Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
OneAlert preview

OneAlert

GitHubmangod12/onealert

AI-powered SOC for OT/ICS networks — 6 autonomous agents, MITRE ATT&CK mapping, Suricata/Zeek ingestion, human-in-the-loop response, 330+ tests.…

ai-securityincident-responsenetwork-security+1
34
1 month ago
EasyEASM preview

EasyEASM

GitHubg0ldencybersec/easyeasm

Zero-dollar attack surface management tool

cloud-securitydns-analysisdns-subdomain-enumeration+7
3302 years ago
Cisco-FMC-honeypot preview

Cisco-FMC-honeypot

GitHubhassan-pouladi/cisco-fmc-honeypot

Originally a Honeypot for CVE-2026-20131

incident-responsemalware-analysisnetwork-security+2
22 months ago
cpanel-control-plane-exposure-check preview

cpanel-control-plane-exposure-check

GitHubsreejaputhan/cpanel-control-plane-exposure-check

Defensive exposure assessment tool for identifying externally accessible cPanel, WHM, and Webmail management interfaces related to CVE-2026-41940.

configuration-auditingdefensive-toolsnetwork-security+3
4 months ago
ketshash preview

ketshash

GitHubcyberark/ketshash

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

authenticationdefensive-toolsincident-response+3
1681 year ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubredscan/cve-2019-19781

CVE-2019-19781 Attack Triage Script

exploitationforensicsincident-response+2
16 years ago
Firewall-Rules preview

Firewall-Rules

GitHubessafar/firewall-rules

Firewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell

defensive-toolsincident-responsemisconfiguration+2
2 years ago
stegowiper preview

stegowiper

GitHubmindcrypt/stegowiper

A powerful and flexible tool to apply active attacks for disrupting stegomalware

defensive-toolsincident-responsemalware-analysis+2
554 years ago
shadowhammer preview

shadowhammer

GitHubwithsecurelabs/shadowhammer

Batch-mode checker for Shadowhammer malware indicators, scanning local or provided MAC addresses against known malicious hashes, with offline support…

defensive-toolsincident-responsemalware-analysis+2
87 years ago
tenzir preview

tenzir

GitHubtenzir/tenzir

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

incident-responselog-analysisnetwork-security+1
75850 minutes ago
xz-vulnerable-honeypot preview

xz-vulnerable-honeypot

GitHublockness-ko/xz-vulnerable-honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

defensive-toolsincident-responsenetwork-security+2
1462 years ago
citrix-logchecker preview

citrix-logchecker

GitHubcertat/citrix-logchecker

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

incident-responselog-analysisnetwork-security+3
52 years ago
honeypot.rs preview

honeypot.rs

GitHubmranv/honeypot.rs

CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.

incident-responsemalware-analysisnetwork-security+2
2 years ago
Honeypot-Logs-CVE-2025-5777 preview
Archived

Honeypot-Logs-CVE-2025-5777

GitHubbelow0day/honeypot-logs-cve-2025-5777

CitrixBleed 2 NetScaler honeypot logs

incident-responseintrusion-detectionnetwork-security+2
1 year ago
mitmengine preview
Archived

mitmengine

GitHubcloudflare/mitmengine

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

defensive-toolsincident-responsenetwork-security+1
8132 years ago