Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
117 results
SharpSploit preview

SharpSploit

GitHubcobbr/sharpsploit

SharpSploit is a .NET post-exploitation library written in C#

command-and-controlexploitationinformation-gathering+9
1.9k5 years ago
WPCracker preview

WPCracker

GitHubjonirinta-kahila/wpcracker

WordPress pentest tool

information-gatheringpassword-attackspenetration-testing+1
425 years ago
RunAs-Stealer preview

RunAs-Stealer

GitHubdarkspacesecurity/runas-stealer

RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging

adversarial-attackpassword-attackspost-exploitation+1
2081 year ago
iDict preview

iDict

GitHubpr0x13/idict

PHP-based iCloud Apple ID dictionary attack tool that bypasses account lockout and secondary authentication to brute-force credentials.

authenticationexploitationpassword-attacks+3
9023 years ago
t14m4t preview

t14m4t

GitHubms-web-bn/t14m4t

Automated brute-forcing attack tool.

network-securitypassword-attackspenetration-testing
4235 years ago
smbexec preview

smbexec

GitHubbrav0hax/smbexec

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

command-and-controlexploitationlateral-movement+6
26211 years ago
Steghide-Brute-Force-Tool preview

Steghide-Brute-Force-Tool

GitHubva5c0/steghide-brute-force-tool

Execute a brute force attack with Steghide to file with hide information and password established

password-attackspenetration-testingsteganography
1239 years ago
pydictor preview

pydictor

GitHublandgrey/pydictor

A powerful and useful hacker dictionary builder for a brute-force attack

password-attackspassword-crackingsocial-engineering
3.7k1 year ago
2FA-Bypass-using-a-Brute-Force-Attack-CVE-2025-60424 preview

2FA-Bypass-using-a-Brute-Force-Attack-CVE-2025-60424

GitHubaakashtyal/2fa-bypass-using-a-brute-force-attack-cve-2025-60424

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

authenticationexploitationpassword-attacks+3
111 months ago
SocialBox preview

SocialBox

GitHubcyb0r9/socialbox

Brute-force attack framework targeting social media platforms (Facebook, Gmail, Instagram, Twitter) with automated credential testing and account…

information-gatheringpassword-attackssocial-engineering
2.1k7 years ago
CVE-2026-23005-Matter-Commissioning-Code-Brute-Force-Without-Rate-Limit preview

CVE-2026-23005-Matter-Commissioning-Code-Brute-Force-Without-Rate-Limit

GitHubgeorge0papasotiriou/cve-2026-23005-matter-commissioning-code-brute-force-without-rate-limit

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…

embedded-systems-securityexploitationiot-security+2
1 month ago
reaver-wps-fork-t6x preview

reaver-wps-fork-t6x

GitHubt6x/reaver-wps-fork-t6x

Brute-force attack tool against WPS registrar PINs to recover WPA/WPA2 passphrases, supporting online brute force and offline Pixie Dust attacks on…

exploitationpassword-attackswi-fi-auditing+1
2.0k10 months ago
hashcat preview

hashcat

GitHubhashcat/hashcat

World's fastest and most advanced password recovery utility

cryptographyencryption-decryption-toolshash-analysis+2
26.9k10h 28m ago
Internal-Monologue preview

Internal-Monologue

GitHubeladshamir/internal-monologue

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

lateral-movementpassword-attackspenetration-testing+2
1.7k7 years ago
dymerge preview

dymerge

GitHubk4m4/dymerge

🔓 A dynamic dictionary merger for successful dictionary based attacks.

password-attackspassword-crackingutilities-frameworks
2288 years ago
RedLogin preview

RedLogin

GitHubparsingteam/redlogin

Red Login: SSH Brute-force Tools

password-attackspenetration-testing
1058 years ago
AutoWIFI preview

AutoWIFI

GitHubmomenbasel/autowifi

Wireless penetration testing framework. Automates WPA/WPA2/WEP/WPS attacks - recon to exploitation in one command. aircrack-ng + hashcat + PMKID.

exploitationinformation-gatheringpassword-attacks+7
635 months ago
joombrute preview

joombrute

GitHubrvzsec/joombrute

Modern Joomla Auth-attack Toolkit J3 / J4 / J5 - CVE-2023-23752 · CVE-2023-23755 · CVE-2025-25227

exploitationinformation-gatheringpassword-attacks+3
13 months ago
Previous1234567Next