Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
569 results
nmap-nse-scripts preview

nmap-nse-scripts

GitHubcldrn/nmap-nse-scripts

My collection of nmap NSE scripts

curated-resourceseducationinformation-gathering+5
9949 days ago
wifi-bruteforcer-fsecurify preview

wifi-bruteforcer-fsecurify

GitHubfaizann24/wifi-bruteforcer-fsecurify

Android application to brute force WiFi passwords without requiring a rooted device.

android-securitymobile-securitypassword-attacks+1
1.5k7 years ago
KitHack preview

KitHack

GitHubadrmxr/kithack

Hacking tools pack & backdoors generator.

android-securityexploit-frameworksinformation-gathering+6
2.1k1 year ago
Lockdoor-Framework preview

Lockdoor-Framework

GitHubsofianehamlaoui/lockdoor-framework

🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources

educationexploitationinformation-gathering+6
1.6k1 year ago
turkce-wordlist preview

turkce-wordlist

GitHubutkusen/turkce-wordlist

Türk kullanıcıların parola seçimlerinin analizi için yapılmış bir çalışmadır

educationpapers-researchpassword-attacks+1
8593 years ago
Steghide-Brute-Force-Tool preview

Steghide-Brute-Force-Tool

GitHubva5c0/steghide-brute-force-tool

Execute a brute force attack with Steghide to file with hide information and password established

password-attackspenetration-testingsteganography
1239 years ago
DracOS preview

DracOS

GitHubscreetsec/dracos

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

educationexploitationforensics+8
589 years ago
PasswordFilter preview

PasswordFilter

GitHub3gstudent/passwordfilter

2 ways of Password Filter DLL to record the plaintext password

password-attackspenetration-testing
655 years ago
jmxbf preview

jmxbf

GitHubnccgroup/jmxbf

A brute force program to test weak accounts configured to access a JMX Registry

authenticationpassword-attackspenetration-testing
359 years ago
CVE-2025-2304 preview

CVE-2025-2304

GitHubalien0ne/cve-2025-2304

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

educationexploitationpassword-attacks+4
188 months ago
CVE-2024-1698-Exploit preview

CVE-2024-1698-Exploit

GitHubkamranhasan/cve-2024-1698-exploit

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

educationexploitationpassword-attacks+3
82 years ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
24 days ago
CVE-2024-51482 preview

CVE-2024-51482

GitHubbridgeralderson/cve-2024-51482

ZenoMinder Blind SQL Injection PoC

database-securityeducationexploitation+4
97 months ago
CVE-2024-28000-Exploit-Lab preview

CVE-2024-28000-Exploit-Lab

GitHubshawnng078-ops/cve-2024-28000-exploit-lab

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

educationexploitationlabs-practice+5
1 month ago
Hack-The-Box-Enigma-Findings-Report preview

Hack-The-Box-Enigma-Findings-Report

GitHubmmoobbeeiidat-design/hack-the-box-enigma-findings-report

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager…

ctfeducationexploitation+8
2 months ago
SAP-brute preview

SAP-brute

GitHubrandomrobbiebf/sap-brute

SAP Netweaver Login Bruteforcer.

authenticationpassword-attackspenetration-testing+2
25 years ago
CVE-2026-55579 preview

CVE-2026-55579

GitHubch4120n/cve-2026-55579

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

educationexploitationlabs-practice+6
12 months ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubdungsocool/cve-2026-8206

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

authenticationeducationexploitation+6
12 months ago
Previous1…303132Next