Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
91 results
hacktricks preview

hacktricks

GitHubhacktricks-wiki/hacktricks

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

ctfcurated-resourceseducation+11
12.2k9h 9m ago
SecLists preview

SecLists

GitHubdanielmiessler/seclists

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

ctfcurated-resourcesdns-fuzzing+11
73.2k21h 2m ago
telegram-phish-simulator preview

telegram-phish-simulator

GitHubmaty156/telegram-phish-simulator

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

educationinformation-gatheringlabs-practice+6
27 days ago
Hacking-Tools preview

Hacking-Tools

GitHubyogsec/hacking-tools

A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other…

educationexploitationforensics+9
1.9k8 days ago
fscan preview

fscan

GitHubshadow1ng/fscan

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

educationexploitationlateral-movement+9
14.5k8 days ago
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

container-escapectfcurated-resources+9
11 days ago
CVE-2024-28000-Exploit-Lab preview

CVE-2024-28000-Exploit-Lab

GitHubshawnng078-ops/cve-2024-28000-exploit-lab

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

educationexploitationlabs-practice+5
11 days ago
HIKRAVEN preview

HIKRAVEN

GitHubsylhetyhackvenger/hikraven

HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260…

exploitationinformation-gatheringiot-security+6
412 days ago
pentestcode preview

pentestcode

GitHubs0ld13rr/pentestcode

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

ai-securitycloud-securityctf+9
51413 days ago
CVE-2026-8793 preview

CVE-2026-8793

GitHubh4zaz/cve-2026-8793

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

authenticationeducationexploitation+4
19 days ago
ZeroLogon-PoC-DC-Pwn preview

ZeroLogon-PoC-DC-Pwn

GitHubmods20hh/zerologon-poc-dc-pwn

Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.

educationexploitationpapers-research+6
419 days ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
11.5k1 month ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

educationexploitationlabs-practice+5
1 month ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubdungsocool/cve-2026-8206

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

authenticationeducationexploitation+6
11 month ago
Netgrave preview

Netgrave

GitHubxewdy444/netgrave

A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)

educationexploitationinformation-gathering+5
71 month ago
CVE-2026-55579 preview

CVE-2026-55579

GitHubch4120n/cve-2026-55579

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

educationexploitationlabs-practice+6
11 month ago
Hack-The-Box-Enigma-Findings-Report preview

Hack-The-Box-Enigma-Findings-Report

GitHubmmoobbeeiidat-design/hack-the-box-enigma-findings-report

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager…

ctfeducationexploitation+8
1 month ago
CVE-2024-51482 preview

CVE-2024-51482

GitHubc0gnit00/cve-2024-51482

CVE-2025-51482 POC, Dump Credentials From zm.Users

educationexploitationinformation-gathering+4
1 month ago
Previous123456Next