Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
261 results
VeilTransfer preview

VeilTransfer

GitHubinfosecn1nja/veiltransfer

VeilTransfer is a data exfiltration utility designed to test and enhance the detection capabilities. This tool simulates real-world data exfiltration…

data-exfiltrationnetwork-securitypenetration-testing+1
1598 months ago
fortigate-belsen-leak preview

fortigate-belsen-leak

GitHubarsolutioner/fortigate-belsen-leak

Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group

educationincident-responseinformation-gathering+3
871 year ago
nmap-log4shell preview

nmap-log4shell

GitHubgiterlizzi/nmap-log4shell

Nmap NSE script for detecting Apache Log4j RCE (CVE-2021-44228) by injecting JNDI exploit payloads via HTTP headers or TCP/UDP sockets across…

exploitationnetwork-securitypayload-generation+4
794 years ago
OpenClawMachines preview

OpenClawMachines

GitHubmathaix/openclawmachines

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

ai-securityauthenticationcloud-security+6
571 month ago
threat-finder preview

threat-finder

GitHuboffseq/threat-finder

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

devsecopsnetwork-securitythreat-intelligence+2
5811 days ago
NoPacScan preview

NoPacScan

GitHubknightswd/nopacscan

Scans Active Directory domain controllers for CVE-2021-42287 and CVE-2021-42278 by querying DNS for all DCs and analyzing PAC structures for the 0x10…

authenticationexploitationnetwork-security+2
874 years ago
urgent11-detector preview

urgent11-detector

GitHubarmissecurity/urgent11-detector

URGENT/11 detection tool by Armis

embedded-systems-securityinformation-gatheringiot-security+5
646 years ago
zscan preview

zscan

GitHubzcyberseclab/zscan

A fast, customizable service detection tool powered by a flexible fingerprint system. It helps you identify services, APIs, and network…

network-securitypenetration-testingport-scanning+3
452 months ago
CVE-2023-20198-Scanner preview

CVE-2023-20198-Scanner

GitHubshadow0ps/cve-2023-20198-scanner

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273

exploitationinformation-gatheringioc-management+3
332 years ago
abdal-anydesk-remote-ip-detector preview

abdal-anydesk-remote-ip-detector

GitHubebrasha/abdal-anydesk-remote-ip-detector

CVE-2024-52940 - A zero-day vulnerability in AnyDesk's "Allow Direct Connections" feature, discovered and registered by Ebrahim Shafiei (EbraSha),…

exploitationinformation-gatheringnetwork-security+3
361 year ago
killasa preview

killasa

GitHubjgajek/killasa

Exploit tool for CVE-2016-1287 that tests Cisco ASA devices by sending crafted IKEv2 fragments with invalid lengths to trigger denial of service.

exploitationfuzzingnetwork-security+2
1610 years ago
Antignis preview

Antignis

GitHubhuntandhackett/antignis

Automates Windows host-based firewall management by importing network data into a central database, creating Active Directory groups, and generating…

configuration-auditingdefensive-toolsnetwork-access-control+1
433 years ago
DNSnitch preview

DNSnitch

GitHublele394/dnsnitch

DNSnitch is a local, privacy-first DNS server that puts you in complete control of your network traffic. Unlike passive blocklists, DNSnitch operates…

defensive-toolsdns-analysisdns-fuzzing+3
239 months ago
CVE-2024-38063 preview

CVE-2024-38063

GitHubpatchpoint/cve-2024-38063

Proof-of-concept exploit for CVE-2024-38063, a Windows TCP/IP remote code execution vulnerability triggered by sending two crafted IPv6 packets with…

binary-exploitationexploitationnetwork-security+3
202 years ago
CVE-2024-38063 preview

CVE-2024-38063

GitHubdiegoalbuquerque/cve-2024-38063

mitigation script by disabling ipv6 of all interfaces

general-purpose-utilitiesmisconfigurationnetwork-security+2
132 years ago
CVE-2018-10933 preview

CVE-2018-10933

GitHubkn6869610/cve-2018-10933

Leveraging it is a simple matter of presenting the server with the SSH2_MSG_USERAUTH_SUCCESS message, which shows that the login already occurred…

authenticationexploitationnetwork-security+2
147 years ago
CVE-2023-48795 preview

CVE-2023-48795

GitHubtrixsec/cve-2023-48795

A Python-based tool to check for vulnerabilities in OpenSSH installations on local or remote systems by scanning specific IPs. It checks if the…

information-gatheringnetwork-securitypenetration-testing+3
131 year ago
Etern-blue-Windows-7-Checker preview

Etern-blue-Windows-7-Checker

GitHubnatteesetobol/etern-blue-windows-7-checker

EternalBlue is a well-known SMB exploit created by the NSA to attack various versions of Windows, including Windows 7. Etern-Blue-Windows-7-Checker…

exploitationinformation-gatheringnetwork-security+3
76 months ago
Previous1…345…15Next