Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
303 results
exchange-0days-202103 preview

exchange-0days-202103

GitHubsgnls/exchange-0days-202103

IoC determination for exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.

digital-forensicsexploitationincident-response+3
5
5 years ago
CVE-2021-36934 preview

CVE-2021-36934

GitHubn3tsurge/cve-2021-36934

Detection and Mitigation script for CVE-2021-36934 (HiveNightmare aka. SeriousSam)

exploitationincident-responseprivilege-escalation+1
55 years ago
NetScope preview

NetScope

GitHubspectralzero/netscope

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

anomaly-detectiondigital-forensicsincident-response+5
313 days ago
C2-detection-manjusaka preview

C2-detection-manjusaka

GitHubcorelight/c2-detection-manjusaka

Detection of Manjusaka C2 framework

command-and-controlincident-responseintrusion-detection+3
62 years ago
Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment preview

Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment

GitHubonapsis/onapsis-mandiant-cve-2025-31324-vuln-compromise-assessment

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

cloud-securityforensicsincident-response+4
91 year ago
KQL-Hunting_and_Detection-Queries preview

KQL-Hunting_and_Detection-Queries

GitHublukehebe/kql-hunting_and_detection-queries

Some of my KQL hunting queries

incident-responseioc-managementlog-analysis+1
26 days ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubsentinelblue/cve-2022-29072

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

exploitationincident-responselog-analysis+3
84 years ago
fetch-broker-conf preview

fetch-broker-conf

GitHubvulncheck-oss/fetch-broker-conf

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

exploitationincident-responseinformation-gathering+3
51 year ago
forensic-msvpn preview

forensic-msvpn

GitHubsynacktiv/forensic-msvpn

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

digital-forensicsforensicsincident-response+1
62 years ago
reactor preview

reactor

GitHubnccgroup/reactor

Runs custom filters on Elasticsearch and alerts on matches

anomaly-detectiondefensive-toolsincident-response+2
33 years ago
citrix-logchecker preview

citrix-logchecker

GitHubcertat/citrix-logchecker

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

incident-responselog-analysisnetwork-security+3
52 years ago
tanstack-compromise-checker preview

tanstack-compromise-checker

GitHubry-allan/tanstack-compromise-checker

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

command-and-controlforensicsincident-response+6
2 months ago
copyfail2_electric_boogaloo_fix preview

copyfail2_electric_boogaloo_fix

GitHubvorkampfer/copyfail2_electric_boogaloo_fix

A temporary mitigation against copy_fail variant (copyfail2_electric_boogaloo) - Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW…

exploitationincident-responseprivilege-escalation+1
3 months ago
SonicWall-SMA1000-Zero-Day-IoC-Check preview

SonicWall-SMA1000-Zero-Day-IoC-Check

GitHubmrrawbit/sonicwall-sma1000-zero-day-ioc-check

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

exploitationforensicsincident-response+5
1 month ago
jsp-webshell-scanner preview

jsp-webshell-scanner

GitHubrespondiq/jsp-webshell-scanner

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

code-analysisdigital-forensicsforensics+6
12 months ago
wp-user-registration-vuln-checker preview

wp-user-registration-vuln-checker

GitHublimo57640-crypto/wp-user-registration-vuln-checker

Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.

forensicsincident-responseinformation-gathering+3
1 month ago
shai-scan preview

shai-scan

GitHubdigi4care/shai-scan

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

code-analysisdevsecopsincident-response+6
3 months ago
mini-shai-hulud-scanner preview

mini-shai-hulud-scanner

GitHubintrudify/mini-shai-hulud-scanner

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

forensicsincident-responseioc-management+6
23 months ago
Previous1…678…17Next