Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
CVE-2023-36884-Checker preview

CVE-2023-36884-Checker

GitHubtarraschk/cve-2023-36884-checker

Script to check for CVE-2023-36884 hardening

configuration-auditingmisconfigurationscripting-automation+1
15
3 years ago
CVE-2022-30190-Follina-Patch preview

CVE-2022-30190-Follina-Patch

GitHubsuenerve/cve-2022-30190-follina-patch

The CVE-2022-30190-follina Workarounds Patch

configuration-auditingexploitationincident-response+2
24 years ago
Windows-Local-Privilege-Escalation-Cookbook preview

Windows-Local-Privilege-Escalation-Cookbook

GitHubnickvourd/windows-local-privilege-escalation-cookbook

Windows Local Privilege Escalation Cookbook

configuration-auditingeducationexploitation+9
1.4k6 months ago
Misconfiguration-Manager preview

Misconfiguration-Manager

GitHubsubat0mik/misconfiguration-manager

Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening…

configuration-auditingcurated-resourcesdefensive-tools+7
1.2k5 days ago
hardentools preview

hardentools

GitHubhardentools/hardentools

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.

configuration-auditingdefensive-toolsmisconfiguration
3.1k1 year ago
monkey365 preview

monkey365

GitHubsilverhack/monkey365

PowerShell-based security assessment framework for Microsoft 365, Azure, and Entra ID. Scans for misconfigurations, CIS benchmark compliance, and…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+2
1.3k27 days ago
EntraGoat preview

EntraGoat

GitHubsemperis/entragoat

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

authenticationcloud-securityctf+7
9793 months ago
EntraFalcon preview

EntraFalcon

GitHubcompasssecurity/entrafalcon

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

cloud-securityidentity-access-managementinformation-gathering+3
5019 days ago
defender-privilege-escalation-scanner preview

defender-privilege-escalation-scanner

GitHubridhinva/defender-privilege-escalation-scanner

Scanner: CVE-2026-41091/45498 Microsoft Defender LPE/DoS — Python scanner for Windows Defender privilege escalation (CISA KEV)

configuration-auditingdefensive-toolsmisconfiguration+3
26 days ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubim007/cve-2023-23397

PowerShell script to detect and remediate CVE-2023-23397 privilege escalation vulnerability in Microsoft Outlook and Exchange environments.

cloud-securityconfiguration-auditingemail-security+3
3 years ago
Disable-IPv6-CVE-2024-38063-Fix preview

Disable-IPv6-CVE-2024-38063-Fix

GitHubalmogopp/disable-ipv6-cve-2024-38063-fix

A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the…

defensive-toolsgeneral-purpose-utilitiesmisconfiguration+2
2 years ago
Serious-Sam---CVE-2021-36934-Mitigation-for-Datto-RMM preview

Serious-Sam---CVE-2021-36934-Mitigation-for-Datto-RMM

GitHubjmaddington/serious-sam---cve-2021-36934-mitigation-for-datto-rmm

PowerShell script to apply Microsoft and US CERT mitigation measures for CVE-2021-36934 (Serious SAM) via Datto RMM, with UDF-based status tracking.

configuration-auditingeducationmisconfiguration+2
5 years ago
Disable-Spooler-Service-PrintNightmare-CVE-2021-34527 preview

Disable-Spooler-Service-PrintNightmare-CVE-2021-34527

GitHubvinaysudheer/disable-spooler-service-printnightmare-cve-2021-34527

Simple batch script to disable the Microsoft Print Spooler service from system

defensive-toolsexploitationmisconfiguration+1
5 years ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubdroidrzrlover/cve-2022-30190

Patch for CVE-2022-30190 vulnerability. Provides mitigation steps and detection logic for the Microsoft Support Diagnostic Tool (MSDT) remote code…

code-analysisexploitationmisconfiguration+2
4 years ago
ScubaGear preview

ScubaGear

GitHubcisagov/scubagear

Automation to assess the state of your M365 tenant against CISA's baselines

cloud-securityconfiguration-auditingdefensive-tools+3
2.7k6 days ago
power-pwn preview

power-pwn

GitHubmbrg/power-pwn

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

ai-securitycloud-securityinformation-gathering+8
1.2k8 months ago
sccm-http-looter preview

sccm-http-looter

GitHubbadsectorlabs/sccm-http-looter

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

data-exfiltrationinformation-gatheringmisconfiguration+3
2161 year ago
KINGSOFT-WPS-Office-LPE preview

KINGSOFT-WPS-Office-LPE

GitHubhadimed/kingsoft-wps-office-lpe

CVE-2022-25943

binary-exploitationexploitationlateral-movement+4
584 years ago
Previous12Next