Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
httpx preview

httpx

GitHubprojectdiscovery/httpx

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

api-securityapi-security-testingcrawler+18
10.3k
1 day ago
WhatWeb preview

WhatWeb

GitHuburbanadventurer/whatweb

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

crawlerdynamic-code-analysisinformation-gathering+9
6.8k4 months ago
firefox-devtools-mcp preview

firefox-devtools-mcp

GitHubmozilla/firefox-devtools-mcp

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

android-securityapi-security-testingdebuggers+7
3714 days ago
pwn-hisilicon-dvr preview

pwn-hisilicon-dvr

GitHubtothi/pwn-hisilicon-dvr

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

binary-analysisembedded-systems-securityexploitation+8
3833 years ago
mcpsnoop preview

mcpsnoop

GitHubkerlenton/mcpsnoop

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

api-security-testingdebuggersdynamic-analysis-sandboxing+5
3432 days ago
pentest-mcp preview

pentest-mcp

GitHubdmontgomery40/pentest-mcp

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

exploitationfuzzingnetwork-mapping+8
1425 months ago
INtrack preview

INtrack

GitHubk3ystr0k3r/intrack

A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.

crawlerexploitationinformation-gathering+7
6028 days ago
peeko preview

peeko

GitHubb3rito/peeko

XSS-based C2 that turns a victim's browser into a proxy for internal scanning, URL fetch, cookie theft, JS execution, and data exfiltration via…

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
Nmap-API preview

Nmap-API

GitHubmorpheuslord/nmap-api

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

api-security-testingnetwork-mappingosint+2
821 year ago
dahua-cve-research preview

dahua-cve-research

GitHubumair-aziz025/dahua-cve-research

Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

authenticationeducationexploitation+5
274 months ago
UltraViolet preview

UltraViolet

GitHubyakushstanislav/ultraviolet

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

dns-analysisincident-responseiot-security+6
444 days ago
Telerik_CVE-2019-18935 preview

Telerik_CVE-2019-18935

GitHubthanhuutuan/telerik_cve-2019-18935

Scans for Telerik UI RCE vulnerability (CVE-2019-18935) via Python and Nmap scripts, supporting IP, hostname, CIDR, and list targets.

exploitationnetwork-mappingpenetration-testing+3
123 years ago
CVE-2026-61511-PoC-Exploit preview

CVE-2026-61511-PoC-Exploit

GitHubtc4dy/cve-2026-61511-poc-exploit

Exploit toolkit for CVE-2026-61511 targeting vBulletin pre-auth RCE, featuring multi-endpoint exploitation, WAF bypass via PHPFuck, and…

database-securityexploitationnetwork-mapping+7
519 days ago
WebLogic-SSRF_CVE-2014-4210 preview

WebLogic-SSRF_CVE-2014-4210

GitHubnhpt/weblogic-ssrf_cve-2014-4210

Weblogic SearchPublicRegistries SSRF(CVE-2014-4210) Exploit Script based on Python3

exploitationnetwork-mappingport-scanning+3
115 years ago
JavaDeserialization preview

JavaDeserialization

GitHubetocheney/javadeserialization

Java deserialization vulnerability scanner targeting CVE-2017-10271 with nmap integration, multi-target port scanning, and customizable XML-based POC…

exploitationnetwork-mappingpayload-generation+3
97 years ago
CVE-2020-5902-NSE preview

CVE-2020-5902-NSE

GitHubrwincey/cve-2020-5902-nse

Nmap NSE script for detecting and exploiting CVE-2020-5902, a remote code execution vulnerability in F5 BIG-IP traffic management user interface.

exploitationnetwork-mappingpenetration-testing+2
86 years ago
CVE-2025-24132-Scanner preview

CVE-2025-24132-Scanner

GitHubferalthedogg/cve-2025-24132-scanner

mDNS-based AirPlay device discovery tool that scans local networks and tests for CVE-2025-24132 zero-click HTTP RCE vulnerability with a simple GUI…

exploitationinformation-gatheringnetwork-mapping+3
31 year ago
Multi-VLAN-Enterprise-Network-Vulnerability-Assessment preview

Multi-VLAN-Enterprise-Network-Vulnerability-Assessment

GitHubklairmanraj/multi-vlan-enterprise-network-vulnerability-assessment

Multi-VLAN enterprise network vulnerability assessment using Nessus, OWASP ZAP, and Wireshark. Confirms Stored XSS on WebGoat and EternalBlue…

exploitationnetwork-mappingnetwork-security+6
4 months ago
Previous12Next