Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
307 results
runeward preview

runeward

GitHubrunewardd/runeward

Governed execution cells for AI agents.

ai-securityauthentication-authorizationcloud-security+7
1
4 days ago
Kage-DFIR-toolkit preview

Kage-DFIR-toolkit

GitHubkarim852/kage-dfir-toolkit

Windows host DFIR triage console that chains artefact collection, Sigma-correlated timelines, YARA scans, socket and account inspection, indicator…

defensive-toolsdigital-forensicsforensics+8
84 days ago
CVE-2026-86218-N-central-IOC-Toolkit preview

CVE-2026-86218-N-central-IOC-Toolkit

GitHubjithinkrishnanrs/cve-2026-86218-n-central-ioc-toolkit

Defensive IOC and detection toolkit for CVE-2026-86218, a critical pre-auth RCE in N-able N-central. Includes IOCs, log scanner, Sigma, Splunk,…

defensive-toolseducationincident-response+5
3 days ago
gitlab-cve-2026-85706-ioc preview

gitlab-cve-2026-85706-ioc

GitHubjithinkrishnanrs/gitlab-cve-2026-85706-ioc

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE…

defensive-toolsincident-responseinformation-gathering+8
13 days ago
SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515 preview

SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515

GitHubborsch-appreciator/soc235---atlassian-confluence-broken-access-control-0-day-cve-2023-22515

SOC analyst walkthrough triaging a Confluence CVE-2023-22515 broken access control exploitation attempt, covering log analysis, MITRE ATT&CK mapping,…

defensive-toolseducationincident-response+5
1 month ago
TATS preview

TATS

GitHubicemoonhsv/tats

Analyze and track OAuth 2.0, OIDC, and Microsoft Entra ID tokens from Burp, mitmproxy, or Chrome DevTools captures. Visualize token lifecycles,…

authenticationidentity-access-managementlog-analysis+2
720 days ago
log4shell-exploitation-detection preview

log4shell-exploitation-detection

GitHubkalidoulabghaly/log4shell-exploitation-detection

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…

container-securityeducationexploitation+5
7 days ago
ESFang preview

ESFang

GitHubwithsecurelabs/esfang

ESF modular ingestion tool for development and research.

digital-forensicsforensicsincident-response+1
384 years ago
FLAIR preview

FLAIR

GitHubwithsecurelabs/flair

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

digital-forensicsforensicsincident-response+2
165 years ago
lazarus-sigma-rules preview

lazarus-sigma-rules

GitHubwithsecurelabs/lazarus-sigma-rules

Sigma rules for detecting Lazarus Group TTPs, covering malicious document execution, PowerShell abuse, scheduled tasks, and credential access,…

defensive-toolsincident-responseintrusion-detection+2
205 years ago
SOC335-CVE-2024-49138-Investigation preview

SOC335-CVE-2024-49138-Investigation

GitHubnadineelliottcyber/soc335-cve-2024-49138-investigation

SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.

curated-resourcesdigital-forensicseducation+3
16 days ago
papercut-toolkit preview

papercut-toolkit

GitHubvirologi-info/papercut-toolkit

#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained

configuration-auditingdefensive-toolseducation+3
216 days ago
PaperCut-CVE-2026-81578-82078 preview

PaperCut-CVE-2026-81578-82078

GitHubyora1928/papercut-cve-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

educationexploitationlabs-practice+4
417 days ago
Zimbra-CVE-2026-73570-Rules preview

Zimbra-CVE-2026-73570-Rules

GitHubinfokom-ki/zimbra-cve-2026-73570-rules

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

intrusion-detectionlog-analysisthreat-intelligence+2
18 days ago
aegis-latent-core preview

aegis-latent-core

GitHubjuanlunaia/aegis-latent-core

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

ai-securityapi-securitycloud-security+3
176 days ago
RDP-Guard preview

RDP-Guard

GitLabsiberanka/rdp-guard

Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and…

configuration-auditingdefensive-toolsincident-response+2
20 days ago
cve-2026-31431 preview

cve-2026-31431

GitHubashok523/cve-2026-31431

Defensive IR playbook and detection package for CVE-2026-31431 (Copy Fail) Linux kernel LPE, including Sigma, auditd, Falco, Wazuh, YARA, eBPF, and…

container-securityincident-responseintrusion-detection+3
4 months ago
CVE-2026-41940-Detection preview

CVE-2026-41940-Detection

GitHubunfold-security/cve-2026-41940-detection

Detection signatures for CVE-2026-41940 and shemas for cPanel logs

cloud-securityintrusion-detectionlog-analysis+2
14 months ago
Previous12…18Next