Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
4900 results
ad_attack_architecture preview

ad_attack_architecture

GitHubkypvas/ad_attack_architecture

Active Directory Attack Architecture Map Comprehensive Pentest Reference — From Recon to Domain Dominance

curated-resourceseducationidentity-management+7
36
1 month ago
red-team-map preview

red-team-map

GitHubkypvas/red-team-map

Red Team Operations Architecture Map Comprehensive Operator Reference — From Infrastructure to Impact

command-and-controlcurated-resourceseducation+7
3024 days ago
phantom-grid preview

phantom-grid

GitHubevkir/phantom-grid

Free Burp Collaborator alternative- OOB interaction capture (HTTP/HTTPS/DNS) with SQLite & exfil reassembly

data-exfiltrationdns-analysisinformation-gathering+7
11 month ago
tanuki preview

tanuki

GitHubmafifrizi/tanuki

Tactical Identity Operator for Linux & Hybrid Active Directory

ai-securityauthenticationdefensive-tools+6
152 days ago
EBurst preview

EBurst

GitHubgrayddq/eburst

这个脚本主要提供对Exchange邮件服务器的账户爆破功能,集成了现有主流接口的爆破方式。

authenticationemail-securityinformation-gathering+4
3433 years ago
cyclepatrol preview

cyclepatrol

GitHubbuybitart/cyclepatrol

Bash tool for on-foot Wi-Fi security checks in a loop, with evidence reports.

defensive-toolshash-analysisinformation-gathering+8
42 days ago
dddd preview

dddd

GitHubsleepingbag945/dddd

Batch asset collection and vulnerability scanning tool for red teams. Pulls targets from Hunter, Fofa, and Quake, performs fingerprinting, subdomain…

fingerprint-spoofinginformation-gatheringnetwork-mapping+9
1.9k2 years ago
Get-NetNTLM preview

Get-NetNTLM

GitHubelnerd/get-netntlm

Powershell module to get the NetNTLMv2 hash of the current user

hash-analysisinformation-gatheringpassword-attacks+4
974 years ago
blackbox-pentesting-infsecos preview

blackbox-pentesting-infsecos

GitHubsaqibnet/blackbox-pentesting-infsecos

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

ctfeducationexploitation+9
5 months ago
Cyber-Library preview

Cyber-Library

GitHubcyber-courses/cyber-library

Community-maintained Markdown knowledge base covering cybersecurity foundations, offensive and defensive practice, governance, threat intelligence,…

curated-resourcesdefensive-toolseducation+7
852 days ago
watchTowr-vs-Atlassian-CVE-2026-21589 preview

watchTowr-vs-Atlassian-CVE-2026-21589

GitHubwatchtowrlabs/watchtowr-vs-atlassian-cve-2026-21589

Python detection artifact that checks Atlassian Jira, Confluence, and Bitbucket instances for the CVE-2026-21589 arbitrary file read vulnerability.

exploitationinformation-gatheringpapers-research+5
54 days ago
GoFileX preview

GoFileX

GitHubabraxas/gofilex

Wordlist Bruteforcer for GoFile (gofile.io) Download Passwords

ctfinformation-gatheringpassword-attacks+5
1 month ago
caeruleus preview

caeruleus

GitHubpraetorian-inc/caeruleus

Single Go binary for Bluetooth Low Energy security testing on Linux/BlueZ: scan, enumerate GATT, read/write/notify, fuzz characteristics, and run…

bluetooth-securityfuzzinghardware-iot-security+8
5610 days ago
PentagridResponseOverview preview

PentagridResponseOverview

GitHubpentagridsec/pentagridresponseoverview

Response Overview Extension for BurpSuite - Find exotic responses by grouping response bodies

anomaly-detectiondefensive-toolsinformation-gathering+6
118 months ago
repeat-strike preview

repeat-strike

GitHubhackvertor/repeat-strike

Burp Suite extension that uses AI-generated regex strike rules to detect IDOR and access-control flaws, then scans proxy history to find similar…

ai-securityapi-security-testinginformation-gathering+6
411 year ago
Kimai-CVE-2026-52824-POC preview

Kimai-CVE-2026-52824-POC

GitHubcyeezy08/kimai-cve-2026-52824-poc

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

authenticationexploitationinformation-gathering+7
19 days ago
qyvora-anansi preview

qyvora-anansi

GitHubqyvora/qyvora-anansi

Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.

exploitationinformation-gatheringnetwork-mapping+8
45 days ago
enumerate-iam preview

enumerate-iam

GitHubandresriancho/enumerate-iam

Enumerate the permissions associated with AWS credential set

authentication-authorizationcloud-securityconfiguration-auditing+6
1.3k2 years ago
Previous12…100Next