Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
264 results
Daily-dose-of-malware preview

Daily-dose-of-malware

GitHubwoj-ciech/daily-dose-of-malware

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

command-and-controlinformation-gatheringmalware-analysis+2
40
8 years ago
log4shell_ioc_ips preview

log4shell_ioc_ips

GitHubhackinghippo/log4shell_ioc_ips

log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)

incident-responseinformation-gatheringioc-management+3
374 years ago
Cisa-KEV-Threat-Intel-Orchestrator preview

Cisa-KEV-Threat-Intel-Orchestrator

GitHubmanishrawat21/cisa-kev-threat-intel-orchestrator

Zero-touch pipeline that turns newly weaponized CVEs from the CISA Known Exploited Vulnerabilities (KEV) catalog into production-ready Sigma…

ai-securitycloud-securitydevsecops+3
382 days ago
oversight preview

oversight

GitHubrakosn1cek/oversight

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

code-analysisdevsecopsdynamic-analysis-sandboxing+7
3925 days ago
iocx preview

iocx

GitHubiocx-dev/iocx

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

binary-analysisdevsecopsforensics+6
2910 days ago
MSDT_CVE-2022-30190 preview

MSDT_CVE-2022-30190

GitHubarchanchoudhury/msdt_cve-2022-30190

This Repository Talks about the Follina MSDT from Defender Perspective

educationincident-responseioc-management+3
374 years ago
misp-wireshark preview

misp-wireshark

GitHubmisp/misp-wireshark

Lua plugin to extract data from Wireshark and convert it into MISP format

digital-forensicsforensicsnetwork-forensics+2
502 years ago
DDWPasteRecon preview

DDWPasteRecon

GitHubviralmaniar/ddwpasterecon

DDWPasteRecon tool will help you identify code leak, sensitive files, plaintext passwords, password hashes. It also allow member of SOC & Blue Team…

data-exfiltrationdefensive-toolsincident-response+4
454 years ago
IOCScraper preview

IOCScraper

GitHubchaitanyakrishna/iocscraper

IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.

information-gatheringioc-managementosint+1
364 years ago
AIP preview

AIP

GitHubstratosphereips/aip

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

information-gatheringintrusion-detectioniot-security+3
321 year ago
nvd preview

nvd

GitHubdaehee/nvd

Fast, simple library in Go to fetch CVEs from the National Vulnerability Database feeds

information-gatheringthreat-intelligenceutilities-frameworks+1
335 years ago
OSIPs preview

OSIPs

GitHubciprianster/osips

A Python script that gathers all valid IP addresses from all text files from a directory, and checks them against Whois database, TOR relays and…

information-gatheringnetwork-securityosint+1
294 years ago
yaml2yara preview

yaml2yara

GitHubnccgroup/yaml2yara

Generate bulk YARA rules from YAML input

digital-forensicsincident-responseintrusion-detection+4
226 years ago
sloppy-joe preview

sloppy-joe

GitHubbrennhill/sloppy-joe

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

code-analysisdevsecopseducation+5
324 months ago
certgraveyard_yara preview

certgraveyard_yara

GitHubtjnel/certgraveyard_yara

Automated YARA rule generation from the Cert Central compromised certificate database.

binary-analysisdefensive-toolsforensics+2
151 day ago
AI-SPM preview

AI-SPM

GitHubdshapi/ai-spm

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

ai-securitycloud-securitymisconfiguration+3
133 months ago
PoC-AutoSync preview

PoC-AutoSync

GitHubjenderal92/poc-autosync

🧠 Automatically collects and updates public Proof-of-Concept (PoC) exploits from poc-in-github.motikan2010.net

curated-resourcesexploitationthreat-intelligence+1
316 days ago
sigint-hombre preview

sigint-hombre

GitHubmalvuln/sigint-hombre

Dynamically generated Suricata rules from real-time threat feeds

defensive-toolsdns-analysisintrusion-detection+4
147 months ago
Previous1…456…15Next