Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
431 results
kerberoast preview

kerberoast

GitHubskelsec/kerberoast

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

authenticationexploitationinformation-gathering+2
434
2 years ago
CVE-2020-1472-visualizer preview

CVE-2020-1472-visualizer

GitHubtobey123/cve-2020-1472-visualizer

Visualization tool for CVE-2020-1472 (Zerologon) to identify and exploit vulnerable domain controllers in Active Directory environments.

exploitationinformation-gatheringpenetration-testing+2
6 years ago
otto-support preview

otto-support

GitHubbishopfox/otto-support

An implementation of a vulnerable MCP server using mcp-go

api-securityauthentication-authorizationctf+5
194 months ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
217 days ago
CVE-2017-5689-Checker preview

CVE-2017-5689-Checker

GitHubtheway-hue/cve-2017-5689-checker

Automated checker-exploit for CVE-2017-5689, scanning Intel AMT panels for authentication bypass and reporting vulnerable IPs.

authentication-authorizationexploitationinformation-gathering+3
5 years ago
CVE-2024-9106 preview

CVE-2024-9106

GitHubrandomrobbiebf/cve-2024-9106

Wechat Social login <= 1.3.0 - Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
11 year ago
CVE-2023-49547 preview

CVE-2023-49547

GitHubgeraldoalcantara/cve-2023-49547

Customer Support System 1.0 - SQL Injection Login Bypass

authentication-authorizationexploitationinformation-gathering+3
2 years ago
CVE-2023-4800 preview

CVE-2023-4800

GitHubb0marek/cve-2023-4800

Repository for CVE-2023-4800 vulnerability.

authentication-authorizationinformation-gatheringmisconfiguration+2
2 years ago
Memcrashed-DDoS-Exploit preview

Memcrashed-DDoS-Exploit

GitHub649/memcrashed-ddos-exploit

DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API

exploitationinformation-gatheringosint
1.4k6 years ago
Silver preview

Silver

GitHubs0md3v/silver

Mass scan IPs for vulnerable services

information-gatheringnetwork-securityreconnaissance+1
1.1k4 months ago
yasuo preview

yasuo

GitHub0xsauby/yasuo

A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network

exploitationinformation-gatheringpenetration-testing+2
5748 years ago
CVE-2024-6387_Check preview

CVE-2024-6387_Check

GitHubxaitax/cve-2024-6387_check

CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH

exploitationinformation-gatheringnetwork-security+3
5273 months ago
HostileSubBruteforcer preview

HostileSubBruteforcer

GitHubnahamsec/hostilesubbruteforcer

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

cloud-securitydns-subdomain-enumerationinformation-gathering+3
4829 years ago
dnstake preview

dnstake

GitHubpwnesia/dnstake

Fast DNS takeover scanner that checks for missing hosted zones by querying nameservers and fingerprinting providers to identify vulnerable subdomains.

dns-analysisinformation-gatheringsubdomain-enumeration+1
8564 years ago
DorkNet preview

DorkNet

GitHubnullarray/dorknet

Selenium powered Python script to automate searching for vulnerable web apps.

information-gatheringosintvulnerability-scanners+1
3486 years ago
dorkScanner preview

dorkScanner

GitHubmadhavmehndiratta/dorkscanner

A typical search engine dork scanner scrapes search engines with dorks that you provide in order to find vulnerable URLs.

information-gatheringosintvulnerability-scanners+1
2863 years ago
php_filter_chains_oracle_exploit preview

php_filter_chains_oracle_exploit

GitHubsynacktiv/php_filter_chains_oracle_exploit

A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.

exploitationinformation-gatheringpenetration-testing+2
3342 years ago
AdbNet preview

AdbNet

GitHub0x1ca3/adbnet

A tool that allows you to search for vulnerable android devices across the world and exploit them.

android-securityexploitationinformation-gathering+4
4344 years ago
Previous12…24Next