Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
NetAlertX preview

NetAlertX

GitHubnetalertx/netalertx

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

configuration-auditingdevsecopsincident-response+6
7.2k
20h 56m ago
sharingan preview

sharingan

GitHubleobeosab/sharingan

Offensive Security recon tool

dns-subdomain-enumerationinformation-gatheringpenetration-testing+2
925 years ago
CVE-2024-30043-XXE preview

CVE-2024-30043-XXE

GitHubw01fh4cker/cve-2024-30043-xxe

Exploiting XXE Vulnerabilities on Microsoft SharePoint Server and Cloud via Confused URL Parsing

exploitationinformation-gatheringpenetration-testing+3
332 years ago
tgscope preview

tgscope

GitHubitsmoorgrove/tgscope

Telegram OSINT, scraping and archival as a local web app. Multi-account collection, profile lookup with historic photos and change diffs, ten export…

crawlerdigital-forensicsinformation-gathering+1
1 month ago
wifi-pentesting-guide preview

wifi-pentesting-guide

GitHubricardojoserf/wifi-pentesting-guide

WiFi Penetration Testing Guide

educationinformation-gatheringpassword-cracking+5
7452 years ago
hide-me preview
Archived

hide-me

GitHubandrei-zgirvaci/hide-me

Mac and hostname random changer

general-purpose-utilitiesinformation-gatheringpenetration-testing+4
448 years ago
smtp_userenum preview

smtp_userenum

GitHubh3x0v3rl0rd/smtp_userenum

Python script for enumerating SMTP users by leveraging VRFY and EXPN commands to identify valid email accounts on a target mail server.

email-harvestingemail-securityinformation-gathering+4
1 year ago
xpl-ModernWMS-CVE-2024-57698 preview

xpl-ModernWMS-CVE-2024-57698

GitHubrodolfomarianocy/xpl-modernwms-cve-2024-57698

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

exploitationinformation-gatheringmisconfiguration+3
1 year ago
Nac_Bypass_Agent preview

Nac_Bypass_Agent

GitHubalperenugurlu/nac_bypass_agent

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

educationids-ips-evasionimpersonation-tools+5
733 years ago
JSScanner preview

JSScanner

GitHubdark-warlord14/jsscanner

You can read the writeup on this script here

information-gatheringosintsecret-detection+1
2736 years ago
spybrowse preview

spybrowse

GitHub1d8/spybrowse

Code developed to steal certain browser config files (history, preferences, etc)

data-exfiltrationinformation-gatheringmalware-analysis+2
636 years ago
ipchanger preview

ipchanger

GitHubcappricio-securities/ipchanger

IPChanger is a lightweight command-line tool designed for ethical hackers, security researchers, and privacy enthusiasts. It allows users to…

information-gatheringosintpenetration-testing+2
166 months ago
Monitorizer preview

Monitorizer

GitHubbitthebyte/monitorizer

Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools

dns-subdomain-enumerationinformation-gatheringreconnaissance+1
2872 years ago
Rogue-MySql-Server preview

Rogue-MySql-Server

GitHubal1ex/rogue-mysql-server

Rogue-MySql-Server

database-securitydata-exfiltrationexploitation+3
56 years ago
ChangeTower preview

ChangeTower

GitHubdc4ts/changetower

Lightweight web page change monitor written in Go. Detects updates on target URLs and sends notifications via Telegram or other services, ideal for…

crawlerinformation-gatheringweb-security
415 years ago
nanwinata-CVE-2024-52301 preview

nanwinata-CVE-2024-52301

GitHubfckoo/nanwinata-cve-2024-52301

Scans for CVE-2024-52301, an argument injection vulnerability in Laravel, using subfinder and httpx to identify affected web applications.

exploitationinformation-gatheringreconnaissance+2
1 year ago
CVE-2020-24029 preview

CVE-2020-24029

GitHubredteambrasil/cve-2020-24029

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

authenticationexploitationinformation-gathering+4
1 month ago
CVE-2020-24029 preview

CVE-2020-24029

GitHubunderprotection/cve-2020-24029

Proof-of-concept for CVE-2020-24029: unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege…

authenticationexploitationinformation-gathering+3
6 years ago
Previous12Next