Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
379 results
EntraFalcon preview

EntraFalcon

GitHubcompasssecurity/entrafalcon

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

cloud-securityidentity-access-managementinformation-gathering+3
503
13 days ago
hackbox preview

hackbox

GitHubsamhaxr/hackbox

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

information-gatheringmisconfigurationpenetration-testing+5
4193 years ago
eos preview

eos

GitHubsynacktiv/eos

Enemies Of Symfony - Debug mode Symfony looter

information-gatheringmisconfigurationpenetration-testing+3
3621 year ago
of-CORS preview

of-CORS

GitHubtrufflesecurity/of-cors

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

information-gatheringmisconfigurationphishing+3
1553 years ago
flumberboozle preview

flumberboozle

GitHubfellchase/flumberboozle

Suite of programs meant to aid in bug hunting and security assessments

cloud-securityinformation-gatheringmisconfiguration+3
776 years ago
s3reverse preview

s3reverse

GitHubhahwul/s3reverse

The format of various s3 buckets is convert in one format. for bugbounty and security testing.

cloud-securityinformation-gatheringmisconfiguration+1
913 years ago
agentsid-scanner preview

agentsid-scanner

GitHubagentsid-dev/agentsid-scanner

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

ai-securityapi-security-testingauthentication+7
254 months ago
CVE-2023-34965 preview

CVE-2023-34965

GitHubagenty0/cve-2023-34965

SSPanel UIM is a multi-purpose agency service sales management system specially designed for Shadowsocks / V2Ray / Trojan protocols. SSPanel-Uim…

information-gatheringmisconfigurationpenetration-testing+2
33 years ago
CVE-2020-24029 preview

CVE-2020-24029

GitHubredteambrasil/cve-2020-24029

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

authenticationexploitationinformation-gathering+4
1 month ago
CVE-2020-36287 preview

CVE-2020-36287

GitHubf4rber/cve-2020-36287

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from…

exploitationinformation-gatheringmisconfiguration+3
35 years ago
CVE-2023-23138 preview

CVE-2023-23138

GitHubomaratallahh/cve-2023-23138

short view of ruby on rails properties misconfiguration

information-gatheringmisconfigurationpenetration-testing+2
23 years ago
CVE-2026-31156 preview

CVE-2026-31156

GitHubunicorn-hyh/cve-2026-31156

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

code-analysisexploitationinformation-gathering+3
3 months ago
CVE-2025-34171 preview

CVE-2025-34171

GitHubeyodav/cve-2025-34171

CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

exploitationinformation-gatheringmisconfiguration+3
8 months ago
coolermaster-masterctrl-vuln preview

coolermaster-masterctrl-vuln

GitHubarbatinis1/coolermaster-masterctrl-vuln

CVE-2025-52216 – Cooler Master MasterCTRL Silent Installation of Insecure Services

exploitationmisconfigurationprivilege-escalation+1
1 year ago
xpl-ModernWMS-CVE-2024-57698 preview

xpl-ModernWMS-CVE-2024-57698

GitHubrodolfomarianocy/xpl-modernwms-cve-2024-57698

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

exploitationinformation-gatheringmisconfiguration+3
1 year ago
Digisol-DG--GR1321-s-Password-Storage-in-Plaintext--CVE-2024-4232 preview

Digisol-DG--GR1321-s-Password-Storage-in-Plaintext--CVE-2024-4232

GitHubredfox-security/digisol-dg--gr1321-s-password-storage-in-plaintext--cve-2024-4232

Proof-of-concept exploit for CVE-2024-4232 targeting plaintext password storage in Digisol DG-GR1321 routers. Demonstrates extraction of credentials…

exploitationiot-securitymisconfiguration+3
2 years ago
tfsec preview

tfsec

GitHubaquasecurity/tfsec

Tfsec is now part of Trivy

cloud-securitycode-analysisdevsecops+3
7.0k5 months ago
ScubaGear preview

ScubaGear

GitHubcisagov/scubagear

Automation to assess the state of your M365 tenant against CISA's baselines

cloud-securityconfiguration-auditingdefensive-tools+3
2.7k3 days ago
Previous1…456…22Next