Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
26 results
pipelock preview

pipelock

GitHubluckypipewrench/pipelock

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

ai-securityapi-securitycloud-security+8
8354h 1m ago
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

anomaly-detectionanti-botdefensive-tools+11
8.6k15h 12m ago
beelzebub preview

beelzebub

GitHubbeelzebub-labs/beelzebub

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ai-securityapi-securitycontainer-security+7
2.2k18h 45m ago
crowdsec preview

crowdsec

GitHubcrowdsecurity/crowdsec

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

anti-botdefensive-toolsids-ips-evasion+6
14.8k4 days ago
HTTP-Basma preview

HTTP-Basma

GitHubnetomize/http-basma

In the realm of cybersecurity, accurately identifying and characterizing web servers is crucial for threat detection, vulnerability assessment, and…

command-and-controlinformation-gatheringmalware-analysis+6
1 month ago
NGINX_2026_CVE_Bundle_CTI_Report preview

NGINX_2026_CVE_Bundle_CTI_Report

GitHubchpratik/nginx_2026_cve_bundle_cti_report

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

cloud-securitycurated-resourceseducation+6
1 month ago
quien preview

quien

GitHubretlehs/quien

A better whois and domain intelligence toolkit

dns-analysisemail-securityinformation-gathering+6
1.3k2 months ago
elastic-peak-dashboards preview

elastic-peak-dashboards

GitHubjconeby/elastic-peak-dashboards

PEAK Baseline Threat Hunt dashboards for Security Onion 3.0 — covering DNS, HTTP, TLS, SMB, Kerberos, SSH, RDP, DCE/RPC, LDAP, Modbus, DNP3,…

digital-forensicsdns-analysiseducation+6
32 months ago
machinae preview

machinae

GitHubhurricanelabs/machinae

Automated security intelligence collector that queries public feeds and APIs for threat data on IPs, domains, URLs, hashes, and SSL fingerprints,…

information-gatheringosintthreat-feeds-aggregators+1
5363 months ago
mcp-shark preview

mcp-shark

GitHubmcp-shark/mcp-shark

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

ai-securityapi-securityconfiguration-auditing+7
1764 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHublogesh-git001/cve-2025-55182

"One crafted HTTP request can compromise your entire server." — React Security Team, Dec 2025

educationexploitationincident-response+3
24 months ago
Apache-Authentication-Flaw-Research-CVE-2024-38476- preview

Apache-Authentication-Flaw-Research-CVE-2024-38476-

GitHubabanop22333/apache-authentication-flaw-research-cve-2024-38476-

Technical research paper analyzing CVE-2024-38476, a critical Apache HTTP Server vulnerability enabling SSRF, information disclosure, and potential…

educationincident-responsepapers-research+3
7 months ago
CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit preview

CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit

GitHubadityabhatt3010/cve-2025-61882-oracle-e-business-suite-pre-auth-rce-exploit

A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full…

exploitationforensicsincident-response+4
1210 months ago
Log4Shell-Honeypot preview
Archived

Log4Shell-Honeypot

GitHubmichaelsanford/log4shell-honeypot

Dockerized honeypot for CVE-2021-44228.

container-securityintrusion-detectionlog-analysis+2
41 year ago
galah preview

galah

GitHub0x4d31/galah

Galah: An LLM-powered web honeypot.

incident-responseintrusion-detectionthreat-intelligence+1
6631 year ago
CVE-2025-29927-Sigma-Rule preview

CVE-2025-29927-Sigma-Rule

GitHubelshaheedy/cve-2025-29927-sigma-rule

Sigma rule for detecting CVE-2025-29927 exploitation via suspicious x-middleware-subrequest HTTP headers in Next.js applications, with detection…

educationintrusion-detectionlog-analysis+3
1 year ago
CVE-2021-31166 preview

CVE-2021-31166

GitHubcorelight/cve-2021-31166

Detection rules (Suricata + Zeek) for CVE-2021-31166 HTTP Protocol Stack vulnerability, providing network-level alerts on exploit attempts against…

exploitationintrusion-detectionnetwork-security+3
121 year ago
cve-2022-21907 preview

cve-2022-21907

GitHubcorelight/cve-2022-21907

Zeek package to detect CVE-2022-21907 HTTP exploit attempts by analyzing packet captures for malformed requests and triggering alerts.

exploitationintrusion-detectionnetwork-security+3
51 year ago
Previous12Next