Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
laravel-threat-detection preview

laravel-threat-detection

GitHubjay123anta/laravel-threat-detection

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

anti-botapi-securitydefensive-tools+6
36
6 days ago
waf-fu preview

waf-fu

GitHubconfused-binary/waf-fu

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

cloud-securitydefensive-toolsincident-response+6
21 month ago
Honeypot-Project preview

Honeypot-Project

GitHubowasp/honeypot-project

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

defensive-toolseducationincident-response+5
1091 month ago
Zimbra-CVE-2026-73570-Rules preview

Zimbra-CVE-2026-73570-Rules

GitHubinfokom-ki/zimbra-cve-2026-73570-rules

Wazuh detection rules for CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite, monitoring web access logs and zimbra.log for…

intrusion-detectionlog-analysisthreat-intelligence+2
1 month ago
GPEWebDefender preview

GPEWebDefender

GitHubgopasteverything/gpewebdefender

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

defensive-toolsincident-responseinformation-gathering+8
21 month ago
POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability preview

POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability

GitHubsam00/poc-cve-2026-42826-2026-42826-microsoft-azure-devops-information-disclosure-vulnerability

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

cloud-securityexploitationinformation-gathering+4
2 months ago
sharemylogin preview

sharemylogin

GitHubelandio-com/sharemylogin

Zero-Knowledge Credential Sharing

authenticationencryption-decryption-toolsprivacy+3
572 months ago
Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation preview

Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation

GitHubzedocun/incident-analysis-response-check-point-security-gateway-cve-2024-24919-lfi-exploitation

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

digital-forensicseducationincident-response+7
12 months ago
nginx-rift-detector preview

nginx-rift-detector

GitHublimo57640-crypto/nginx-rift-detector

Free NGINX Rift CVE-2026-42945 detector for version, rewrite config, ASLR, crash logs, and exploitation indicators.

configuration-auditingdefensive-toolsincident-response+3
3 months ago
CVE-2026-37067 preview

CVE-2026-37067

GitHubjfs-jfs/cve-2026-37067

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract…

exploitationinformation-gatheringmisconfiguration+2
3 months ago
apache-web-log-analysis-lab preview

apache-web-log-analysis-lab

GitHubpedrofbrm/apache-web-log-analysis-lab

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

educationlabs-practicelog-analysis+1
5 months ago
secure-by-default-rce-demo preview

secure-by-default-rce-demo

GitHubmeganekos/secure-by-default-rce-demo

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

cloud-securitycontainer-securitydevsecops+6
9 months ago
sharepoint-toolshell-micro-postmortem preview

sharepoint-toolshell-micro-postmortem

GitHubcameloo1/sharepoint-toolshell-micro-postmortem

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

curated-resourceseducationforensics+7
19 months ago
ToolShellFinder preview

ToolShellFinder

GitHubzach115th/toolshellfinder

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

digital-forensicsforensicsincident-response+5
10 months ago
CVE-2025-56643 preview

CVE-2025-56643

GitHub0xbs0d27/cve-2025-56643

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability

api-securityauthenticationexploitation+2
111 months ago
WSUSploit.NET preview

WSUSploit.NET

GitHub0xbruno/wsusploit.net

C# proof-of-concept for CVE-2025-59287 targeting WSUS, demonstrating exploitation and providing defensive detection guidance for IIS logs and Windows…

educationexploitationpenetration-testing+3
111 months ago
sslsplit preview

sslsplit

GitHubdroe/sslsplit

Transparent man-in-the-middle proxy that terminates SSL/TLS connections, forges certificates on-the-fly, and logs decrypted traffic for network…

encryption-decryption-toolsforensicsids-ips-evasion+5
1.9k11 months ago
CVE-2025-10377 preview

CVE-2025-10377

GitHubnagisayumaa/cve-2025-10377

CVE-2025-10377

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
Previous123Next