Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
81 results
racketeer preview

racketeer

GitHubdsnezhkov/racketeer

Agent-based ransomware simulation toolkit for controlled detection testing across Windows endpoints and network assets, with a cross-platform…

command-and-controldefensive-toolsincident-response+1
69
4 years ago
mimicry preview

mimicry

GitHubchaitin/mimicry

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

defensive-toolsincident-responsered-teaming+1
625 months ago
CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE preview

CVE-2025-53770-SharePoint-Zero-Day-Variant-Exploited-for-Full-RCE

GitHubadityabhatt3010/cve-2025-53770-sharepoint-zero-day-variant-exploited-for-full-rce

A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw…

exploitationincident-responsepenetration-testing+3
111 year ago
CVE-2026-48908 preview

CVE-2026-48908

GitHub0xblackash/cve-2026-48908

CVE-2026-48908

exploitationincident-responsepenetration-testing+3
22 months ago
siras preview

siras

GitHubstuxend/siras

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

cloud-securityincident-responsepenetration-testing+1
1 year ago
DumpsterFire preview

DumpsterFire

GitHubtrycatchhcf/dumpsterfire

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events.…

defensive-toolseducationincident-response+3
1.0k6 years ago
BloodSOCer preview

BloodSOCer

GitHubscoubi/bloodsocer

Aggregates MITRE ATT&CK, Sigma, and Atomic Red Team data into BloodHound graphs so SOC analysts can map detection coverage, identify gaps, and…

defensive-toolsincident-responsethreat-feeds-aggregators+1
619 months ago
redteam-plan preview

redteam-plan

GitHubmagoo/redteam-plan

Issues to consider when planning a red team exercise.

curated-resourceseducationincident-response+3
6149 years ago
Remote-Desktop-Caching- preview

Remote-Desktop-Caching-

GitHubviralmaniar/remote-desktop-caching-

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

digital-forensicsforensicsincident-response+4
2188 years ago
InfraGuard preview

InfraGuard

GitHubwhispergate/infraguard

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

anti-botcommand-and-controldns-analysis+8
31420 days ago
Ledger preview

Ledger

GitHubshellkraft/ledger

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

command-and-controlincident-responselog-analysis+5
273 months ago
cybersecurity-interview-questions preview

cybersecurity-interview-questions

GitHubexcalibra/cybersecurity-interview-questions

Curated collection of 200+ cybersecurity interview questions and answers covering Red Team, Blue Team, Web Security, Incident Response, and network…

curated-resourceseducationincident-response+4
121 month ago
RedEye preview
Archived

RedEye

GitHubcisagov/redeye

RedEye is a visual analytic tool supporting Red & Blue Team operations

command-and-controlincident-responselog-analysis+2
2.8k2 years ago
cve-2021-44228 preview

cve-2021-44228

GitHubkimobu/cve-2021-44228

CVE-2021-44228 investigation toolkit with Log4j RCE PoC, JNDIExploit payload runner, Snort detection rules, and PCAP analysis for red and blue team…

exploitationincident-responseintrusion-detection+3
14 years ago
caldera preview

caldera

GitHubapache/caldera

Automated Adversary Emulation Platform

adversarial-attackcommand-and-controlctf+7
7.3k16 days ago
RedELK preview

RedELK

GitHuboutflanknl/redelk

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

defensive-toolsincident-responseinformation-gathering+4
2.7k10 months ago
kubeshark preview

kubeshark

GitHubkubeshark/kubeshark

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

ai-securitycloud-infrastructure-securitycloud-security+9
12.1k2 days ago
Meerkat preview

Meerkat

GitHubtonyphipps/meerkat

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

digital-forensicsforensicsincident-response+2
4831 year ago
Previous12345Next