Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
C2-detection-manjusaka preview

C2-detection-manjusaka

GitHubcorelight/c2-detection-manjusaka

Detection of Manjusaka C2 framework

command-and-controlincident-responseintrusion-detection+3
6
3 years ago
redxor preview

redxor

GitHubcorelight/redxor

Detection of Linux Malware C2 RedXOR - demonstration

defensive-toolseducationintrusion-detection+3
35 years ago
Threat-Hunting preview

Threat-Hunting

GitHuba2awais/threat-hunting

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

educationincident-responseinformation-gathering+4
843h 54m ago
pingback preview

pingback

GitHubcorelight/pingback

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

command-and-controlintrusion-detectionmalware-analysis+2
1111 months ago
cpanel-cve-2026-41940-fix preview

cpanel-cve-2026-41940-fix

GitHubshahidmallaofficial/cpanel-cve-2026-41940-fix

One-shot detection and remediation for cPanel/WHM servers compromised via CVE-2026-41940, including IOC checks, malware cleanup, C2 blocking, and…

cloud-infrastructure-securityconfiguration-auditingdigital-forensics+5
54 months ago
drovorub-hunt preview

drovorub-hunt

GitHubinsane-forensics/drovorub-hunt

A tool to assist with network-based hunting for GRU's Drovorub malware c2

incident-responseintrusion-detectionmalware-analysis+3
256 years ago
uefi_bootkit_softlanding preview

uefi_bootkit_softlanding

GitHubares-sys/uefi_bootkit_softlanding

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

defensive-toolsdigital-forensicsfirmware-analysis+5
1 month ago
Loki preview

Loki

GitHubneo23x0/loki

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

anomaly-detectiondigital-forensicsdisk-forensics+11
3.8k8 months ago
cpanel-cve-41940-detector preview

cpanel-cve-41940-detector

GitHublimo57640-crypto/cpanel-cve-41940-detector

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

digital-forensicsforensicsincident-response+6
2 months ago
zeek-spicy-facefish preview

zeek-spicy-facefish

GitHubcorelight/zeek-spicy-facefish

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.

command-and-controlintrusion-detectionmalware-analysis+1
14 years ago
Yara-detection-rules preview

Yara-detection-rules

GitHubembee-research/yara-detection-rules

Yara Rules for Modern Malware

curated-resourcesdefensive-toolsintrusion-detection+2
802 years ago
zeek-agenttesla-detector preview

zeek-agenttesla-detector

GitHubcorelight/zeek-agenttesla-detector

A Zeek based Agent Tesla malware C2 detector.

intrusion-detectionmalware-analysisnetwork-security+1
29 months ago
rita preview

rita

GitHubactivecm/rita

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

anomaly-detectioncommand-and-controldns-analysis+4
6382 months ago
BruteRatel-DetectionTools preview

BruteRatel-DetectionTools

GitHubimmersive-labs-sec/bruteratel-detectiontools

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

command-and-controldefensive-toolsincident-response+3
674 years ago
Open-Source-Threat-Intel-Feeds preview

Open-Source-Threat-Intel-Feeds

GitHubbert-janp/open-source-threat-intel-feeds

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such…

intrusion-detectionioc-managementnetwork-security+3
9413 days ago
Zeek-Intelligence-Feeds preview

Zeek-Intelligence-Feeds

GitHubcriticalpathsecurity/zeek-intelligence-feeds

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

command-and-controlintrusion-detectionnetwork-security+3
4003 days ago
detection-validation preview

detection-validation

GitHubalwashali/detection-validation

Detection rule validation

adversarial-attackdefensive-toolsintrusion-detection+1
422 years ago
CVE-2026-24207 preview

CVE-2026-24207

GitHuboffseckit/cve-2026-24207

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

authenticationcloud-securitycommand-and-control+8
12 months ago
Previous12Next