Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
SecLists preview

SecLists

GitHubdanielmiessler/seclists

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

ctfcurated-resourcesdns-fuzzing+11
73.8k
18h 6m ago
pentoo-overlay preview

pentoo-overlay

GitHubpentoo/pentoo-overlay

Gentoo overlay for security tools as well as the heart of the Pentoo Livecd

defensive-toolsexploit-frameworkshardware-security+7
3835 days ago
Aegis preview

Aegis

GitHubbeemdevelopment/aegis

A free, secure and open source app for Android to manage your 2-step verification tokens.

android-securityauthenticationauthentication-authorization+5
13.2k21 days ago
weakpass preview

weakpass

GitHubzzzteph/weakpass

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

hash-analysispassword-attackspassword-cracking+1
7381 month ago
nightcrawler preview

nightcrawler

GitHubgaragehq/nightcrawler

Local AI powered red teamer on a phone

ai-securitycommand-and-controlexploitation+7
8141 month ago
cupp preview

cupp

GitHubmebus/cupp

Interactive password profiler that generates targeted wordlists by gathering personal details about a user, used for penetration testing and forensic…

information-gatheringosintpassword-attacks+1
6.6k2 months ago
WP-Contest-Gallery-28.1.4-Exploit preview

WP-Contest-Gallery-28.1.4-Exploit

GitHubcerberusmrxi/wp-contest-gallery-28.1.4-exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

exploitationpassword-crackingpayload-development+4
12 months ago
JustTryHarder preview

JustTryHarder

GitHubsinfulz/justtryharder

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

educationexploitationpassword-cracking+7
8392 months ago
knowsmore preview

knowsmore

GitHubhelviojunior/knowsmore

Correlates NTLM hashes, BloodHound data, and cracked passwords for Active Directory penetration testing. Imports NTDS.dit, syncs to Neo4j, analyzes…

information-gatheringpassword-crackingpenetration-testing
2712 months ago
cve-2019-9053-py3 preview

cve-2019-9053-py3

GitHubvedantrana73/cve-2019-9053-py3

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.

educationexploitationpassword-cracking+3
3 months ago
rules preview

rules

GitHubibnaleem/rules

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

curated-resourcespassword-attackspassword-cracking+2
733 months ago
CVE-2025-4396 preview

CVE-2025-4396

GitHubsup3rdav3/cve-2025-4396

CVE-2025-4396 - WordPress Relevanssi Time-Based Blind SQL Injection

ctfeducationexploitation+5
4 months ago
ZipRarHunter preview

ZipRarHunter

GitLabs_r_e_e_r_a_j/ziprarhunter

ZipRarHunter is a powerful command-line ethical hacking tool designed to crack passwords of ZIP and RAR archive files using a wordlist.

password-attackspassword-crackingpenetration-testing+1
15 months ago
metasploitable2-vsftpd-exploitation preview

metasploitable2-vsftpd-exploitation

GitHubrinaliyeva/metasploitable2-vsftpd-exploitation

Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.

educationexploitationnetwork-mapping+7
5 months ago
AutoWIFI preview

AutoWIFI

GitHubmomenbasel/autowifi

Wireless penetration testing framework. Automates WPA/WPA2/WEP/WPS attacks - recon to exploitation in one command. aircrack-ng + hashcat + PMKID.

exploitationinformation-gatheringpassword-attacks+7
645 months ago
Moniker-Link-Lab-Setup preview

Moniker-Link-Lab-Setup

GitHube-m-e-k-a/moniker-link-lab-setup

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

authenticationeducationexploitation+6
6 months ago
Metasploitable2-VAPT-Report preview

Metasploitable2-VAPT-Report

GitHubklynezyro/metasploitable2-vapt-report

Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.

educationexploitationlabs-practice+8
8 months ago
Email-exploit-Moniker-Link-CVE-2024-21413- preview

Email-exploit-Moniker-Link-CVE-2024-21413-

GitHubyass2400012/email-exploit-moniker-link-cve-2024-21413-

Proof-of-concept exploit for CVE-2024-21413 using Moniker Link in HTML email to trigger SMB connection and capture netNTLMv2 hashes via Responder.…

educationemail-securityexploitation+6
1 year ago
Previous123Next