Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
264 results
inquisitor preview

inquisitor

GitHubpenafieljlm/inquisitor

Opinionated organisation-centric OSINT footprinting inspired from recon-ng and Maltego

dns-subdomain-enumerationemail-harvestinginformation-gathering+3
180
9 years ago
Minesweeper preview

Minesweeper

GitHubcodingo/minesweeper

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

cryptographythreat-intelligencevulnerability-scanners+1
2027 years ago
maldrolyzer preview

maldrolyzer

GitHubmaldroid/maldrolyzer

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

android-securitycommand-and-controlinformation-gathering+3
11211 years ago
Orion preview

Orion

GitHubstrangerealintel/orion

A YARA rules repository continuously updated for monitoring the old and new threats from articles, incidents responses ...

curated-resourcesdefensive-toolsmalware-analysis+1
1412 years ago
public-research preview

public-research

GitHubdeepfield/public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

ioc-managementmalware-analysisnetwork-security+3
6322 days ago
Gotanda preview

Gotanda

GitHubhash1da1/gotanda

Browser extension for OSINT that searches threat intelligence and reconnaissance data from selected IOCs (IP, domain, URL, hash, SNS) via multiple…

information-gatheringosintreconnaissance+1
1934 years ago
fortigate-belsen-leak preview

fortigate-belsen-leak

GitHubarsolutioner/fortigate-belsen-leak

Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group

educationincident-responseinformation-gathering+3
871 year ago
iocs preview

iocs

GitHubthreatlabz/iocs

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

curated-resourcesincident-responseioc-management+4
8110 days ago
xioc preview

xioc

GitHubassafmo/xioc

Extract indicators of compromise from text, including "escaped" ones.

forensicsinformation-gatheringioc-management+3
1636 years ago
hfinger preview

hfinger

GitHubcert-polska/hfinger

Generates unique fingerprints of malware HTTP requests from pcap files using Tshark, enabling identification and grouping of malware families through…

information-gatheringmalware-analysisthreat-intelligence
1473 years ago
memOptix preview

memOptix

GitHubblueteam0ps/memoptix

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

digital-forensicsforensicsincident-response+2
983 years ago
RansomCoinPublic preview

RansomCoinPublic

GitHubconcinnity-risks/ransomcoinpublic

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

cryptographydigital-forensicsforensics+3
562 years ago
indicator-intelligence preview

indicator-intelligence

GitHubosmankandemir/indicator-intelligence

Collects static files from target domains to discover related domains and IPv4 addresses for threat intelligence and IOC enrichment.

dns-subdomain-enumerationinformation-gatheringosint+1
1021 year ago
ipChecker preview

ipChecker

GitHubmthbernardes/ipchecker

Check if a IP is from tor or is a malicious proxy

information-gatheringnetwork-securityosint+1
568 years ago
z9 preview

z9

GitHubsh1n0g1/z9

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

forensicslog-analysismalware-analysis+2
682 years ago
Royal_APT preview

Royal_APT

GitHubnccgroup/royal_apt

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

command-and-controlcurated-resourcesintrusion-detection+3
528 years ago
Attacker-Group-Predictor preview

Attacker-Group-Predictor

GitHubomergunal/attacker-group-predictor

Tool to predict attacker groups from the techniques and software used

information-gatheringosintreconnaissance+1
495 years ago
threat-research preview

threat-research

GitHubthreatray/threat-research

IoCs and YARA rules from Threatray's Threat Research

forensicsincident-responseioc-management+2
223 days ago
Previous1…345…15Next