Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1451 results
drakvuf-sandbox preview

drakvuf-sandbox

GitHubcert-polska/drakvuf-sandbox

Automated hypervisor-level malware analysis sandbox with agentless guest introspection, web-based result exploration, and guided installer for…

dynamic-analysis-sandboxingforensicsmalware-analysis+2
1.3k
1 month ago
PCAPdroid preview

PCAPdroid

GitHubemanuele-f/pcapdroid

No-root network monitor, firewall and PCAP dumper for Android

android-securitydns-analysiseducation+8
4.8k1 day ago
analyzer preview

analyzer

GitHubqeeqbox/analyzer

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

digital-forensicsdynamic-analysis-sandboxingforensics+8
3222 years ago
YARA_Rules preview

YARA_Rules

GitHubmalgamy/yara_rules

Curated signature-rule collection for detecting and classifying malicious files via pattern matching, with CLI instructions for scanning files and…

curated-resourcesdefensive-toolsincident-response+3
653 years ago
cve-2025-24054-lab preview

cve-2025-24054-lab

GitHubt0tooro/cve-2025-24054-lab

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

authenticationconfiguration-auditingeducation+7
2 months ago
security-research preview

security-research

GitHubgoogle/security-research

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

curated-resourceseducationexploitation+3
4.6k12h 28m ago
OSSEM preview

OSSEM

GitHubotrf/ossem

Community-driven project for documenting, standardizing, and modeling security event logs to improve detection analytics and data normalization…

curated-resourceseducationlog-analysis+1
1.3k3 years ago
ProHunter preview

ProHunter

GitHubxueboqiu/prohunter

Graph-based threat detection system using inexact graph vector matching to compare threat graphs with CTI-derived attack query graphs for automated…

anomaly-detectioninformation-gatheringmachine-learning+3
129 months ago
SOC335-CVE-2024-49138-Investigation preview

SOC335-CVE-2024-49138-Investigation

GitHubnadineelliottcyber/soc335-cve-2024-49138-investigation

SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.

curated-resourcesdigital-forensicseducation+3
23 days ago
CVE-2026-8838-Mitigation-and-Detection preview

CVE-2026-8838-Mitigation-and-Detection

GitHubsana-404/cve-2026-8838-mitigation-and-detection

Detection and mitigation scripts for CVE-2026-8838, providing vulnerability scanning, configuration auditing, and incident response guidance to…

configuration-auditingincident-responseintrusion-detection+3
1 month ago
BugHub preview

BugHub

GitHubdecemberus/bughub

CVEHub of CVE-2023-1498 and CVE-2023-1500

curated-resourceseducationinformation-gathering+2
22 years ago
dfir-malware-investigation preview

dfir-malware-investigation

GitHubsuyash-r-k/dfir-malware-investigation

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

digital-forensicseducationincident-response+9
7 months ago
Detecting-and-Analyzing-CVE-2024-24919-Exploitation preview

Detecting-and-Analyzing-CVE-2024-24919-Exploitation

GitHubmacuchegit/detecting-and-analyzing-cve-2024-24919-exploitation

Step-by-step walkthrough of detecting and analyzing CVE-2024-24919 exploitation using a SIEM platform, including traffic analysis, IOC documentation,…

digital-forensicseducationincident-response+5
1 year ago
SOC335-CVE-2024-49138-Exploitation-Detected preview

SOC335-CVE-2024-49138-Exploitation-Detected

GitHubbridg3ops/soc335-cve-2024-49138-exploitation-detected

Detailed incident response walkthrough analyzing CVE-2024-49138 exploitation on Windows, covering process tree analysis, IOC identification, and…

digital-forensicseducationincident-response+4
9 months ago
0xCr0ssCrush preview

0xCr0ssCrush

GitHubdeathshotxd/0xcr0sscrush

Windows BYOVD research on DCRCVDrv.sys and Alinubx.sys, reverse engineering their kernel primitives, IOCTL surfaces, and detection opportunities.

binary-analysisdefensive-toolsexploitation+4
46 days ago
GOSINT preview
Archived

GOSINT

GitHubciscocsirt/gosint

The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).

information-gatheringioc-managementosint+3
5613 years ago
FileWatchTower preview

FileWatchTower

GitHubiomoath/filewatchtower

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

digital-forensicsforensicshash-analysis+4
292 years ago
crml preview

crml

GitHubfaux16/crml

Open-source declarative language for cyber risk modeling. Build Bayesian risk models like QBER, FAIR Monte Carlo engines, and enterprise risk…

educationpapers-researchthreat-intelligence+1
396 months ago
Previous12…81Next