Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
189 results
salt-scanner preview
Archived

salt-scanner

GitHub0x4d31/salt-scanner

Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration

cloud-securityconfiguration-auditingdevsecops+3
262
8 years ago
defenseclaw preview

defenseclaw

GitHubcisco-ai-defense/defenseclaw

Security Governance for Agentic AI

ai-securitycloud-securitycode-analysis+7
8262 days ago
log4shell-rex preview

log4shell-rex

GitHubback2root/log4shell-rex

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs

incident-responseintrusion-detectionioc-management+3
2914 years ago
awesome-wazuh preview

awesome-wazuh

GitHubttlab-research/awesome-wazuh

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

cloud-securityconfiguration-auditingcurated-resources+8
1401 month ago
brawl-public-game-001 preview

brawl-public-game-001

GitHubmitre/brawl-public-game-001

Data from a BRAWL Automated Adversary Emulation Exercise

adversarial-attackcloud-securitydigital-forensics+7
2148 years ago
ARTLAS preview

ARTLAS

GitHubmthbernardes/artlas

Apache Real Time Logs Analyzer System

incident-responseintrusion-detectionlog-analysis+3
1255 years ago
Agentic-SOC-Simulation preview

Agentic-SOC-Simulation

GitHubsafelineman/agentic-soc-simulation

AI 驱动的 SOC 仿真平台

ai-securityeducationforensics+8
1667 months ago
LogHound preview

LogHound

GitHubrnb-team/loghound

Post-Exploitation EVTX Analyzer for BloodHound Mapping

authenticationdigital-forensicsforensics+6
113 months ago
log4j preview

log4j

GitHubwortell/log4j

Repo containing all info, scripts, etc. related to CVE-2021-44228

curated-resourceseducationexploitation+6
104 years ago
CVE-2007-2447-Exploitation-SIEM-Detection-Lab preview

CVE-2007-2447-Exploitation-SIEM-Detection-Lab

GitHubharshiys/cve-2007-2447-exploitation-siem-detection-lab

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

educationexploitationexploit-frameworks+7
13 days ago
SenselessViolence preview

SenselessViolence

GitHubevergreencartoons/senselessviolence

CVE-2022-31814 Exploitation Toolkit.

command-and-controlexploitationlog-analysis+7
43 years ago
defender preview

defender

GitLab0warn/defender

This is a bash script focus on hardening linux. This is a custom think of windows defender but unlike of their privacy issue. User can feel freedom…

anomaly-detectionauthenticationconfiguration-auditing+6
5 months ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
4 months ago
soc-investigation-lab preview

soc-investigation-lab

GitHubmithileshan/soc-investigation-lab

End-to-end SOC investigation: CVE-2011-2523 kill chain, multi-source log correlation, incident report — MITRE ATT&CK T1190

educationexploitationforensics+8
4 months ago
reditrap preview

reditrap

GitHubsrozb/reditrap

Minimal Redis honeypot detecting RediShell (CVE-2025-49844) exploits.

intrusion-detectionlog-analysisnetwork-security+2
10 months ago
check-your-pulse preview
Archived

check-your-pulse

GitHubcisagov/check-your-pulse

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

forensicsincident-responseioc-management+3
286 years ago
VcenterKiller preview

VcenterKiller

GitHubschira4396/vcenterkiller

一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传…

command-and-controlexploitationlog-analysis+6
1.5k2 years ago
Kvasir preview

Kvasir

GitHubkvasirsecurity/kvasir

Kvasir: Penetration Test Data Management

data-recoveryinformation-gatheringlog-analysis+3
4289 years ago
Previous1…789…11Next