Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
320 results
reportly preview

reportly

GitHubsap8899/reportly

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

cloud-securityidentity-access-managementincident-response+2
96
3 years ago
rootly-graphify-importer preview

rootly-graphify-importer

GitHubrootly-ai-labs/rootly-graphify-importer

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

incident-responseinformation-gatheringlog-analysis+1
444 months ago
laravel-threat-detection preview

laravel-threat-detection

GitHubjay123anta/laravel-threat-detection

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

anti-botapi-securitydefensive-tools+6
322 days ago
Mortimer preview

Mortimer

GitHubnccgroup/mortimer

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

forensicsioc-managementlog-analysis+3
1211 years ago
Spip-Go preview

Spip-Go

GitHubhoneylabshq/spip-go

Spip network sensor written in Go

defensive-toolsincident-responseinformation-gathering+7
716 days ago
BerrySentinel preview

BerrySentinel

GitHubdereeqw/berrysentinel

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

anomaly-detectioncommand-and-controldefensive-tools+8
135 months ago
cve-2025-24054-lab preview

cve-2025-24054-lab

GitHubt0tooro/cve-2025-24054-lab

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

authenticationconfiguration-auditingeducation+7
1 month ago
pared preview

pared

GitLabrenich/pared

Lightweight, secure control plane & real-time web dashboard in Crystal for Linux firewalld and NetworkManager host security.

authentication-authorizationdefensive-toolsidentity-access-management+2
13 days ago
kcatcher preview

kcatcher

GitHubthe-infra-company/kcatcher

Catch what's lurking in your Kafka clusters.

authentication-authorizationcloud-securityconfiguration-auditing+6
67 months ago
DiffCatcher preview

DiffCatcher

GitHubteycir/diffcatcher

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

code-analysisdevsecopsinformation-gathering+7
44 months ago
SonicWall-SMA1000-Zero-Day-IoC-Check preview

SonicWall-SMA1000-Zero-Day-IoC-Check

GitHubmrrawbit/sonicwall-sma1000-zero-day-ioc-check

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

exploitationforensicsincident-response+5
1 month ago
Wireshark preview

Wireshark

GitHubkirkdjohnson/wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

command-and-controldigital-forensicseducation+9
32 years ago
ThreatSentry-AI preview

ThreatSentry-AI

GitHubeclipsemanic/threatsentry-ai

ThreatSentry AI is an intelligent threat hunting dashboard that leverages machine learning to proactively identify and prioritize risks in your…

defensive-toolsincident-responseinformation-gathering+6
16 months ago
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover preview

Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover

GitHubmrk336/cluster-chaos-exploiting-cve-2025-59359-for-kubernetes-takeover

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

cloud-securitycommand-and-controlcontainer-security+8
11 months ago
BearFTP preview
Archived

BearFTP

GitHubkolya5544/bearftp

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

defensive-toolsincident-responseinformation-gathering+4
143 years ago
MemProcFS-Analyzer preview

MemProcFS-Analyzer

GitHublethal-forensics/memprocfs-analyzer

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

anomaly-detectiondigital-forensicsincident-response+5
7283 months ago
SECMON preview
Archived

SECMON

GitHubalb-uss/secmon

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

email-securityexploitationinformation-gathering+4
2684 years ago
grapl preview
Archived

grapl

GitHubgrapl-security/grapl

Graph platform for Detection and Response

cloud-securitydigital-forensicsforensics+8
6993 years ago
Previous1…8910…18Next