Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
Claude-BugHunter preview

Claude-BugHunter

GitHubelementalsouls/claude-bughunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

api-securitycloud-securitycurated-resources+8
4.8k
16h 28m ago
vuln-bank preview

vuln-bank

GitHubcommando-x/vuln-bank

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

ai-securityapi-securitycode-analysis+5
96513 days ago
CVE-2026-52616 preview

CVE-2026-52616

GitHubs1ko/cve-2026-52616

Advisory and benign PoC for OS command injection in an nmap MCP server, with duplicate CVE tracking, detection guidance, and mitigation.

api-securityexploitationnetwork-security+1
1 month ago
CVE-2026-73519-WolfStack-PoC preview

CVE-2026-73519-WolfStack-PoC

GitHubsqueeze440/cve-2026-73519-wolfstack-poc

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

api-securityauthenticationcontainer-security+3
1 month ago
EITS-Portal-Exploit-CVE-2026-31367-PoC preview

EITS-Portal-Exploit-CVE-2026-31367-PoC

GitHubhereticl1nk/eits-portal-exploit-cve-2026-31367-poc

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

api-securityexploitationpenetration-testing+2
1 month ago
keyhacks preview

keyhacks

GitHubstreaak/keyhacks

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

api-securitypenetration-testingsecret-detection+1
6.3k1 month ago
corelight-client preview

corelight-client

GitHubcorelight/corelight-client

Corelight Sensor API command-line client

api-securityauthentication-authorizationdefensive-tools+2
182 months ago
PwnedCheck preview

PwnedCheck

GitHubmohamedation/pwnedcheck

A command-line tool to check if passwords have been exposed in data breaches using the Have I Been Pwned (HIBP) API.

api-securityencryption-decryption-toolspassword-cracking+3
33 months ago
http-mcp-bridge preview

http-mcp-bridge

GitHubnccgroup/http-mcp-bridge

HTTP proxy bridge for security testing of remote MCP servers, allowing standard HTTP tools to send JSON-RPC messages and manage sessions.

api-securitypenetration-testingweb-proxies-interception+1
185 months ago
wardgate preview

wardgate

GitHubwardgate/wardgate

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

api-securityauthentication-authorizationcloud-security+8
1367 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
37 months ago
CVE-2025-6514 preview

CVE-2025-6514

GitHubcyberency/cve-2025-6514

mcp-remote exposed to OS command injection

api-securityauthenticationcommand-and-control+3
710 months ago
graphql-cop preview

graphql-cop

GitHubdolevf/graphql-cop

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

api-securityapi-security-testingdynamic-code-analysis+5
69511 months ago
appspec-yaml-leaks preview

appspec-yaml-leaks

GitHubcappricio-securities/appspec-yaml-leaks

Appspec YML and YAML leaks

api-securitycloud-securityinformation-gathering+4
12 years ago
GraphStrike preview

GraphStrike

GitHubredsiege/graphstrike

Cobalt Strike HTTPS beaconing over Microsoft Graph API

api-securitycloud-securitycommand-and-control+3
6372 years ago
azureOutlookC2 preview

azureOutlookC2

GitHubboku7/azureoutlookc2

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

api-securitycloud-securitycommand-and-control+2
5033 years ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1186 years ago
wikipedia-c2 preview

wikipedia-c2

GitHubdaniel-infosec/wikipedia-c2

POC for utilizing wikipedia API for Command and Control

api-securitycommand-and-controlexploitation+3
297 years ago