Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
even-you-brutus preview

even-you-brutus

GitHubj-baines/even-you-brutus

Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

authenticationembedded-systems-securityexploitation+5
9
3 years ago
custom-oscp-tooling preview

custom-oscp-tooling

GitLabwattocyber/custom-oscp-tooling

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

database-securitydns-analysishash-analysis+9
1 month ago
SharpNTLMRawUnHide preview

SharpNTLMRawUnHide

GitHubx-c3ll/sharpntlmrawunhide

C# version of NTLMRawUnHide

hash-analysisnetwork-securitypacket-sniffing-analysis+2
724 years ago
mtpass preview

mtpass

GitHubmanio/mtpass

MikroTik Password Recovery Tool

network-securitypassword-attackspassword-cracking+1
2912 years ago
cisco-SNMP-enumeration preview

cisco-SNMP-enumeration

GitHubnccgroup/cisco-snmp-enumeration

Automated Cisco SNMP Enumeration, Brute Force, Configuration Download and Password Cracking

configuration-auditinginformation-gatheringnetwork-security+3
22610 years ago
Massive-Subdomain-Enumerator preview

Massive-Subdomain-Enumerator

GitHubjenderal92/massive-subdomain-enumerator

This tool uses a combination of dictionary-based wordlists (brute-force) and DNS resolution checks to verify the existence of subdomains.

dns-analysisdns-subdomain-enumerationinformation-gathering+2
4 months ago
patator preview

patator

GitHublanjelot/patator

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

authenticationdns-analysishash-analysis+6
3.9k1 year ago
ridenum preview

ridenum

GitHubtrustedsec/ridenum

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

authenticationinformation-gatheringnetwork-security+3
3176 years ago
CVE-2024-21754-Forti-RCE preview

CVE-2024-21754-Forti-RCE

GitHubcybersecuritist/cve-2024-21754-forti-rce

Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

exploitationnetwork-securitypassword-cracking+2
22 years ago
SSHUsernameBruter-SSHUB preview

SSHUsernameBruter-SSHUB

GitHubjoeblacksecurity/sshusernamebruter-sshub

Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

exploitationnetwork-securitypassword-attacks+2
27 years ago
siem-threat-detection-lab preview

siem-threat-detection-lab

GitHubsarjanpatel22/siem-threat-detection-lab

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

defensive-toolseducationincident-response+6
3 months ago
py-network-scanner preview

py-network-scanner

GitHubanonymous121029034720384234234/py-network-scanner

Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and…

educationexploitationids-ips-evasion+6
11 year ago
cve-2026-8697 preview

cve-2026-8697

GitHubitzmetanjim/cve-2026-8697

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

educationexploitationhardware-iot-security+7
14 months ago
network-security-snort preview

network-security-snort

GitHubtaisa456/network-security-snort

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

defensive-toolseducationexploitation+6
4 months ago
Krb5RoastParser preview

Krb5RoastParser

GitHubjalvarezz13/krb5roastparser

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

authenticationhash-analysisnetwork-security+3
1151 month ago
brutus preview

brutus

GitHubpraetorian-inc/brutus

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

authenticationexploitationinformation-gathering+7
3274 days ago
ncrack preview

ncrack

GitHubnmap/ncrack

Ncrack network authentication tool

authenticationhash-analysisnetwork-security+3
1.2k4 years ago
SNMP-Brute preview

SNMP-Brute

GitHubsecforce/snmp-brute

Fast SNMP brute force, enumeration, CISCO config downloader and password cracking script.

configuration-auditinginformation-gatheringnetwork-security+1
3345 years ago
Previous12Next