Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
PatrowlHears preview

PatrowlHears

GitHubpatrowl/patrowlhears

PatrowlHears - Vulnerability Intelligence Center / Exploits

defensive-toolsexploitationinformation-gathering+3
167
5 months ago
libtaxii preview

libtaxii

GitHubtaxiiproject/libtaxii

A Python library for handling TAXII Messages invoking TAXII Services.

ioc-managementthreat-feeds-aggregatorsthreat-intelligence+1
744 months ago
ThreatActors-TTPs preview

ThreatActors-TTPs

GitHubessexrich/threatactors-ttps

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

curated-resourcesdigital-forensicseducation+6
4828 days ago
iocs preview

iocs

GitHubthreatlabz/iocs

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

curated-resourcesincident-responseioc-management+4
8110 days ago
loboguara preview

loboguara

GitHubolivsec/loboguara
data-exfiltrationdns-subdomain-enumerationinformation-gathering+6
731 year ago
Crawlector preview

Crawlector

GitHubmfmokbel/crawlector

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

crawlerinformation-gatheringmalware-analysis+5
1238 months ago
Abused-Legitimate-Services preview

Abused-Legitimate-Services

GitHubbushidouk/abused-legitimate-services

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

curated-resourcespapers-researchphishing+2
603 years ago
gundog preview

gundog

GitHubjangeisbauer/gundog

gundog - guided hunting in Microsoft Defender

incident-responseinformation-gatheringlog-analysis+2
535 years ago
log4shell_ioc_ips preview

log4shell_ioc_ips

GitHubhackinghippo/log4shell_ioc_ips

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

incident-responseinformation-gatheringioc-management+3
374 years ago
100_days_of_kql_2026 preview

100_days_of_kql_2026

GitHubm4nbat/100_days_of_kql_2026

A repo to hold KQL queries as part of my 100 days of KQL effort.

curated-resourceseducationlearning-paths-courses+3
1915 days ago
Antiphishing preview

Antiphishing

GitHubjulioliraup/antiphishing

Advanced Phishing Protection: Suricata rulesets open and free

defensive-toolsdns-analysisids-ips-evasion+6
3016h 52m ago
phishcollector preview

phishcollector

GitHubolizimmermann/phishcollector

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

crawlereducationinformation-gathering+8
235 months ago
SeekYou preview

SeekYou

GitHubteycir/seekyou

OSINT intelligence on any IP, domain, or ASN

cloud-securitycrawlerdns-analysis+9
192 months ago
drovorub-hunt preview

drovorub-hunt

GitHubinsane-forensics/drovorub-hunt

A tool to assist with network-based hunting for GRU's Drovorub malware c2

incident-responseintrusion-detectionmalware-analysis+3
255 years ago
darkgrid preview

darkgrid

GitHubkaal22/darkgrid
dns-analysisinformation-gatheringnetwork-security+4
135 months ago
vexhub-crawler preview

vexhub-crawler

GitHubaquasecurity/vexhub-crawler

Collect VEX documents and update VEX Hub

crawlerinformation-gatheringsupply-chain-security+3
79 months ago
sigint-hombre preview

sigint-hombre

GitHubmalvuln/sigint-hombre

Dynamically generated Suricata rules from real-time threat feeds

defensive-toolsdns-analysisintrusion-detection+4
147 months ago
darwis-taxii preview

darwis-taxii

GitHubcspf-founder/darwis-taxii

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

api-securityauthentication-authorizationioc-management+3
116 months ago
Previous123Next