Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
181 results
pockint preview

pockint

GitHubedoardogerosa/pockint

A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️

digital-forensicsdns-analysisincident-response+5
285
3 years ago
Trawler preview

Trawler

GitHubjoeavanzato/trawler

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

defensive-toolsdigital-forensicsforensics+2
3401 year ago
Threat-Hunting preview

Threat-Hunting

GitHuba2awais/threat-hunting

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

educationincident-responseinformation-gathering+4
8213 days ago
Crow-Eye preview

Crow-Eye

GitHubghassan-elsman/crow-eye

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

defensive-toolsdigital-forensicsdisk-forensics+3
11218 days ago
soc-faker preview

soc-faker

GitHubswimlane/soc-faker

A python package for use in generating fake data for SOC and security automation.

defensive-toolseducationincident-response+4
1751 year ago
PolinRider preview

PolinRider

GitHubopensourcemalware/polinrider

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

code-analysiscurated-resourceseducation+8
851 month ago
Douglas-042 preview

Douglas-042

GitHubemrekybs/douglas-042

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

forensicsincident-responseinformation-gathering+1
442 days ago
gentlemen-decryptor preview

gentlemen-decryptor

GitHubbedrock-safeguard/gentlemen-decryptor

First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extraction. 35/35…

cryptographydigital-forensicseducation+7
313 months ago
ServerSecurityAudit preview

ServerSecurityAudit

GitHubcyb3rint3l-labs/serversecurityaudit

PowerShell-based Windows Server Security Audit Engine by Cyb3rint3l Labs. Measures alignment with the NIS2 directive and maps findings to MITRE…

configuration-auditingincident-responsethreat-intelligence
476 months ago
DriverSentinel preview

DriverSentinel

GitHubbi8d0/driversentinel

DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the…

defensive-toolsforensicsincident-response+2
363 months ago
ADFT preview

ADFT

GitHubkjean13/adft

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

configuration-auditingdigital-forensicsforensics+3
515 months ago
pacmap preview

pacmap

GitHubm0vi0/pacmap

Graph-first network traffic visualizer for live capture and PCAP replay with checkpoint diffing, path tracing, and Wireshark-style display filters…

dns-analysisforensicsincident-response+4
134 months ago
BerrySentinel preview

BerrySentinel

GitHubdereeqw/berrysentinel

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

anomaly-detectioncommand-and-controldefensive-tools+8
135 months ago
HTSOC preview

HTSOC

GitHubnktris/htsoc

Reproducible SOC lab for CVE-2024-4577 detection and response

educationincident-responseintrusion-detection+7
27 days ago
BlackLotus preview

BlackLotus

GitHubajf8729/blacklotus

BlackLotus aka CVE-2023-24932 Detection/Remediation Scripts for Intune, ConfigMgr, and generic use

cloud-securityconfiguration-auditingdevsecops+3
81 year ago
Get-log4j-Windows.ps1 preview

Get-log4j-Windows.ps1

GitHubkeysau/get-log4j-windows.ps1

Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228

configuration-auditingincident-responseinformation-gathering+3
74 years ago
aiagent-detection-rules preview

aiagent-detection-rules

GitHubkjean13/aiagent-detection-rules

Detection rules for the Claude Code source leak : 16 Sigma rules, Splunk, Elastic, YARA. Lab-validated on GOAD Light DC02.

curated-resourceseducationforensics+6
32 months ago
From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps preview

From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps

GitHubmrk336/from-foothold-to-domain-admin-weaponizing-cve-2025-54918-in-real-world-devops

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

cloud-securityconfiguration-auditingdevsecops+7
411 months ago
Previous1…567…11Next