Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
14 results
CredNinja preview

CredNinja

GitHubraikia/credninja

A multithreaded tool designed to identify if credentials are valid, invalid, or local admin valid credentials within a network at-scale via SMB, plus…

information-gatheringlateral-movementpenetration-testing
4484 years ago
SnaffPoint preview

SnaffPoint

GitHubnheiniger/snaffpoint

A tool for pointesters to find candies in SharePoint

cloud-securityinformation-gatheringpenetration-testing+3
2893 years ago
czds preview

czds

GitHubmsadministrator/czds

A Python package to download Zone Files from the Centralized Zone Data Service hosted by ICAAN.

crawlerdns-analysisinformation-gathering+2
171 year ago
ninja-forms-brute preview

ninja-forms-brute

GitHubrandomrobbiebf/ninja-forms-brute
information-gatheringvulnerability-analysisweb-application-exploitation
4 years ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubbarry-mccockiner/cve-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker…

exploitationinformation-gatheringpenetration-testing+3
17 years ago
ntlm_theft preview

ntlm_theft

GitHubgreenwolf/ntlm_theft

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

information-gatheringpassword-attackspenetration-testing+2
1.5k11 months ago
massdns preview

massdns

GitHubblechschmidt/massdns

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

dns-analysisdns-subdomain-enumerationinformation-gathering+2
3.6k4 months ago
React2Shell preview

React2Shell

GitHubmuhammaduwais/react2shell

A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications.

educationinformation-gatheringpenetration-testing+2
26 months ago
ghosthound preview

ghosthound

GitHubjvbotelho/ghosthound

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

exploitationinformation-gatheringlateral-movement+5
4313 days ago
ipChecker preview

ipChecker

GitHubmthbernardes/ipchecker

Check if a IP is from tor or is a malicious proxy

information-gatheringnetwork-securityosint+1
568 years ago
CVE-2023-49103 preview

CVE-2023-49103

GitHubd0rb/cve-2023-49103

This is a simple proof of concept for CVE-2023-49103.

exploitationinformation-gatheringpenetration-testing+2
2 years ago
bashacks preview

bashacks

GitHubmerces/bashacks

A set of functions to increase productivity while hacking with Bash

encryption-decryption-toolsgeneral-purpose-utilitieshash-analysis+3
2104 months ago
CWFF preview

CWFF

GitHubd4vinci/cwff

Create your Custom Wordlist For Fuzzing

fuzzinginformation-gatheringpenetration-testing+2
2041 year ago
CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH preview

CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH

GitHubs1d6point7bugcrowd/cve-2024-6387-race-condition-in-signal-handling-for-openssh
binary-exploitationeducationexploitation+3
2 years ago