Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
Panoptic preview

Panoptic

GitHublightos/panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

information-gatheringpenetration-testingreconnaissance+2
325
1 day ago
cowrie preview

cowrie

GitHubcowrie/cowrie

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

defensive-toolsincident-responseinformation-gathering+3
6.6k2 days ago
msticpy preview

msticpy

GitHubmicrosoft/msticpy

Microsoft Threat Intelligence Security Tools

anomaly-detectioncloud-securityeducation+6
2.0k17 days ago
waf-fu preview

waf-fu

GitHubconfused-binary/waf-fu

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

cloud-securitydefensive-toolsincident-response+6
21 month ago
PAGASUS-PRO preview

PAGASUS-PRO

GitHubthakur2309/pagasus-pro

Python ADB-based Android device management and security audit toolkit with an interactive menu for root detection, permission dumps, debuggable app…

android-securitydata-exfiltrationeducation+8
5341 month ago
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

data-exfiltrationexploitationinformation-gathering+3
1 month ago
Zeek-Endpoint-Enrichment preview

Zeek-Endpoint-Enrichment

GitHubcorelight/zeek-endpoint-enrichment

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

information-gatheringlog-analysisnetwork-security+1
43 months ago
By-Poloss..-..CVE-2026-39938 preview

By-Poloss..-..CVE-2026-39938

GitHubpolosss/by-poloss..-..cve-2026-39938

Proof-of-concept exploit for CVE-2026-39938: unauthenticated local file inclusion in Cacti <= 1.2.30, enabling arbitrary file read and remote code…

exploitationinformation-gatheringpenetration-testing+3
3 months ago
duckLogger preview

duckLogger

GitHubitsmmdoha/ducklogger

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

command-and-controldata-exfiltrationembedded-systems-security+8
935 months ago
bluepot preview

bluepot

GitHubandrewmichaelsmith/bluepot

Java-based Bluetooth honeypot that captures and stores malware from BlueBugging and BlueSnarfing attacks, with a GUI for monitoring and log analysis.

bluetooth-securitydefensive-toolsinformation-gathering+1
2796 months ago
Llama-Stack-0.4.0rc3-local-CVE-2026-25211 preview

Llama-Stack-0.4.0rc3-local-CVE-2026-25211

GitHubmbanyamer/llama-stack-0.4.0rc3-local-cve-2026-25211

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

database-securityexploitationinformation-gathering+3
8 months ago
CVE-2025-44823 preview

CVE-2025-44823

GitHubskraft9/cve-2025-44823

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

api-securityauthenticationexploitation+3
10 months ago
chatlog preview

chatlog

GitHubsjzar/chatlog

chat log tool, easily use your own chat data. 聊天记录工具,轻松使用自己的聊天数据

database-securityforensicsinformation-gathering+1
9.2k11 months ago
aced preview

aced

GitHubgarrettfoster13/aced

Parses and resolves a single Active Directory principal's DACL to identify inbound access privileges, resolve SIDs, and log LDAP attributes for…

information-gatheringpenetration-testingprivilege-escalation+1
2031 year ago
AnySniff preview

AnySniff

GitHubmkultra6969/anysniff

AnySniff is a tool for monitoring TCP connections of processes like AnyDesk on Windows. It uses the CVE-2024-52940 vulnerability to track open…

exploitationinformation-gatheringnetwork-security+3
41 year ago
CVE-2020-17519 preview

CVE-2020-17519

GitHubgazettel/cve-2020-17519

Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

exploitationinformation-gatheringpenetration-testing+3
1 year ago
url-tracker preview

url-tracker

GitHubal-sultani/url-tracker

Change monitoring app that checks the content of web pages in different periods.

information-gatheringreconnaissanceweb-security
3611 year ago
fortios-auth-bypass-poc-CVE-2024-55591 preview

fortios-auth-bypass-poc-CVE-2024-55591

GitHubsysirq/fortios-auth-bypass-poc-cve-2024-55591

Proof-of-concept exploit for FortiOS authentication bypass (CVE-2024-55591) that allows unauthenticated access to system logs via WebSocket on…

authentication-authorizationexploitationinformation-gathering+3
261 year ago
Previous123Next