Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
MysqlHoneypot preview

MysqlHoneypot

GitHubal1ex/mysqlhoneypot

MysqlHoneypot

defensive-toolsinformation-gatheringintrusion-detection+2
254 years ago
icannTLD preview

icannTLD

GitHubcorelight/icanntld

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

dns-analysisinformation-gatheringintrusion-detection+3
81 year ago
top-dns preview

top-dns

GitHubcorelight/top-dns

Top DNS Measurement for Bro

dns-analysisinformation-gatheringintrusion-detection+2
105 years ago
zeek-openvpn preview

zeek-openvpn

GitHubcorelight/zeek-openvpn

A Zeek OpenVPN protocol analyzer plugin.

defensive-toolsinformation-gatheringintrusion-detection+3
73 years ago
wp-mhn preview

wp-mhn

GitHubd0n601/wp-mhn

Integrates your Modern Honeypot Network Server and Wordpress Blog via MHN's REST API and WP's shortcodes

defensive-toolsinformation-gatheringintrusion-detection+4
9 years ago
sigcorr preview

sigcorr

GitHubsage-s11/sigcorr

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

anomaly-detectiondefensive-toolsdns-analysis+8
4 months ago
buttinsky preview

buttinsky

GitHubmushorg/buttinsky

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

information-gatheringintrusion-detectionmalware-analysis+2
8213 years ago
wordpot preview

wordpot

GitHubgbrindisi/wordpot

A Wordpress Honeypot

defensive-toolsinformation-gatheringintrusion-detection+2
1893 years ago
hpfeeds preview

hpfeeds

GitHubhpfeeds/hpfeeds

Honeynet Project generic authenticated datafeed protocol

information-gatheringintrusion-detectionnetwork-security+3
2182 years ago
react2shell-honeypot preview

react2shell-honeypot

GitHubstrainxx/react2shell-honeypot

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

information-gatheringintrusion-detectionthreat-intelligence+2
48 months ago
Log4jTools preview

Log4jTools

GitHubmalwaretech/log4jtools

Tools for investigating Log4j CVE-2021-44228

exploitationinformation-gatheringintrusion-detection+2
944 years ago
ThreatIngestor preview

ThreatIngestor

GitHubpedramamini/threatingestor

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

information-gatheringintrusion-detectionioc-management+3
9242 months ago
AIP preview

AIP

GitHubstratosphereips/aip

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

information-gatheringintrusion-detectioniot-security+3
321 year ago
libpcap preview

libpcap

GitHubthe-tcpdump-group/libpcap

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

dns-analysisinformation-gatheringintrusion-detection+3
3.2k2 days ago
log4shell-data preview

log4shell-data

GitHubhoneynet/log4shell-data

Data we are receiving from our honeypots about CVE-2021-44228

incident-responseinformation-gatheringintrusion-detection+3
4 years ago
BaconSampler preview

BaconSampler

GitHublogisek/baconsampler

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

dns-analysisforensicsinformation-gathering+6
207 months ago
ALYCON-Threat-Landscape preview

ALYCON-Threat-Landscape

GitHubmcastens/alycon-threat-landscape
anomaly-detectiondefensive-toolsinformation-gathering+3
5 months ago
thrunt-god preview

thrunt-god

GitHubbackbay-labs/thrunt-god

Threat hunting command system for agentic IDEs

incident-responseinformation-gatheringintrusion-detection+5
361 month ago
Previous12Next