Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

anomaly-detectionanti-botdefensive-tools+11
8.6k
16h 18m ago
crowdsec preview

crowdsec

GitHubcrowdsecurity/crowdsec

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

anti-botdefensive-toolsids-ips-evasion+6
14.8k4 days ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k19h 51m ago
pipelock preview

pipelock

GitHubluckypipewrench/pipelock

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

ai-securityapi-securitycloud-security+8
8355h 7m ago
honeyLambda preview

honeyLambda

GitHub0x4d31/honeylambda

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

cloud-securitydefensive-toolsincident-response+2
5257 years ago
teler preview
Archived

teler

GitHubteler-sh/teler

Real-time HTTP Intrusion Detection

defensive-toolsincident-responseintrusion-detection+2
3.1k2 years ago
quien preview

quien

GitHubretlehs/quien

A better whois and domain intelligence toolkit

dns-analysisemail-securityinformation-gathering+6
1.3k2 months ago
Log4Shell-Honeypot preview
Archived

Log4Shell-Honeypot

GitHubmichaelsanford/log4shell-honeypot

Dockerized honeypot for CVE-2021-44228.

container-securityintrusion-detectionlog-analysis+2
41 year ago
machinae preview

machinae

GitHubhurricanelabs/machinae

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

information-gatheringosintthreat-feeds-aggregators+1
5363 months ago
mcp-shark preview

mcp-shark

GitHubmcp-shark/mcp-shark

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

ai-securityapi-securityconfiguration-auditing+7
1764 months ago
galah preview

galah

GitHub0x4d31/galah

Galah: An LLM-powered web honeypot.

incident-responseintrusion-detectionthreat-intelligence+1
6631 year ago
hfinger preview

hfinger

GitHubcert-polska/hfinger

Generates unique fingerprints of malware HTTP requests from pcap files using Tshark, enabling identification and grouping of malware families through…

information-gatheringmalware-analysisthreat-intelligence
1473 years ago
CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit preview

CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit

GitHubadityabhatt3010/cve-2025-61882-oracle-e-business-suite-pre-auth-rce-exploit

A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full…

exploitationforensicsincident-response+4
1210 months ago
cve-2022-21907 preview

cve-2022-21907

GitHubcorelight/cve-2022-21907

Zeek package to detect CVE-2022-21907 HTTP exploit attempts by analyzing packet captures for malformed requests and triggering alerts.

exploitationintrusion-detectionnetwork-security+3
51 year ago
CVE-2021-41773_Honeypot preview
Archived

CVE-2021-41773_Honeypot

GitHublopqto/cve-2021-41773_honeypot

Lightweight honeypot for Apache HTTP Server path traversal vulnerability CVE-2021-41773, designed to capture and log exploitation attempts.

defensive-toolsintrusion-detectionthreat-intelligence+2
24 years ago
CVE-2021-31166 preview

CVE-2021-31166

GitHubcorelight/cve-2021-31166

Detection rules (Suricata + Zeek) for CVE-2021-31166 HTTP Protocol Stack vulnerability, providing network-level alerts on exploit attempts against…

exploitationintrusion-detectionnetwork-security+3
121 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHublogesh-git001/cve-2025-55182

"One crafted HTTP request can compromise your entire server." — React Security Team, Dec 2025

educationexploitationincident-response+3
24 months ago
Apache-Authentication-Flaw-Research-CVE-2024-38476- preview

Apache-Authentication-Flaw-Research-CVE-2024-38476-

GitHubabanop22333/apache-authentication-flaw-research-cve-2024-38476-

Technical research paper analyzing CVE-2024-38476, a critical Apache HTTP Server vulnerability enabling SSRF, information disclosure, and potential…

educationincident-responsepapers-research+3
7 months ago
Previous12Next