Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
dns_watchdog_windows2 preview

dns_watchdog_windows2

GitHubmicrolaser/dns_watchdog_windows2

PowerShell script that monitors Windows DNS traffic via pktmon to detect poisoning, spoofing, rogue resolver responses, and gateway MAC changes,…

anomaly-detectiondefensive-toolsdns-analysis+5
21 days ago
suricata preview

suricata

GitHuboisf/suricata

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

anomaly-detectionanti-botdefensive-tools+9
6.7k4 days ago
icannTLD preview

icannTLD

GitHubcorelight/icanntld

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

dns-analysisinformation-gatheringintrusion-detection+3
81 year ago
top-dns preview

top-dns

GitHubcorelight/top-dns

Top DNS Measurement for Bro

dns-analysisinformation-gatheringintrusion-detection+2
106 years ago
aiengine preview

aiengine

Bitbucketcamp0/aiengine

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

anomaly-detectiondefensive-toolsdns-analysis+5
3 years ago
Conveigh preview

Conveigh

GitHubkevin-robertson/conveigh

Conveigh is a Windows PowerShell LLMNR/NBNS spoofer detection tool

dns-analysisintrusion-detectionnetwork-security+3
10110 years ago
buttinsky preview

buttinsky

GitHubmushorg/buttinsky

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

information-gatheringintrusion-detectionmalware-analysis+2
8213 years ago
ioc2rpz preview

ioc2rpz

GitHubhomas/ioc2rpz

ioc2rpz is a place where threat intelligence meets DNS.

defensive-toolsdns-analysisdns-fuzzing+6
1173 months ago
hpfeeds preview

hpfeeds

GitHubhpfeeds/hpfeeds

Honeynet Project generic authenticated datafeed protocol

information-gatheringintrusion-detectionnetwork-security+3
2192 years ago
react2shell-honeypot preview

react2shell-honeypot

GitHubstrainxx/react2shell-honeypot

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

information-gatheringintrusion-detectionthreat-intelligence+2
410 months ago
Log4jTools preview

Log4jTools

GitHubmalwaretech/log4jtools

Tools for investigating Log4j CVE-2021-44228

exploitationinformation-gatheringintrusion-detection+2
954 years ago
ThreatIngestor preview

ThreatIngestor

GitHubpedramamini/threatingestor

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

information-gatheringintrusion-detectionioc-management+3
9314 months ago
AIP preview

AIP

GitHubstratosphereips/aip

Generates efficient IPv4 blocklists from Zeek network flows using multiple prioritization models (new, consistent, random forest) to identify…

information-gatheringintrusion-detectioniot-security+3
321 year ago
libpcap preview

libpcap

GitHubthe-tcpdump-group/libpcap

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

dns-analysisinformation-gatheringintrusion-detection+3
3.2k20h 21m ago
Malcolm preview

Malcolm

GitHubcisagov/malcolm

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

digital-forensicsdns-analysisforensics+9
2.5k11 days ago
CVE-2017-5638_struts preview

CVE-2017-5638_struts

GitHubinitconf/cve-2017-5638_struts

Bro/Zeek script for detecting Apache Struts CVE-2017-5638 reconnaissance, compromise, and malware download tracking with automated IP extraction.

exploitationintrusion-detectionmalware-analysis+3
89 years ago
sigint-hombre preview

sigint-hombre

GitHubmalvuln/sigint-hombre

Dynamically generated Suricata rules from real-time threat feeds

defensive-toolsdns-analysisintrusion-detection+4
149 months ago
callstranger-detector preview

callstranger-detector

GitHubcorelight/callstranger-detector

Zeek plugin detecting CallStranger (CVE-2020-12695) exploitation via UPnP SUBSCRIBE/NOTIFY analysis, identifying DDoS amplification, data…

data-exfiltrationdns-analysisintrusion-detection+3
63 years ago
Previous12Next