Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
731 results
Kage-DFIR-toolkit preview

Kage-DFIR-toolkit

GitHubkarim852/kage-dfir-toolkit

Windows host DFIR triage console that chains artefact collection, Sigma-correlated timelines, YARA scans, socket and account inspection, indicator…

defensive-toolsdigital-forensicsforensics+8
8
4 days ago
StealC-Stealer-RuntimeBroker-Hollowing-C2-Extraction-Payload-Extraction-Analysis preview

StealC-Stealer-RuntimeBroker-Hollowing-C2-Extraction-Payload-Extraction-Analysis

GitHubkaandemir993/stealc-stealer-runtimebroker-hollowing-c2-extraction-payload-extraction-analysis

Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction.…

command-and-controldata-exfiltrationdigital-forensics+7
1 day ago
Hundred OSINT preview

Hundred OSINT

GitLabt-beckett/h-osint

Local-first, keyboard-driven OSINT workbench for the terminal with 28 modules covering username, domain, IP, email, breach, and geolocation lookups…

dns-analysiseducationemail-harvesting+7
4 days ago
Tourmaline preview

Tourmaline

GitHubv-pun215/tourmaline

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

command-and-controlcryptographydigital-forensics+7
44 days ago
CVE-2026-86218-N-central-IOC-Toolkit preview

CVE-2026-86218-N-central-IOC-Toolkit

GitHubjithinkrishnanrs/cve-2026-86218-n-central-ioc-toolkit

Defensive IOC and detection toolkit for CVE-2026-86218, a critical pre-auth RCE in N-able N-central. Includes IOCs, log scanner, Sigma, Splunk,…

defensive-toolseducationincident-response+5
3 days ago
gitlab-cve-2026-85706-ioc preview

gitlab-cve-2026-85706-ioc

GitHubjithinkrishnanrs/gitlab-cve-2026-85706-ioc

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE…

defensive-toolsincident-responseinformation-gathering+8
13 days ago
SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515 preview

SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515

GitHubborsch-appreciator/soc235---atlassian-confluence-broken-access-control-0-day-cve-2023-22515

SOC analyst walkthrough triaging a Confluence CVE-2023-22515 broken access control exploitation attempt, covering log analysis, MITRE ATT&CK mapping,…

defensive-toolseducationincident-response+5
1 month ago
CVE-2026-42978-PoC-Research preview

CVE-2026-42978-PoC-Research

GitHubsyntaxmethod/cve-2026-42978-poc-research

CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module…

defensive-toolseducationexploitation+5
133 days ago
CVE-2026-41089-Netlogon preview

CVE-2026-41089-Netlogon

GitHubzerodayvpn/cve-2026-41089-netlogon

🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack…

defensive-toolseducationexploitation+5
4 days ago
spookyssl-pcaps preview

spookyssl-pcaps

GitHubfox-it/spookyssl-pcaps

PCAPs and Suricata signatures for detecting OpenSSL CVE-2022-3602 exploitation attempts, including malicious client/server traffic and legitimate…

intrusion-detectionnetwork-securitypacket-sniffing-analysis+2
103 years ago
SDK preview

SDK

GitHubintelligencex/sdk

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

api-security-testinginformation-gatheringosint+2
5503 months ago
pocindex preview

pocindex

GitHub0xmarcio/pocindex

Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.

curated-resourcesexploitationexploit-frameworks+5
1.4k6 days ago
birdy-edwards preview

birdy-edwards

GitHubjeet-ganguly/birdy-edwards

Automated AI powered Facebook intelligence tool for target profiling, network analysis and threat reporting. Runs entirely on-device via Ollama.…

ai-securitycrawlerinformation-gathering+3
8520 days ago
qubes-secpack preview

qubes-secpack

GitHubqubesos/qubes-secpack

Curated repository of Qubes OS security bulletins, canaries, PGP keys, and ISO digests, with authenticated verification via git tags and detached…

cryptographycurated-resourceseducation+2
5515 days ago
CVE-2024-49138-SOC-Investigation preview

CVE-2024-49138-SOC-Investigation

GitHubadisasoc/cve-2024-49138-soc-investigation

SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege…

digital-forensicseducationincident-response+4
13 days ago
linux-kernel-codex-harness-v2 preview

linux-kernel-codex-harness-v2

GitHubfoxirain/linux-kernel-codex-harness-v2

Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075

ai-securitystatic-analysisthreat-intelligence+1
1 month ago
FLAIR preview

FLAIR

GitHubwithsecurelabs/flair

Lightweight batch script for semi-automated acquisition of key forensic artefacts from Windows hosts, using only native OS tools to support incident…

digital-forensicsforensicsincident-response+2
165 years ago
lazarus-sigma-rules preview

lazarus-sigma-rules

GitHubwithsecurelabs/lazarus-sigma-rules

Sigma rules for detecting Lazarus Group TTPs, covering malicious document execution, PowerShell abuse, scheduled tasks, and credential access,…

defensive-toolsincident-responseintrusion-detection+2
205 years ago
Previous12…41Next