Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
119 results
OmniSec-Hex preview

OmniSec-Hex

GitHubvighnesh91/omnisec-hex

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

ai-securitybinary-analysisfuzzing+9
1
2 days ago
s3dns preview

s3dns

GitHubolizimmermann/s3dns

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

cloud-securitydns-analysisinformation-gathering+5
1292 days ago
CVE-2026-58231 preview

CVE-2026-58231

GitHubwildandeveloper/cve-2026-58231

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

api-securityauthenticationinformation-gathering+4
3 days ago
godirb preview

godirb

GitHubmycode83/godirb

Fast and easy-to-use directory brute-forcer written in Go.

fuzzinginformation-gatheringpenetration-testing+3
56 days ago
Mr.SIP preview

Mr.SIP

GitHubmeliht/mr.sip

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

fuzzinginformation-gatheringpassword-cracking+2
4369 days ago
sippts preview

sippts

GitHubpepelux/sippts

Set of tools to audit SIP based VoIP Systems

exploitationfuzzinginformation-gathering+6
5729 days ago
CVE-2026-20079-checker preview

CVE-2026-20079-checker

GitHubdiegoarias008/cve-2026-20079-checker

Read-only Python checker that validates CVE-2026-20079 Cisco FMC authentication-bypass behavior by comparing unauthenticated and csm_processes…

authenticationdefensive-toolsinformation-gathering+5
10 days ago
censys-python preview

censys-python

GitHubcensys/censys-python

An easy-to-use and lightweight API wrapper for Censys APIs.

api-securityinformation-gatheringosint+2
46926 days ago
Oralyzer preview

Oralyzer

GitHubr0075h3ll/oralyzer

Python-based open redirect vulnerability scanner that fuzzes URLs to detect header, JavaScript, and meta tag-based redirects, with integrated…

fuzzinginformation-gatheringvulnerability-scanners+1
82628 days ago
lm-fingerprint preview

lm-fingerprint

GitLabwattocyber/lm-fingerprint

Fingerprint OpenAI-compatible LLMs from tokenizer and behavior signals.

ai-securityapi-securityinformation-gathering+3
1 month ago
CVE-2026-13736 preview

CVE-2026-13736

GitHubminhhk68/cve-2026-13736

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

api-securityexploitationinformation-gathering+3
1 month ago
CVE-2026-19478-PoC preview

CVE-2026-19478-PoC

GitHubdavkharrr/cve-2026-19478-poc

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

api-securityexploitationinformation-gathering+3
111 month ago
cve-2021-21994_POC preview

cve-2021-21994_POC

GitHubmreza-en/cve-2021-21994_poc

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

authenticationexploitationfuzzing+3
1 month ago
OpenDoor preview

OpenDoor

GitHubstanislav-web/opendoor

OWASP Web Recon & Directory Discovery Platform

information-gatheringpenetration-testingreconnaissance+4
1.0k1 month ago
Panoptic preview

Panoptic

GitHublightos/panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

information-gatheringpenetration-testingreconnaissance+2
3251 month ago
fuzz.txt preview

fuzz.txt

GitHubbo0om/fuzz.txt

Potentially dangerous files

fuzzinginformation-gatheringpenetration-testing+3
3.3k1 month ago
keyFinder preview

keyFinder

GitHubmomenbasel/keyfinder

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

api-securityinformation-gatheringosint+2
7182 months ago
monsoon preview

monsoon

GitHubredteampentesting/monsoon

Fast HTTP enumerator

fuzzinginformation-gatheringpenetration-testing+1
5012 months ago
Previous1234567Next