Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
CVE-2021-1675_CarbonBlack_HuntingQuery preview

CVE-2021-1675_CarbonBlack_HuntingQuery

GitHubmrezqi/cve-2021-1675_carbonblack_huntingquery

CarbonBlack hunting queries to detect PrintNightmare (CVE-2021-1675) exploitation via file, module load, and process events, based on Sigma rules.

defensive-toolsincident-responseioc-management+3
5 years ago
glassworm-hunter preview

glassworm-hunter

GitHubafine-com/glassworm-hunter

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

code-analysisdevsecopseducation+9
304 months ago
MOVEit_CVE-2023-34362_IOCs preview

MOVEit_CVE-2023-34362_IOCs

GitHubdeepinstinct/moveit_cve-2023-34362_iocs

CVE-2023-34362-IOCs. More information on Deep Instinct's blog site.

educationforensicsincident-response+3
23 years ago
PolinRider preview

PolinRider

GitHubopensourcemalware/polinrider

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

code-analysiscurated-resourceseducation+8
972 months ago
shai-scan preview

shai-scan

GitHubdigi4care/shai-scan

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

code-analysisdevsecopsincident-response+6
4 months ago
Log4Shell preview

Log4Shell

GitHub0xsyr0/log4shell

This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.

curated-resourceseducationexploitation+6
61 year ago
krustyloader-analysis preview

krustyloader-analysis

GitHubsynacktiv/krustyloader-analysis

KrustyLoader Analysis

curated-resourcesioc-managementmalware-analysis+2
102 years ago
log4j-CVE-2021-44228-Public-IoCs preview

log4j-CVE-2021-44228-Public-IoCs

GitHubsh0ckfr/log4j-cve-2021-44228-public-iocs

Public IoCs about log4j CVE-2021-44228

curated-resourceseducationioc-management+2
94 years ago
hexalocker-analysis preview

hexalocker-analysis

GitHubsynacktiv/hexalocker-analysis

HexaLocker ransomware analysis

ioc-managementmalware-analysisthreat-intelligence
22 years ago
ToolShell-Honeypot preview

ToolShell-Honeypot

GitHubbitsalv/toolshell-honeypot

Honeypot for CVE-2025-53770 aka ToolShell

incident-responseintrusion-detectionioc-management+5
1 year ago
rustinel preview

rustinel

GitHubkarib0u/rustinel

Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.

incident-responseioc-management
4971 day ago
attack-stix-data preview

attack-stix-data

GitHubmitre-attack/attack-stix-data

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…

curated-resourcesioc-managementmobile-security+4
6771 month ago
public-research preview

public-research

GitHubdeepfield/public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

ioc-managementmalware-analysisnetwork-security+3
702 months ago
OsintCase preview

OsintCase

GitHubemrekybs/osintcase

An OSINT investigation case mapping tool for organizing entities, relationships, evidence, and intelligence.

curated-resourcesdata-recoverydigital-forensics+6
24 days ago
letsdefend-cve-2024-49138-investigation preview

letsdefend-cve-2024-49138-investigation

GitHubcyprianatsyor/letsdefend-cve-2024-49138-investigation

Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.

binary-exploitationdigital-forensicseducation+7
1 year ago
ThePhish preview

ThePhish

GitHubemalderson/thephish

ThePhish: an automated phishing email analysis tool

digital-forensicsemail-securityincident-response+5
1.4k2 years ago
proxynotshell-IOC-Checker preview

proxynotshell-IOC-Checker

GitHubrjsudlow/proxynotshell-ioc-checker

Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

forensicsincident-responseioc-management+3
53 years ago
Loki preview

Loki

GitHubneo23x0/loki

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

anomaly-detectiondigital-forensicsdisk-forensics+11
3.8k8 months ago
Previous1234Next