Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
pentest-guide preview

pentest-guide

GitHubvoorivex/pentest-guide

Penetration tests guide based on OWASP including test cases, resources and examples.

authenticationcryptographyeducation+6
2.8k
5 years ago
janusec preview

janusec

GitHubjanusec/janusec

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

api-securityauthenticationcloud-security+8
1.2k1 month ago
clawpatrol preview

clawpatrol

GitHubdenoland/clawpatrol

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

api-securityapi-security-testingcloud-security+6
1.0k3 days ago
SCCMSecrets preview

SCCMSecrets

GitHubsynacktiv/sccmsecrets

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

authentication-authorizationexploitationinformation-gathering+5
2759 months ago
EvilMist preview

EvilMist

GitHublogisek/evilmist

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

authenticationcloud-securityidentity-access-management+7
1625 months ago
OAUTHScan preview

OAUTHScan

GitHubakabe1/oauthscan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

api-securityapi-security-testingauthentication-authorization+6
1781 year ago
backup_dc_registry preview

backup_dc_registry

GitHubhorizon3ai/backup_dc_registry

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

exploitationlateral-movementmisconfiguration+3
964 years ago
atproto preview

atproto

GitHubblacksky-algorithms/atproto

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

api-securityauthenticationcloud-infrastructure-security+6
9411h 21m ago
AD-description-password-finder preview

AD-description-password-finder

GitHubassurancemaladiesec/ad-description-password-finder

Retrieve AD accounts description and search for password in it

authenticationdefensive-toolsinformation-gathering+5
814 years ago
DNSint preview

DNSint

GitHubwho0xac/dnsint

DNSint - A comprehensive DNS reconnaissance and OSINT toolkit for domain intelligence gathering and security analysis.

dns-analysisdns-fuzzingemail-security+7
199 months ago
kcmapper preview

kcmapper

GitHubsynacktiv/kcmapper

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

authentication-authorizationconfiguration-auditingidentity-access-management+3
146 months ago
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
183 months ago
kong-pwn preview

kong-pwn

GitHubrandomrobbiebf/kong-pwn

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

api-securitycloud-securityexploitation+6
66 years ago
CVE-2019-19033 preview

CVE-2019-19033

GitHubricardojoserf/cve-2019-19033

CVE-2019-19033 description and scripts to check the vulnerability in Jalios JCMS 10 (Authentication Bypass)

authentication-authorizationexploitationinformation-gathering+4
36 years ago
DiffCatcher preview

DiffCatcher

GitHubteycir/diffcatcher

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

code-analysisdevsecopsinformation-gathering+7
44 months ago
clawdguard preview

clawdguard

GitHubfadidevv/clawdguard

🦞 Security hardening patch for Clawdbot/Moltbot. Detects and fixes exposed gateways automatically.

authenticationconfiguration-auditingdefensive-tools+3
26 months ago
domain-protect preview

domain-protect

GitHubovotech/domain-protect

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

cloud-securitymisconfigurationreconnaissance+1
33 years ago
CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026 preview

CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026

GitHub14mb1v45h/cyberdudebivash-mongodb-detector-v2026

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

database-securityexploitationinformation-gathering+3
7 months ago
Previous1234…13Next