Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
teler preview
Archived

teler

GitHubteler-sh/teler

Real-time HTTP Intrusion Detection

defensive-toolsincident-responseintrusion-detection+2
3.1k
2 years ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4071 year ago
crowdsec preview

crowdsec

GitHubcrowdsecurity/crowdsec

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

anti-botdefensive-toolsids-ips-evasion+6
14.8k4 days ago
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

anomaly-detectionanti-botdefensive-tools+11
8.6k14h 25m ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

anti-botapi-securitydefensive-tools+7
9.8k2 months ago
cve-2021-44228 preview

cve-2021-44228

GitHubcorelight/cve-2021-44228

Zeek package for detecting Log4j CVE-2021-44228 exploit attempts via HTTP header payloads, LDAP Java class downloads, and second-stage Java class…

exploitationintrusion-detectionlog-analysis+3
199 months ago
http-stalling-detector preview

http-stalling-detector

GitHubcorelight/http-stalling-detector

Detect HTTP stalling attacks like slowloris with Bro

anomaly-detectiondefensive-toolsintrusion-detection+2
198 years ago
CVE-2021-31166 preview

CVE-2021-31166

GitHubcorelight/cve-2021-31166

Detection rules (Suricata + Zeek) for CVE-2021-31166 HTTP Protocol Stack vulnerability, providing network-level alerts on exploit attempts against…

exploitationintrusion-detectionnetwork-security+3
121 year ago
cve-2022-21907 preview

cve-2022-21907

GitHubcorelight/cve-2022-21907

Zeek package to detect CVE-2022-21907 HTTP exploit attempts by analyzing packet captures for malformed requests and triggering alerts.

exploitationintrusion-detectionnetwork-security+3
51 year ago
elastic-peak-dashboards preview

elastic-peak-dashboards

GitHubjconeby/elastic-peak-dashboards

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…

digital-forensicsdns-analysiseducation+6
32 months ago
CVE-2022-3602 preview

CVE-2022-3602

GitHubcorelight/cve-2022-3602

Zeek package detecting CVE-2022-3602 exploitation attempts and vulnerable OpenSSL servers via HTTP Server header and TLS punycode anomalies,…

exploitationintrusion-detectionnetwork-security+2
43 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubcorelight/cve-2021-41773

Zeek package detecting Apache HTTP Server path traversal/RCE exploits (CVE-2021-41773, CVE-2021-42013) with payload capture and server header…

exploitationincident-responseintrusion-detection+3
14 years ago
fire-wall-server preview

fire-wall-server

GitHubnosie12/fire-wall-server

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

defensive-toolseducationintrusion-detection+3
1 year ago
CVE-2025-29927-Sigma-Rule preview

CVE-2025-29927-Sigma-Rule

GitHubelshaheedy/cve-2025-29927-sigma-rule

Sigma rule for detecting CVE-2025-29927 exploitation via suspicious x-middleware-subrequest HTTP headers in Next.js applications, with detection…

educationintrusion-detectionlog-analysis+3
1 year ago
CVE-2021-41773_Honeypot preview
Archived

CVE-2021-41773_Honeypot

GitHublopqto/cve-2021-41773_honeypot

Lightweight honeypot for Apache HTTP Server path traversal vulnerability CVE-2021-41773, designed to capture and log exploitation attempts.

defensive-toolsintrusion-detectionthreat-intelligence+2
24 years ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k17h 58m ago
py preview

py

GitHubantiwar3/py

飘云ark(pyark)

defensive-toolsdigital-forensicsincident-response+3
53110 days ago
galah preview

galah

GitHub0x4d31/galah

Galah: An LLM-powered web honeypot.

incident-responseintrusion-detectionthreat-intelligence+1
6631 year ago
Previous12Next