Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
Creds preview

Creds

GitHubs3cur3th1ssh1t/creds

Some usefull Scripts and Executables for Pentest & Forensics

digital-forensicspassword-attackspenetration-testing+1
1.2k
10 days ago
secretsdump.py preview

secretsdump.py

GitHubfin3ss3g0d/secretsdump.py

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

data-exfiltrationpassword-attackspenetration-testing+2
2593 years ago
rules preview

rules

GitHubibnaleem/rules

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

curated-resourcespassword-attackspassword-cracking+2
732 months ago
JavaPayload preview

JavaPayload

GitHubschierlm/javapayload

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

exploitationmisconfigurationpayload-development+3
1271 year ago
grafana-bruteforce preview

grafana-bruteforce

GitHubrandomrobbiebf/grafana-bruteforce

Grafana Bruteforce tool

authenticationpassword-attackspenetration-testing+2
6 years ago
postgres-bruteforcer preview

postgres-bruteforcer

GitHubrandomrobbiebf/postgres-bruteforcer

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

authenticationdatabase-securityexploitation+2
3 years ago
security-research preview

security-research

GitHubmirchr/security-research

Security Research

curated-resourcesexploitationpassword-cracking+5
941 year ago
prepos-login-checker preview

prepos-login-checker

GitHubjenderal92/prepos-login-checker

Prepostseo Login Checker

authenticationpassword-attackspenetration-testing+2
2 months ago
CVE-2026-34828 preview

CVE-2026-34828

GitHub0xmrma/cve-2026-34828

listmonk’s Session Persistence After Password Reset and Password Change

authenticationexploitationpenetration-testing+2
14 months ago
cve-2023-22515-exp preview

cve-2023-22515-exp

GitHubdsahen/cve-2023-22515-exp

cve-2023-22515的python利用脚本

exploitationpayload-generationpenetration-testing+2
2 years ago
wpbf preview

wpbf

GitHubdejanlevaja/wpbf

WPBF - a multithreaded WP brute forcer

authenticationinformation-gatheringpassword-attacks+2
512 years ago
FaceBrute preview

FaceBrute

GitHubemerinohdz/facebrute

Facebook brute forcer script

authenticationpassword-attackspenetration-testing+2
2714 years ago
CVE-2024-22274 preview

CVE-2024-22274

GitHubninhpn1337/cve-2024-22274
exploitationpayload-generationpenetration-testing+3
2 years ago
SSHUsernameBruter-SSHUB preview

SSHUsernameBruter-SSHUB

GitHubjoeblacksecurity/sshusernamebruter-sshub

Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

exploitationnetwork-securitypassword-attacks+2
17 years ago
CVE-2025-58434-PoC preview

CVE-2025-58434-PoC

GitHubmananispiwpiw/cve-2025-58434-poc

CVE-2025-58434 Proof of Concept

educationexploitationpenetration-testing+2
3 months ago
Credential-Hunting preview

Credential-Hunting

GitHubnecr00/credential-hunting

CredsHunter - Credential Hunting scripts for Windows and Linux OS

forensicsincident-responseinformation-gathering+7
1751 day ago
CVE-2025-25198-PoC preview

CVE-2025-25198-PoC

GitHubgroppoxx/cve-2025-25198-poc

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

exploitationpassword-attackspenetration-testing+3
203 months ago
CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit preview

CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit

GitHubelizeuopain/cve-2019-9053-cms-made-simple-2.2.10---sql-injection-exploit
exploitationpassword-crackingpenetration-testing+2
54 months ago
Previous123Next