Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
169 results
TendaSpill preview

TendaSpill

GitHubshaheemirza/tendaspill

An exploitation tool to extract passwords using CVE-2015-5995.

educationexploitationpassword-attacks+3
10
7 years ago
usernamer preview
Archived

usernamer

GitHubjseidl/usernamer

Pentest Tool to generate usernames/logins based on supplied names.

educationinformation-gatheringpassword-attacks+2
397 years ago
CVE-2017-7921 preview

CVE-2017-7921

GitHubmverschu/cve-2017-7921

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

authenticationexploitationinformation-gathering+5
6 months ago
RDWAtool preview

RDWAtool

GitHubp0dalirius/rdwatool

A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application

information-gatheringpassword-attacksreconnaissance+1
1228 months ago
wordpress-bf preview

wordpress-bf

GitHubrandomrobbiebf/wordpress-bf

Brute Force Wordpress Blogs.

authentication-authorizationinformation-gatheringpassword-attacks+2
6 years ago
wpbf preview

wpbf

GitHubatarantini/wpbf

Remotely test password strength of WordPress bloging software

information-gatheringpassword-attackspenetration-testing+3
10710 years ago
Tritium preview

Tritium

GitHubaahmad097/tritium

Kerberos-based password spraying framework for Active Directory with built-in lockout prevention, user enumeration integration, recursive password…

authenticationpassword-attackspenetration-testing
644 years ago
lama preview

lama

GitHubtatam/lama

Lama, the application that does not mache these words.

information-gatheringpassword-attackspassword-cracking
237 years ago
m33tfinder preview

m33tfinder

GitHubelevenpaths/m33tfinder

Detects vulnerable Cisco Meeting Server configurations (CVE-2018-15446) by enumerating active conference IDs and testing weak passcodes for…

educationpassword-attackspenetration-testing+2
57 years ago
nounours preview

nounours

GitHubsynacktiv/nounours

Nounours is a tool designed to test APP_KEYs at scale on Laravel applications.

cryptographyencryption-decryption-toolspassword-attacks+3
12 months ago
chiasmodon preview

chiasmodon

GitHubchiasmod0n/chiasmodon

Chiasmodon is an OSINT tool designed to assist in the process of gathering information about a target domain. Its primary functionality revolves…

dns-subdomain-enumerationemail-harvestinginformation-gathering+5
6981 year ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4101 year ago
XposedOrNot preview

XposedOrNot

GitHubviralmaniar/xposedornot

XposedOrNot (XoN) tool is to search an aggregated repository of xposed passwords comprising of ~850 million real time passwords. Usage of such…

information-gatheringosintpassword-attacks+3
1476 years ago
spraycharles preview

spraycharles

GitHubtw1sm/spraycharles

Low and slow password spraying tool, designed to spray on an interval over a long period of time

authenticationpassword-attackspassword-cracking+2
2247 months ago
Hawk preview

Hawk

GitHubprodefense/hawk

Golang tool designed to exfiltrate passwords found via the sshd and su services

data-exfiltrationinformation-gatheringpassword-attacks+3
389 months ago
SAPKiln preview

SAPKiln

GitHubowasp/sapkiln

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

configuration-auditinglateral-movementosint+3
303 years ago
FTPBuster preview

FTPBuster

GitLabs_r_e_e_r_a_j/ftpbuster

FTPBuster is a powerful command-line brute-forcing tool designed to brute-force FTP, SFTP, and explicit FTPS servers by performing dictionary-based…

information-gatheringpassword-attackspenetration-testing
14 months ago
ZipRarHunter preview

ZipRarHunter

GitLabs_r_e_e_r_a_j/ziprarhunter

ZipRarHunter is a powerful command-line ethical hacking tool designed to crack passwords of ZIP and RAR archive files using a wordlist.

password-attackspassword-crackingpenetration-testing+1
14 months ago
Previous1234…10Next