Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
49 results
fail2ban preview

fail2ban

GitHubfail2ban/fail2ban

Daemon to ban hosts that cause multiple authentication errors

defensive-toolsintrusion-detectionlog-analysis+1
18.4k0 days ago
sshroute preview

sshroute

GitHubthereisnotime/sshroute

Network-aware SSH router - routes connections to different IPs/ports/keys/jump hosts based on active VPN or network

general-purpose-utilitiesnetwork-securityscripting-automation+1
201 day ago
phantomprint preview

phantomprint

GitHubharuu77g/phantomprint

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

digital-forensicsinformation-gatheringnetwork-mapping+7
44 days ago
DHCPig preview

DHCPig

GitHubkamorin/dhcpig

DHCP exhaustion script written in python using scapy network library

exploitationfuzzingnetwork-security+3
35411 days ago
cyanide preview

cyanide

GitHubhorizon3ai/cyanide
exploitationinformation-gatheringlateral-movement+6
1616 days ago
sshfinder preview

sshfinder

GitHubkabiri-labs/sshfinder

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

cryptographyinformation-gatheringnetwork-security+5
321 days ago
kestrel preview

kestrel

GitHub1-bit-wonder/kestrel

Single-host runtime-security dashboard on eBPF — Go agent + SvelteKit. Live process tree, network map, and rule-based alerts for plain Linux hosts.

anomaly-detectiondefensive-toolsintrusion-detection+2
29 days ago
netfence preview

netfence

GitHubdanthegoodman1/netfence

Like Envoy xDS, but for eBPF filters

cloud-infrastructure-securitycloud-securitycontainer-security+5
1011 month ago
smbghost preview

smbghost

GitHubp4ncontomat3/smbghost

scanner for CVE-2020-0796

exploitationnetwork-securitypenetration-testing+2
1 month ago
enum4linux preview

enum4linux

GitHubciscocxsecurity/enum4linux

enum4Linux is a Linux alternative to enum.exe for enumerating data from Windows and Samba hosts

information-gatheringnetwork-securityosint+2
1.4k2 months ago
copyfailscan preview

copyfailscan

GitHubmonobrau/copyfailscan

SSH posture helper for CVE-2026-31431 (Copy Fail): kernel and algif_aead inventory

information-gatheringnetwork-securitypenetration-testing+3
2 months ago
FencePost preview

FencePost

GitHubseriocomic/fencepost

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

cloud-securityconfiguration-auditingcontainer-security+6
24 months ago
watchtowr-vs-telnetd-CVE-2026-32746 preview

watchtowr-vs-telnetd-CVE-2026-32746

GitHubwatchtowrlabs/watchtowr-vs-telnetd-cve-2026-32746

Detection script for telnetd CVE-2026-32746 that probes remote hosts to identify vulnerable LINEMODE support via TCP connection, generating detection…

network-securitypenetration-testingreconnaissance+2
115 months ago
sshconfig-lint preview

sshconfig-lint

GitHubnoah4ever/sshconfig-lint

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

code-analysisconfiguration-auditingdevsecops+3
165 months ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
7 months ago
smbcrawler preview

smbcrawler

GitHubsyss-research/smbcrawler

smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares

data-exfiltrationinformation-gatheringnetwork-security+3
1899 months ago
gssapi-abuse preview

gssapi-abuse

GitHubccob/gssapi-abuse

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

authenticationdns-analysisinformation-gathering+5
1881 year ago
ipeeyoupeewepee preview

ipeeyoupeewepee

GitHubpapayajackal/ipeeyoupeewepee

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

dns-analysiseducationexploitation+4
111 year ago
Previous123Next