A tool to recover from ESXiArgs ransomware

data-recoverydefensive-toolsincident-response+1
300
3 years ago
CVE-2024-27198-SOC-Lab preview

CVE-2024-27198-SOC-Lab

GitHubptd200110/cve-2024-27198-soc-lab

SOC detection and incident response lab simulating CVE-2024-27198 authentication bypass in JetBrains TeamCity. Includes ELK SIEM, Suricata IDS, Sigma…

educationexploitationids-ips-evasion+7
23 months ago
csaf preview

csaf

GitHubcsalab-id/csaf

Cyber Security Awareness Framework (CSAF)

ctfdefensive-toolseducation+9
1067 months ago
loki preview

loki

GitHubgrafana/loki

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

general-purpose-utilitiesincident-responselog-analysis+1
29.0k9h 45m ago
stackrox preview

stackrox

GitHubstackrox/stackrox

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

anomaly-detectioncloud-infrastructure-securitycloud-security+6
1.3k11h 21m ago
soc-faker preview

soc-faker

GitHubswimlane/soc-faker

A python package for use in generating fake data for SOC and security automation.

defensive-toolseducationincident-response+4
1751 year ago
cve-2025-57819-freepbx-range preview

cve-2025-57819-freepbx-range

GitHubshivammittal2403/cve-2025-57819-freepbx-range

Isolated educational FreePBX-compatible cyber range for CVE-2025-57819 (CWE-89/CWE-288). Docker lab — not official Sangoma FreePBX.

ctfeducationincident-response+4
12 days ago
cve-2026-27483-lab preview

cve-2026-27483-lab

GitHubnabhan-mohy/cve-2026-27483-lab

A containerized enterprise-style lab for researching and defending against CVE-2026-27483.

educationexploitationincident-response+5
1 month ago
xz-vulnerable-honeypot preview

xz-vulnerable-honeypot

GitHublockness-ko/xz-vulnerable-honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

defensive-toolsincident-responsenetwork-security+2
1462 years ago
block-copyfail preview

block-copyfail

GitHubatgreen/block-copyfail

BPF LSM blocker for CVE-2026-31431 (Copy Fail) — blocks authencesn AF_ALG binds at runtime without rebooting

defensive-toolsdynamic-analysis-sandboxingincident-response+1
74 months ago
scan preview

scan

GitHubatomdrift-project/scan

0-day malware detection for binaries, source & scripts (that doesn't suck)

binary-analysiscode-analysisdefensive-tools+9
514 days ago
openedr preview

openedr

GitHubcomodosecurity/openedr

Open EDR public repository

defensive-toolsforensicsincident-response+2
2.7k4 months ago
cyberbro preview

cyberbro

GitHubstanfrbd/cyberbro

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

defensive-toolsdns-analysiseducation+9
6903 days ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

ai-securitycloud-securitycommand-and-control+7
2161 day ago
YourMemory preview

YourMemory

GitHubsachitrafa/yourmemory

Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.

ai-securityauthentication-authorizationforensics+5
2702 months ago
mcpguard-dynamic preview

mcpguard-dynamic

GitHubfacebook/mcpguard-dynamic

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

ai-securitycode-analysiscontainer-security+8
742 months ago
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover preview

Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover

GitHubmrk336/cluster-chaos-exploiting-cve-2025-59359-for-kubernetes-takeover

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

cloud-securitycommand-and-controlcontainer-security+8
1 year ago
log4shell-homework9 preview

log4shell-homework9

GitHubserpilrivas/log4shell-homework9

Log4Shell (CVE-2021-44228) exploit demo for SEAS 8405. Includes a vulnerable Spring Boot app, fake LDAP server, Docker setup, MITRE mapping, incident…

educationexploitationincident-response+3
1 year ago
Previous12345Next