Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
100 results
faction preview

faction

GitHubfactionsecurity/faction

Pen Test Report Generation and Assessment Collaboration

penetration-testingpenetration-testing-frameworksvulnerability-analysis
60211h 46m ago
reconmap preview

reconmap

GitHubreconmap/reconmap

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from…

ai-securitydevsecopspenetration-testing+2
97313h 23m ago
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

crawlerexploitationinformation-gathering+4
22 days ago
atomic-red-team preview

atomic-red-team

GitHubredcanaryco/atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

educationlabs-practicepenetration-testing+1
12.4k3 days ago
CVE-2025-11740 preview

CVE-2025-11740

GitHubalixploit22/cve-2025-11740

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

exploitationpenetration-testingvulnerability-analysis
4 days ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
7 days ago
CVE-2026-72898-PoC preview

CVE-2026-72898-PoC

GitHubcodeb0ssx/cve-2026-72898-poc

Proof-of-concept exploit for CVE-2026-72898 in Metabase, with technical reproduction steps and usage guidance for validating the vulnerability during…

exploitationpenetration-testingvulnerability-analysis+1
7 days ago
missing-cve-nuclei-templates preview

missing-cve-nuclei-templates

GitHubedoardottt/missing-cve-nuclei-templates

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and…

curated-resourcespenetration-testingthreat-intelligence+3
44611 days ago
keyhacks preview

keyhacks

GitHubstreaak/keyhacks

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

api-securitypenetration-testingsecret-detection+1
6.3k13 days ago
owasp-istg preview

owasp-istg

GitHubowasp/owasp-istg

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

curated-resourceseducationembedded-systems-security+9
12818 days ago
CVE-2026-57821-PoC-Exploit preview

CVE-2026-57821-PoC-Exploit

GitHubtc4dy/cve-2026-57821-poc-exploit

🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no…

code-analysisdatabase-securityeducation+5
31 month ago
Google-api-key-scanner preview

Google-api-key-scanner

GitHubcoffinxp/google-api-key-scanner
api-security-testingcloud-securitymisconfiguration+3
551 month ago
mongobleedburp preview

mongobleedburp

GitHubj0lt-github/mongobleedburp

Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.

data-exfiltrationexploitationinformation-gathering+3
1 month ago
malicious-pdf preview

malicious-pdf

GitHubjonaslejon/malicious-pdf

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

data-exfiltrationeducationexploitation+6
4.1k2 months ago
cloudfox preview

cloudfox

GitHubbishopfox/cloudfox

Automating situational awareness for cloud penetration tests.

cloud-securityexploitationinformation-gathering+5
2.6k2 months ago
relay_bible preview

relay_bible

GitHubrootsecdev/relay_bible

Technical Reference to multiple relay techniques

authenticationcurated-resourceseducation+8
1933 months ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
63 months ago
cervantes preview

cervantes

GitHubcervantessec/cervantes

Open-source collaborative platform for pentesters and red teams to manage projects, clients, vulnerabilities, and generate OWASP-compliant reports…

penetration-testingpenetration-testing-frameworksvulnerability-analysis
4463 months ago
Previous123456Next