Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
59 results
Malcolm preview

Malcolm

GitHubidaholab/malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

defensive-toolsdigital-forensicsforensics+8
478
12h 47m ago
MESH preview

MESH

GitHubbarghest-ngo/mesh

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

android-securitydigital-forensicsencryption-decryption-tools+8
18814h 20m ago
santa preview

santa

GitHubnorthpolesec/santa

A binary and file access authorization system for macOS.

authentication-authorizationbinary-analysisdefensive-tools+2
7461 day ago
packetfence preview

packetfence

GitHubinverse-inc/packetfence

Open-source network access control (NAC) system with captive portal, 802.1X, BYOD management, wired/wireless enforcement, and IDS/vulnerability…

authentication-authorizationconfiguration-auditingdefensive-tools+6
1.7k1 day ago
AiSOC preview

AiSOC

GitHubbeenuar/aisoc

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

ai-securityanomaly-detectiondefensive-tools+5
2.4k1 day ago
rayhunter preview

rayhunter

GitHubefforg/rayhunter

Rust tool to detect cell site simulators on an orbic mobile hotspot

defensive-toolseducationembedded-systems-security+9
5.7k4 days ago
sigcorr preview

sigcorr

GitHubsage-s11/sigcorr

Passive cross-protocol attack detection tool for mobile core networks. Correlates SS7/MAP, Diameter S6a, and GTPv2-C events to detect location…

anomaly-detectiondefensive-toolsdns-analysis+8
6 days ago
pySigma preview

pySigma

GitHubsigmahq/pysigma

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

defensive-toolsintrusion-detectionlog-analysis+2
5879 days ago
ja4 preview

ja4

GitHubfoxio-llc/ja4

JA4+ is a suite of network fingerprinting standards

dns-analysisencryption-decryption-toolsfingerprint-spoofing+9
2.1k11 days ago
logdata-anomaly-miner preview

logdata-anomaly-miner

GitHubait-aecid/logdata-anomaly-miner

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

anomaly-detectionintrusion-detectionlog-analysis+2
9315 days ago
falco preview

falco

GitHubfalcosecurity/falco

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

anomaly-detectionanti-botchaos-engineering+10
9.3k22 days ago
mcp-attack-detection-sentinel preview

mcp-attack-detection-sentinel

GitHubj-dahl7/mcp-attack-detection-sentinel

Azure Sentinel detection lab for MCP attack patterns, providing 5 analytics rules and 7 KQL hunting queries against SSRF token theft, tool poisoning,…

ai-securitycloud-securityeducation+5
21 month ago
SuricataLog preview

SuricataLog

GitHubjosevnz/suricatalog

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

educationintrusion-detectionlog-analysis+1
271 month ago
mcpguard-dynamic preview

mcpguard-dynamic

GitHubfacebook/mcpguard-dynamic

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

ai-securitycode-analysiscontainer-security+8
721 month ago
CVE-2026-29145-Everything preview

CVE-2026-29145-Everything

GitHubgkdgkd123/cve-2026-29145-everything

Reproducible PoC environment for CVE-2026-29145 Apache Tomcat CLIENT_CERT + OCSP soft-fail bypass, including exploit scripts, mock OCSP responder,…

authentication-authorizationeducationexploitation+6
11 month ago
ddos-traffic-monitor preview

ddos-traffic-monitor

GitHubjenderal92/ddos-traffic-monitor

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

anomaly-detectiondefensive-toolsintrusion-detection+2
12 months ago
ThreatIngestor preview

ThreatIngestor

GitHubpedramamini/threatingestor

Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

information-gatheringintrusion-detectionioc-management+3
9243 months ago
CVE-2026-23813 preview

CVE-2026-23813

GitHuboffseckit/cve-2026-23813

PoC and detection toolkit for CVE-2026-23813, an unauthenticated nginx regex bypass in HPE Aruba AOS-CX exposing the management REST API and hashed…

authentication-authorizationexploitationintrusion-detection+3
3 months ago
Previous1234Next