Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Vulnerability Analysis

Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

NewestRelevanceMost popularRecently updated
25175 results
lynis preview

lynis

GitHubcisofy/lynis

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

vulnerability-scannersconfiguration-auditingpenetration-testing
16.1k15 days ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

vulnerability-scannersweb-vulnerability-scannersdynamic-analysis-sandboxing+5
15.6k22h 51m ago
Sn1per preview

Sn1per

GitHub1n3/sn1per

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

osintpenetration-testing-frameworksreconnaissance+7
10.8k1 month ago
faraday preview

faraday

GitHubinfobyte/faraday

Open Source Vulnerability Management Platform

vulnerability-scannerspenetration-testingdevsecops+1
6.7k1 day ago
windows_hardening preview

windows_hardening

GitHub0x6d69636b/windows_hardening

Audits Windows security settings against CIS, Microsoft, STIG, and BSI baselines, scores compliance, and applies hardening changes via registry or…

defensive-toolsconfiguration-auditingmisconfiguration
2.6k1 month ago
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationdefensive-toolspassword-attacks+5
2.5k1 month ago
the-bastion preview

the-bastion

GitHubovh/the-bastion

Authentication, authorization, traceability and auditability for SSH accesses.

authentication-authorizationconfiguration-auditingnetwork-security+4
2.2k23 days ago
Findsploit preview

Findsploit

GitHub1n3/findsploit

Find exploits in local and online databases instantly

exploit-frameworksvulnerability-analysisinformation-gathering+2
1.8k4 years ago
BinAbsInspector preview

BinAbsInspector

GitHubkeensecuritylab/binabsinspector

Static binary vulnerability scanner using abstract interpretation on Ghidra Pcode. Detects CWE classes like buffer overflows, use-after-free, and…

static-analysisvulnerability-scannersreverse-engineering+2
1.7k2 years ago
noir preview

noir

GitHubowasp-noir/noir

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

static-analysisvulnerability-analysisweb-security+3
1.4k1 day ago
nuclei-wordfence-cve preview

nuclei-wordfence-cve

GitHubtopscoder/nuclei-wordfence-cve

80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

vulnerability-scannersvulnerability-analysisexploitation+3
1.3k29 minutes ago
Pompem preview

Pompem

GitHubrfunix/pompem

Find exploit tool

vulnerability-scannersexploit-frameworksinformation-gathering+1
1.0k7 years ago
Wordpresscan preview
Archived

Wordpresscan

GitHubswisskyrepo/wordpresscan

WPScan rewritten in Python + some WPSeku ideas

reconnaissancevulnerability-scannersweb-vulnerability-scanners+3
6535 years ago
brutus preview

brutus

GitHubpraetorian-inc/brutus

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

vulnerability-scannerspassword-attacksexploitation+7
30714h 10m ago
octoscan preview

octoscan

GitHubsynacktiv/octoscan

Octoscan is a static vulnerability scanner for GitHub action workflows.

static-analysisvulnerability-scannerscode-analysis+5
2734 months ago
extended-xss-search preview

extended-xss-search

GitHubdamian89/extended-xss-search

A better version of my xssfinder tool - scans for different types of xss on a list of urls.

vulnerability-scannersweb-vulnerability-scannersinformation-gathering+2
1897 years ago
caracal preview

caracal

GitHubcrytic/caracal

Static Analyzer for Starknet smart contracts

static-analysisvulnerability-analysiscode-analysis
1482 years ago
trigmap preview

trigmap

GitHubleviathan36/trigmap

A wrapper for Nmap to quickly run network scans

vulnerability-scannersnetwork-mappingpassword-attacks+3
1465 years ago
Previous1234…1399Next