Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
418 results
proxmark3 preview

proxmark3

GitHubrfidresearchgroup/proxmark3

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

bluetooth-securitycryptographyembedded-systems-security+11
6.1k
2 days ago
AutoRecon preview

AutoRecon

GitHubautorecon/autorecon

Multi-threaded network reconnaissance tool that automates service enumeration, port scanning, and information gathering for penetration testing and…

ctfinformation-gatheringnetwork-mapping+3
6.1k10 months ago
nishang preview

nishang

GitHubsamratashok/nishang

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

command-and-controldata-exfiltrationexploitation+9
10.1k3 years ago
android-reverse-engineering-skill preview

android-reverse-engineering-skill

GitHubsimoneavogadro/android-reverse-engineering-skill

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

android-securityapi-security-testingbinary-analysis+8
8.0k1 month ago
Hacking-Tools preview

Hacking-Tools

GitHubyogsec/hacking-tools

A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other…

educationexploitationforensics+9
2.1k5 days ago
Offensive-OSINT-Tools preview

Offensive-OSINT-Tools

GitHubwddadk/offensive-osint-tools

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

curated-resourcesdns-analysisemail-harvesting+8
1.3k2 months ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.3k1 month ago
AzureHound preview

AzureHound

GitHubspecterops/azurehound

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

cloud-securityinformation-gatheringosint+2
96716 days ago
airecon preview

airecon

GitHubpikpikcu/airecon

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

ai-securityeducationexploitation+6
1.1k27 days ago
ADRecon preview

ADRecon

GitHubadrecon/adrecon

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

defensive-toolsdigital-forensicsincident-response+6
9801 year ago
fridump preview

fridump

GitHubnightbringer21/fridump

Cross-platform memory dumper using Frida to extract accessible memory from iOS, Android, and Windows applications for forensic analysis and…

digital-forensicsforensicsinformation-gathering+3
8627 years ago
AndroTickler preview

AndroTickler

GitHubernw/androtickler

Penetration testing and auditing toolkit for Android apps.

android-securitydynamic-analysis-sandboxinginformation-gathering+4
2541 year ago
Afuzz preview

Afuzz

GitHubrapiddns/afuzz

Automated web path fuzzing tool that detects hidden directories, files, and endpoints using intelligent language detection, blacklist/whitelist…

fuzzinginformation-gatheringreconnaissance+2
3093 years ago
Wonka preview

Wonka

GitHubshac0x/wonka

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

authenticationinformation-gatheringpenetration-testing+3
1753 months ago
graphicator preview

graphicator

GitHubcybervelia/graphicator

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

api-security-testinginformation-gatheringpenetration-testing+1
1343 years ago
DNSrecon-gui preview

DNSrecon-gui

GitHubmicro-joan/dnsrecon-gui

Graphical DNS enumeration tool for Kali Linux that scans standard records (A, NS, SOA, MX) and visualizes results in mind maps for reconnaissance and…

dns-analysisdns-subdomain-enumerationinformation-gathering+2
633 years ago
abdal-cve-2026-63030 preview

abdal-cve-2026-63030

GitHubebrasha/abdal-cve-2026-63030

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

api-security-testinginformation-gatheringpenetration-testing+2
42 months ago
phpMyAdmin-CVE-2020-5504-Exploit preview

phpMyAdmin-CVE-2020-5504-Exploit

GitHubcerberusmrxi/phpmyadmin-cve-2020-5504-exploit

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

database-securityexploitationinformation-gathering+5
1 month ago
Previous12…24Next