Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
90 results
mimikatz-detector-busylight preview

mimikatz-detector-busylight

GitHubnccgroup/mimikatz-detector-busylight

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

defensive-toolsincident-responseintrusion-detection+3
21
3 years ago
Corelight-Ansible-Roles preview

Corelight-Ansible-Roles

GitHubcorelight/corelight-ansible-roles

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…

configuration-auditingdevsecopsintrusion-detection+3
165 years ago
zeek-quic preview

zeek-quic

GitHubcorelight/zeek-quic

Bro analyzer that detects Google's QUIC protocol

intrusion-detectionlog-analysisnetwork-forensics+2
115 years ago
callstranger-detector preview

callstranger-detector

GitHubcorelight/callstranger-detector

Zeek Plugin that detects CallStranger (CVE-2020-12695) attempts (http://callstranger.com/)

data-exfiltrationdns-analysisintrusion-detection+3
63 years ago
beacon-hunter preview

beacon-hunter

GitHubmrcord77/beacon-hunter

Detects phi-structured C2 beacons that evade RITA and standard regularity-based detectors

anomaly-detectioncommand-and-controleducation+5
92 months ago
fail2ban-log4j preview

fail2ban-log4j

GitHubatnetws/fail2ban-log4j

fail2ban filter that catches attacks againts log4j CVE-2021-44228

ids-ips-evasionintrusion-detectionlog-analysis+3
84 years ago
cve-2020-0601-plugin preview

cve-2020-0601-plugin

GitHub0xxon/cve-2020-0601-plugin

Zeek package that uses OpenSSL to detect CVE-2020-0601 exploit attempts

cryptographyexploitationintrusion-detection+3
56 years ago
Mahoraga-Webapp-Defender preview

Mahoraga-Webapp-Defender

GitHubageofalgorithms/mahoraga-webapp-defender

AI-powered reactive website defense system that detects attacks, analyzes them, and autonomously patches source code in real-time using LLM agents.

ai-securityapi-securityctf+6
43 months ago
Dirty-Frag-CVE-2026-43284 preview

Dirty-Frag-CVE-2026-43284

GitHubkuniyal08/dirty-frag-cve-2026-43284

A report on Dirty Frag, which is a Linux Local Privilege Escalation (LPE) vulnerability chain that allows an unprivileged user to gain root access

educationexploitationforensics+5
11 day ago
ddos-traffic-monitor preview

ddos-traffic-monitor

GitHubjenderal92/ddos-traffic-monitor

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

anomaly-detectiondefensive-toolsintrusion-detection+2
12 months ago
wp2shell-compromise-scanner-plugin preview

wp2shell-compromise-scanner-plugin

GitHubeyesecurity/wp2shell-compromise-scanner-plugin

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

database-securitydigital-forensicsforensics+5
1 month ago
SentinelThread-Forensics preview

SentinelThread-Forensics

GitHubadham504/sentinelthread-forensics

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

digital-forensicsforensicsincident-response+5
24 months ago
CVE-2018-11776 preview

CVE-2018-11776

GitHubcucadili/cve-2018-11776

Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.

exploitationids-ips-evasionintrusion-detection+2
6 years ago
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

defensive-toolsdns-analysisinformation-gathering+5
8.6k10h 32m ago
ja4 preview

ja4

GitHubfoxio-llc/ja4

JA4+ is a suite of network fingerprinting standards

dns-analysisencryption-decryption-toolsfingerprint-spoofing+9
2.1k6 days ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k3 days ago
auditd preview

auditd

GitHubneo23x0/auditd

Best Practice Auditd Configuration

configuration-auditingdefensive-toolsforensics+3
1.9k3 months ago
purple-team-exercise-framework preview

purple-team-exercise-framework

GitHubscythe-io/purple-team-exercise-framework

Purple Team Exercise Framework

adversarial-attackai-securitycloud-security+5
8154 months ago
Previous12345Next