Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
575 results
Bludit-3-9-2-bb preview

Bludit-3-9-2-bb

GitHublucareggiannini/bludit-3-9-2-bb

Bludit 3.9.2 - bruteforce bypass - CVE-2019-17240

exploitationpassword-attackspenetration-testing+2
6 years ago
CVE-2023-37073 preview

CVE-2023-37073

GitHubhamza0x/cve-2023-37073

Telnet default credentials can lead to information disclosure and denial-of-service (DoS) attacks.

exploitationhardware-iot-securityinformation-gathering+2
2 years ago
CVE-2024-41290 preview

CVE-2024-41290

GitHubparagbagul111/cve-2024-41290

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data

authenticationexploitationinformation-gathering+3
1 year ago
artemis2hashcat preview

artemis2hashcat

GitHubmbadanoiu/artemis2hashcat

Python3 implementation for converting Artemis PBKDF2WithHmacSHA1 hashes to hashcat format

hash-analysispassword-attackspassword-cracking
1 year ago
iberyanbytes preview

iberyanbytes

GitHubleviathanfromdeepsea/iberyanbytes

PowerShell-based Active Directory enumeration tool for gathering network configuration, domain objects, user sessions, share permissions, and…

information-gatheringpassword-attackspenetration-testing+2
2 years ago
gardyn preview

gardyn

GitHubmselbrede/gardyn

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

command-and-controlembedded-systems-securityexploitation+8
1 year ago
gMSA_Dumper preview

gMSA_Dumper

GitHubh3x0v3rl0rd/gmsa_dumper

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…

authenticationinformation-gatheringpassword-attacks+2
2 years ago
CVE-2023-32243-Detection-and-Mitigation-in-WordPress preview

CVE-2023-32243-Detection-and-Mitigation-in-WordPress

GitHubdev0558/cve-2023-32243-detection-and-mitigation-in-wordpress

Educational lab demonstrating detection and mitigation of CVE-2023-32243 privilege escalation in WordPress Essential Addons for Elementor, using…

educationexploitationlabs-practice+6
1 year ago
detect_bruteforce preview

detect_bruteforce

GitHubtieulong21prosper/detect_bruteforce

detect bruteforce using for cve-2021-34527

exploitationpassword-attackspenetration-testing+2
2 years ago
xmlrpc-brute preview

xmlrpc-brute

GitHubankhcorp/xmlrpc-brute

This tool tests WordPress installations for XML-RPC authentication vulnerabilities.

password-attackspenetration-testingvulnerability-analysis+1
1 year ago
wargame-turkey_in_2 preview

wargame-turkey_in_2

GitHubm0d0ri205/wargame-turkey_in_2

CTF wargame platform featuring Unicode bypass exploitation (CVE-2015-9238), flag file segmentation, brute force delay, and password hashing for…

ctfeducationlabs-practice+3
1 year ago
MSF_PassSpray_Wordlist_Generator preview

MSF_PassSpray_Wordlist_Generator

GitHubcyb3r-techie/msf_passspray_wordlist_generator

A handy tool that helps to create your own wordlist for Metasploit framework, in order to carry out a password spray attack against various network…

exploit-frameworkspassword-attackspenetration-testing+1
4 years ago
CVE-2023-32784-Exploitation preview

CVE-2023-32784-Exploitation

GitHubcmadhushanka/cve-2023-32784-exploitation

year 2 semester 1 Systems and Network Programming Assignment

educationexploitationpassword-attacks+2
2 years ago
CVE-2021-36460 preview

CVE-2021-36460

GitHubmartinfrancois/cve-2021-36460

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

authenticationexploitationmobile-security+2
24 days ago
qyvora-toha3ee preview

qyvora-toha3ee

GitHubqyvora/qyvora-toha3ee

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

exploitationnetwork-securityosint+9
311 days ago
SprayingToolkit preview
Archived

SprayingToolkit

GitHubbyt3bl33d3r/sprayingtoolkit

Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient

email-harvestinginformation-gatheringosint-social-engineering+4
1.6k3 years ago
CVE-2020-12712 preview

CVE-2020-12712

GitHub0xvedette/cve-2020-12712

Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

cryptographyexploitationpassword-attacks+2
6 years ago
bettercap preview
Archived

bettercap

GitHubevilsocket/bettercap

DEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap

dns-analysisnetwork-securitypacket-sniffing-analysis+3
2.5k8 years ago
Previous1…303132Next