Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
57 results
awesome-lists preview

awesome-lists

GitHubmthcht/awesome-lists

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

curated-resourcesdigital-forensicseducation+4
1.9k
2 days ago
CSPBypass preview

CSPBypass

GitHubrenniepak/cspbypass

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

configuration-auditingcurated-resourcesmisconfiguration+4
7142 days ago
misp-taxonomies preview

misp-taxonomies

GitHubmisp/misp-taxonomies

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

curated-resourcesincident-responseioc-management+2
3043 days ago
agent-governance-toolkit preview

agent-governance-toolkit

GitHubmicrosoft/agent-governance-toolkit

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

ai-securitycurated-resourcesdevsecops+2
6.1k3 days ago
resolvers preview

resolvers

GitHubtrickest/resolvers

The most exhaustive list of reliable DNS resolvers.

curated-resourcesdns-analysisdns-subdomain-enumeration+6
1.0k6 days ago
Learn-Web-Hacking preview

Learn-Web-Hacking

GitHublylemi/learn-web-hacking

Structured study notes covering web hacking fundamentals, common vulnerabilities, penetration testing techniques, and defensive security, with…

curated-resourceseducationlearning-paths-courses+2
5.5k7 days ago
misp-galaxy preview

misp-galaxy

GitHubmisp/misp-galaxy

Clusters and elements to attach to MISP events or attributes (like threat actors)

adversarial-attackcurated-resourcesioc-management+5
6357 days ago
querytool preview

querytool

GitHuboryon-osint/querytool

Querytool is an OSINT framework based on Google Spreadsheet. With this tool you can perform complex search of terms, people, email addresses, files…

curated-resourceseducationinformation-gathering+3
31815 days ago
OWASP-MCP-Threat-Modeling preview

OWASP-MCP-Threat-Modeling

GitHubowasp/owasp-mcp-threat-modeling

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

curated-resourceseducationthreat-intelligence+1
1 month ago
awesome-osint-arsenal preview

awesome-osint-arsenal

GitHubrawfilejson/awesome-osint-arsenal

OSINT & recon toolkit // 100+ tools, one-command installer, SOCMINT, GEOINT, network recon, dark web, forensics & more.

ctfcurated-resourcesdigital-forensics+8
2.5k1 month ago
API-Security-Checklist preview

API-Security-Checklist

GitHubshieldfy/api-security-checklist

Checklist of the most important security countermeasures when designing, testing, and releasing your API

api-securityauthentication-authorizationcurated-resources+4
23.3k1 month ago
dicozorus preview

dicozorus

GitHubsynacktiv/dicozorus

A tool to generate and maintain wordlists for Web fuzzing.

curated-resourcesfuzzinginformation-gathering+4
161 month ago
ossem-power-up preview

ossem-power-up

GitHubhxnoyd/ossem-power-up

A tool to assess data quality, built on top of the awesome OSSEM.

curated-resourceseducationlog-analysis+1
791 month ago
CVE-2026-54519 preview

CVE-2026-54519

GitHubchaitanyagarware/cve-2026-54519

Public advisory landing page for CVE-2026-54519: missing ownership checks in ai-agent-automation memory APIs enabling cross-user memory read and…

ai-securityauthentication-authorizationcurated-resources+3
11 month ago
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.6k1 month ago
kassandra_x33fcon_2026 preview

kassandra_x33fcon_2026

GitHubthreathunters-io/kassandra_x33fcon_2026

This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made available…

curated-resourceseducationpapers-research
642 months ago
obsidian-osint-templates preview

obsidian-osint-templates

GitHubwebbreacher/obsidian-osint-templates

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

curated-resourceseducationinformation-gathering+2
8062 months ago
cent preview

cent

GitHubxm1k3/cent

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

curated-resourcespenetration-testingvulnerability-scanners+1
1.0k2 months ago
Previous1234Next