Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
81 results
M365-Assess preview

M365-Assess

GitHubgalvnyz/m365-assess

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

cloud-securityconfiguration-auditingdevsecops+4
2042 months ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

ai-securitycloud-securitycommand-and-control+7
21611h 15m ago
ransomwhere preview

ransomwhere

GitHubhazcod/ransomwhere

A PoC ransomware sample to test out your ransomware response strategy.

adversarial-attackencryption-decryption-toolsincident-response+3
2181 month ago
InfraGuard preview

InfraGuard

GitHubwhispergate/infraguard

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

anti-botcommand-and-controldns-analysis+8
3161 month ago
paniclock preview

paniclock

GitHubpaniclock/paniclock

Instantly disable Touch ID and lock your Mac with one click or keyboard shortcut.

authenticationdefensive-toolsincident-response+1
4315 months ago
lowkey preview

lowkey

GitHubinceptionstack/lowkey

Deploy self-hosted AI coding agents (OpenClaw, Claude Code, Codex) into your AWS account with CloudFormation, IAM profiles, and sandbox isolation for…

ai-securitycloud-infrastructure-securitycloud-security+7
719 days ago
vinifera preview

vinifera

GitHubzomato/vinifera

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

incident-responseinformation-gatheringosint+2
952 years ago
loldrivers-client preview

loldrivers-client

GitHubrtfmkiesel/loldrivers-client

Scan your Windows computer for known vulnerable or malicious drivers.

defensive-toolsincident-responsethreat-intelligence+2
1074 months ago
oversight preview

oversight

GitHubrakosn1cek/oversight

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

code-analysisdevsecopsdynamic-analysis-sandboxing+7
391 month ago
fleet-cve-scanner preview

fleet-cve-scanner

GitHubboostedchaos/fleet-cve-scanner

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…

configuration-auditingincident-responselog-analysis+3
122 months ago
drs-malware-scan preview

drs-malware-scan

GitHubaws-samples/drs-malware-scan

Perform file-based malware scan on your on-prem servers with AWS

cloud-securityincident-responsemalware-analysis+2
142 years ago
chanleakcheck preview

chanleakcheck

GitHublightninglabs/chanleakcheck

A tool to check if your lnd node was targeted by CVE-2019-12999

cryptographyincident-responsepenetration-testing+1
106 years ago
CVE-2025-48593 preview

CVE-2025-48593

GitHublogesh-git001/cve-2025-48593

"A single malicious packet can own your device." — Android Security Team, Nov 2025

android-securitybluetooth-securityeducation+7
75 months ago
Sitecore.Solr-log4j-mitigation preview

Sitecore.Solr-log4j-mitigation

GitHubavwolferen/sitecore.solr-log4j-mitigation

This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228

configuration-auditingincident-responsescripting-automation+2
23 years ago
CVE-2022-47966_checker preview

CVE-2022-47966_checker

GitHubace-responder/cve-2022-47966_checker

Run on your ManageEngine server

forensicsincident-responseioc-management+3
23 years ago
Embarcadero-Workaround preview

Embarcadero-Workaround

GitHubhelpsystems/embarcadero-workaround

This is a workaround for CVE-2014-0993 and CVE-2014-0994 that patches on memory without the need to recompile your vulnerable software. This is not…

binary-analysisdefensive-toolsexploitation+3
111 years ago
CVE-2025-55182 preview

CVE-2025-55182

GitHublogesh-git001/cve-2025-55182

"One crafted HTTP request can compromise your entire server." — React Security Team, Dec 2025

educationexploitationincident-response+3
25 months ago
tarian preview

tarian

GitHubdevopstoday11/tarian

Anti-Virus for K8s. Protect your Applications running on Kubernetes from malicious attacks with pre-registered source code, runtime processes…

cloud-securitycontainer-securitydevsecops+2
24 years ago
Previous12345Next