Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
203 results
HashSiphon preview

HashSiphon

GitHubivancabrera02/hashsiphon

Extracts the current user's NetNTLMv2 hash via HTTP authentication proxying, avoiding direct SSPI calls; v2 delegates auth to the BITS service to…

defensive-toolsinformation-gatheringpassword-attacks+3
32
8 days ago
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
36 days ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
954 days ago
misfortune-cookie preview

misfortune-cookie

GitHubluel-4013/misfortune-cookie

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

binary-exploitationembedded-systems-securityexploitation+6
7 days ago
CVE-2026-33234 preview

CVE-2026-33234

GitHubpavanchow/cve-2026-33234

SSRF via smtplib raw TCP sockets bypassing HTTP blocklist in AutoGPT SendEmailBlock

exploitationinformation-gatheringnetwork-security+2
8 days ago
CVE-2025-62168 preview

CVE-2025-62168

GitHubshahroodcert/cve-2025-62168

Proof-of-concept scanner for CVE-2025-62168, a Squid Proxy information disclosure vulnerability that exposes HTTP authentication credentials,…

exploitationinformation-gatheringpenetration-testing+2
110 months ago
CVE-2026-21962 preview

CVE-2026-21962

GitHubsamael0x4/cve-2026-21962

Unauthenticated vulnerability that may allow remote attackers to compromise confidentiality and integrity, potentially leading to full system…

information-gatheringpenetration-testingvulnerability-scanners+1
67 months ago
CVE-2025-62168 preview

CVE-2025-62168

GitHubmonzaviman/cve-2025-62168

Scanner and proof-of-concept for CVE-2025-62168, detecting Squid Proxy information disclosure that leaks HTTP authentication credentials.

exploitationinformation-gatheringpenetration-testing+2
1610 months ago
GitLab-SSRF-CVE-2021-22214 preview

GitLab-SSRF-CVE-2021-22214

GitHubkh4sh3i/gitlab-ssrf-cve-2021-22214

Proof-of-concept exploit for CVE-2021-22214, a server-side request forgery in GitLab webhooks, allowing unauthenticated attackers to make internal…

exploitationinformation-gatheringvulnerability-analysis+2
34 years ago
log4j preview

log4j

GitHubhassaanahmad813/log4j

Multithreaded Python scanner that detects Log4Shell (CVE-2021-44228) by sending crafted HTTP requests with JNDI payloads and monitoring DNS callbacks…

dns-analysisexploitationinformation-gathering+2
4 years ago
cve-2026-20127 preview

cve-2026-20127

GitHubgigachadusers/cve-2026-20127

Windows-based C++ network scanner that fingerprints Cisco SD-WAN/vManage services and checks for CVE-2026-20127 exposure via HTTP endpoint analysis.

information-gatheringnetwork-securitypenetration-testing+2
25 months ago
CVE-2026-35584 preview

CVE-2026-35584

GitHubspoo1k/cve-2026-35584

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

exploitationinformation-gatheringpenetration-testing+3
5 months ago
ethr preview

ethr

GitHubmicrosoft/ethr

Cross-platform CLI for network performance testing over TCP, UDP, HTTP, HTTPS, and ICMP: bandwidth, connections/s, packets/s, latency, loss, jitter,…

data-exfiltrationgeneral-purpose-utilitiesinformation-gathering+3
5.9k9 months ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
23 days ago
cantina preview
Archived

cantina

GitLabwattocyber/cantina

OSCP-legal network recon orchestrator for port discovery, service classification, and enum-only plugin dispatch across HTTP, SMB, FTP, SNMP, SSH, and…

information-gatheringnetwork-mappingpenetration-testing+2
26 days ago
httprobe preview

httprobe

GitHubtomnomnom/httprobe

Take a list of domains and probe for working HTTP and HTTPS servers

dns-subdomain-enumerationgeneral-purpose-utilitiesinformation-gathering+7
3.1k4 years ago
CypherDog preview

CypherDog

GitHubsadprocessor/cypherdog

PoSh BloodHound Dog Whisperer

information-gatheringpenetration-testingreconnaissance+2
1933 years ago
thermoptic preview

thermoptic

GitHubmandatoryprogrammer/thermoptic

A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.

anti-botcaptcha-bypasscrawler+5
1.0k5 months ago
Previous12…12Next