Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
236 results
akamai-security-research preview

akamai-security-research

GitHubakamai/akamai-security-research

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

exploitationioc-managementmalware-analysis+2
537
4 months ago
droidbox preview

droidbox

GitHubpjlantz/droidbox

Dynamic analysis sandbox for Android apps that monitors network traffic, file operations, cryptographic API usage, permission circumvention, and…

android-securitydynamic-analysis-sandboxinginformation-gathering+2
8056 years ago
Hunt-Sleeping-Beacons preview

Hunt-Sleeping-Beacons

GitHubtheflink/hunt-sleeping-beacons

Callstack scanner that identifies IOCs of unpacked or injected C2 agents by analyzing thread idle behavior, unbacked memory, module stomping, APCs,…

binary-analysisdefensive-toolsforensics+3
6796 months ago
packj preview

packj

GitHubossillate-inc/packj

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

devsecopsdynamic-analysis-sandboxingmalware-analysis+3
6914 months ago
VMwareCloak preview

VMwareCloak

GitHubd4rksystem/vmwarecloak

A PowerShell script that attempts to help malware analysts hide their VMware Windows VM's from malware that may be trying to evade analysis.

defensive-toolsdynamic-analysis-sandboxingmalware-analysis+1
4461 year ago
crypter preview

crypter

GitHubpushpenderindia/crypter

Python-based crypter that encrypts source code with AES-256 and Base64, evades VM detection via registry, process, and MAC checks, and executes…

encryption-decryption-toolsids-ips-evasionmalware-analysis
3494 years ago
php-malware-finder preview

php-malware-finder

GitHubnbs-system/php-malware-finder

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

malware-analysisstatic-analysisvulnerability-scanners+1
3424 years ago
mobileAudit preview

mobileAudit

GitHubmpast/mobileaudit

Django application that performs SAST and Malware Analysis for Android APKs

android-securitycode-analysismalware-analysis+4
22627 days ago
bluepot preview

bluepot

GitHubandrewmichaelsmith/bluepot

Java-based Bluetooth honeypot that captures and stores malware from BlueBugging and BlueSnarfing attacks, with a GUI for monitoring and log analysis.

bluetooth-securitydefensive-toolsinformation-gathering+1
2774 months ago
VBoxCloak preview

VBoxCloak

GitHubd4rksystem/vboxcloak

A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade…

anti-botdefensive-toolsids-ips-evasion+1
4171 year ago
IATelligence preview

IATelligence

GitHubfr0gger/iatelligence

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

ai-assisted-reversingbinary-analysismalware-analysis+3
3843 years ago
GoAT preview

GoAT

GitHubpetercunha/goat

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

command-and-controlexploitationlateral-movement+7
2619 years ago
replica preview

replica

GitHubreb311ion/replica

Ghidra plugin that enhances reverse engineering by fixing missed disassembly, detecting functions, labeling crypto constants, and renaming functions…

binary-analysiscryptographymalware-analysis+2
3156 years ago
droidlysis preview

droidlysis

GitHubcryptax/droidlysis

Automated pre-analysis tool for Android apps that disassembles samples, extracts properties via configurable pattern matching, and organizes output…

android-securityinformation-gatheringmalware-analysis+3
31110 days ago
Reversecore_MCP preview

Reversecore_MCP

GitHubsjkim1127/reversecore_mcp

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

binary-analysisdigital-forensicsdynamic-analysis-sandboxing+7
1883 days ago
RansomLord preview

RansomLord

GitHubmalvuln/ransomlord

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

binary-exploitationdefensive-toolsexploitation+4
5161 year ago
DGA preview

DGA

GitHubandrewaeva/dga

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

dns-analysiseducationmachine-learning+4
2269 years ago
zombie-zip preview

zombie-zip

GitHubbombadil-systems/zombie-zip

Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.

exploitationids-ips-evasionmalware-analysis+5
1975 months ago
Previous123…14Next