Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
CVE-2021-1675_CarbonBlack_HuntingQuery preview

CVE-2021-1675_CarbonBlack_HuntingQuery

GitHubmrezqi/cve-2021-1675_carbonblack_huntingquery

CarbonBlack hunting queries to detect PrintNightmare (CVE-2021-1675) exploitation via file, module load, and process events, based on Sigma rules.

defensive-toolsincident-responseioc-management+3
5 years ago
plaso preview

plaso

GitHublog2timeline/plaso

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

data-recoverydigital-forensicsdisk-forensics+5
2.2k9 days ago
Noriben preview

Noriben

GitHubrurik/noriben

Python-based malware analysis sandbox that integrates with Sysinternals Procmon to automatically collect, analyze, and report runtime indicators with…

dynamic-analysis-sandboxingforensicsioc-management+1
1.3k5 days ago
ThePhish preview

ThePhish

GitHubemalderson/thephish

ThePhish: an automated phishing email analysis tool

digital-forensicsemail-securityincident-response+5
1.4k2 years ago
attack-stix-data preview

attack-stix-data

GitHubmitre-attack/attack-stix-data

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

curated-resourcesioc-managementmobile-security+4
6721 month ago
spyre preview

spyre

GitHubspyre-project/spyre

simple YARA-based IOC scanner

forensicsincident-responseioc-management+1
1816 months ago
SPiCa preview

SPiCa

GitHub0xkirisame/spica

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

anomaly-detectionbinary-analysisdefensive-tools+7
1042 months ago
hyperhives-macos-infostealer-analysis preview

hyperhives-macos-infostealer-analysis

GitHubdarksp33d/hyperhives-macos-infostealer-analysis

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

curated-resourceseducationforensics+6
335 months ago
odin preview

odin

GitHubhamza-megahed/odin

Centralized IoC scanner that deploys Loki across endpoints, collects detection results, and parses logs into CSV for incident response and forensic…

defensive-toolsforensicsincident-response+2
204 years ago
log4j-CVE-2021-44228-Public-IoCs preview

log4j-CVE-2021-44228-Public-IoCs

GitHubsh0ckfr/log4j-cve-2021-44228-public-iocs

Public IoCs about log4j CVE-2021-44228

curated-resourceseducationioc-management+2
94 years ago
proxynotshell-IOC-Checker preview

proxynotshell-IOC-Checker

GitHubrjsudlow/proxynotshell-ioc-checker

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

forensicsincident-responseioc-management+3
53 years ago
SonicWall-SMA1000-Zero-Day-IoC-Check preview

SonicWall-SMA1000-Zero-Day-IoC-Check

GitHubmrrawbit/sonicwall-sma1000-zero-day-ioc-check

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

exploitationforensicsincident-response+5
2 months ago
jsp-webshell-scanner preview

jsp-webshell-scanner

GitHubrespondiq/jsp-webshell-scanner

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

code-analysisdigital-forensicsforensics+6
13 months ago
CVE-2025-31324 preview

CVE-2025-31324

GitHubjonathanstross/cve-2025-31324

A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of…

information-gatheringioc-managementpenetration-testing+3
11 year ago
soc-investigation-powershell-edrfreeze preview

soc-investigation-powershell-edrfreeze

GitHubzedocun/soc-investigation-powershell-edrfreeze

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

defensive-toolsdigital-forensicseducation+7
16 months ago
CVE-2021-44228_IoCs preview

CVE-2021-44228_IoCs

GitHubguardicode/cve-2021-44228_iocs

Curated collection of public Indicators of Compromise (IoCs) for the Log4j vulnerability (CVE-2021-44228), aggregated from multiple sources for…

information-gatheringioc-managementthreat-feeds-aggregators+2
4 years ago
ToolShell-Honeypot preview

ToolShell-Honeypot

GitHubbitsalv/toolshell-honeypot

Honeypot for CVE-2025-53770 aka ToolShell

incident-responseintrusion-detectionioc-management+5
1 year ago
exist preview
Archived

exist

GitHubnict-csl/exist

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

educationincident-responseinformation-gathering+6
1526 months ago