Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
macos-collector preview

macos-collector

GitHublethal-forensics/macos-collector

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

digital-forensicsforensicsincident-response+2
52
3 days ago
keycloak-cve-2026-18963-hunt preview

keycloak-cve-2026-18963-hunt

GitHubkyos-public/keycloak-cve-2026-18963-hunt

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

authenticationdatabase-securitydigital-forensics+3
1410 days ago
ecs-logstash-mappings preview

ecs-logstash-mappings

GitHubcorelight/ecs-logstash-mappings

Mapping Corelight or Zeek data to Elastic Common Schema logs

incident-responseintrusion-detectionlog-analysis+2
111 month ago
ecs-mapping preview

ecs-mapping

GitHubcorelight/ecs-mapping

Mapping Corelight or Zeek data to Elastic Common Schema fields

log-analysisnetwork-securitythreat-intelligence
331 month ago
Incident-Response-Powershell preview

Incident-Response-Powershell

GitHubbert-janp/incident-response-powershell

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

digital-forensicsdisk-forensicsforensics+6
8093 months ago
Ledger preview

Ledger

GitHubshellkraft/ledger

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

command-and-controlincident-responselog-analysis+5
273 months ago
CVE-2026-31431-Check preview

CVE-2026-31431-Check

GitHubtangjie1/cve-2026-31431-check

CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script

container-securityexploitationforensics+6
4 months ago
CVE-2026-41940---cPanel-WHM-check preview

CVE-2026-41940---cPanel-WHM-check

GitHub3tternp/cve-2026-41940---cpanel-whm-check

This is the office check script provided by cPanel for all the users who are using cPanel

defensive-toolsdigital-forensicsincident-response+3
4 months ago
cpanel-cve-2026-41940-ioc preview

cpanel-cve-2026-41940-ioc

GitHubandrei-dr/cpanel-cve-2026-41940-ioc

CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation

authenticationdefensive-toolsincident-response+3
44 months ago
TuxResponse preview

TuxResponse

GitHubla3ar0v/tuxresponse

Automated Linux incident response script with live triage, memory acquisition (LiME), disk imaging, YARA scanning, and HTML report generation.

digital-forensicsdisk-forensicsforensics+5
914 months ago
vcsa-hardening-tool preview

vcsa-hardening-tool

GitHubmandiant/vcsa-hardening-tool

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

authenticationcloud-infrastructure-securityconfiguration-auditing+9
135 months ago
defender preview

defender

GitLab0warn/defender

This is a bash script focus on hardening linux. This is a custom think of windows defender but unlike of their privacy issue. User can feel freedom…

anomaly-detectionauthenticationconfiguration-auditing+6
5 months ago
cve-2026-22557-unifi-detection preview

cve-2026-22557-unifi-detection

GitHubgarethmsheldon/cve-2026-22557-unifi-detection

Detection content for CVE-2026-22557 — UniFi Network Application unauthenticated path traversal (CVSS 10.0). Includes YARA, Sigma, KQL, Splunk SPL,…

intrusion-detectionlog-analysisthreat-intelligence+1
5 months ago
decode-spam-headers preview

decode-spam-headers

GitHubmgeeky/decode-spam-headers

A script that helps you understand why your E-Mail ended up in Spam

email-securityinformation-gatheringlog-analysis+2
7006 months ago
mongobleed-detector preview

mongobleed-detector

GitHubneo23x0/mongobleed-detector

Detection Script for MongoBleed Exploitation

database-securitydigital-forensicsforensics+5
818 months ago
MongoBleed-DFIR-Triage-Script-CVE-2025-14847 preview

MongoBleed-DFIR-Triage-Script-CVE-2025-14847

GitHubjemhadar/mongobleed-dfir-triage-script-cve-2025-14847

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…

container-securitydatabase-securitydigital-forensics+5
8 months ago
log-add-http-post-bodies preview

log-add-http-post-bodies

GitHubcorelight/log-add-http-post-bodies

Add POST body excerpt to Bro's HTTP log

digital-forensicslog-analysisnetwork-security+1
148 months ago
ToolShellFinder preview

ToolShellFinder

GitHubzach115th/toolshellfinder

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

digital-forensicsforensicsincident-response+5
9 months ago
Previous123Next