Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
209 results
learn365 preview

learn365

GitHubharsh-bothra/learn365

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.

api-securitycloud-securitycurated-resources+5
1.7k
4 years ago
SecArchive preview

SecArchive

GitHubmdkaif302/secarchive

🥷 SecArchive - Cybersecurity Resource Collection A curated archive of high-quality resources for learning cybersecurity, bug bounty, ethical…

curated-resourceseducationpenetration-testing
3281 month ago
pth-toolkit preview
Archived

pth-toolkit

GitHubbyt3bl33d3r/pth-toolkit

Modified version of the passing-the-hash tool collection made to work straight out of the box

lateral-movementpassword-attackspenetration-testing+2
61611 years ago
CVE-2026-54350-Budibase-NoSQL-Injection preview

CVE-2026-54350-Budibase-NoSQL-Injection

GitHubbiitts/cve-2026-54350-budibase-nosql-injection

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

database-securityexploitationpayload-development+4
1 month ago
flashingestor preview

flashingestor

GitHubmacmod/flashingestor

TUI-based Active Directory data collector that ingests LDAP objects, performs remote RPC/SMB/HTTP collection, and generates BloodHound CE-compatible…

information-gatheringnetwork-mappingpenetration-testing+2
1735 months ago
Kernelhub preview

Kernelhub

GitHubascotbe/kernelhub

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

curated-resourceseducationexploitation+4
3.2k3 years ago
wp2shell-lab preview

wp2shell-lab

GitHubananay/wp2shell-lab

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

api-security-testingcode-analysiseducation+3
26 days ago
CVE-2024-32030-Nuclei-Template preview

CVE-2024-32030-Nuclei-Template

GitHubhuseyinstif/cve-2024-32030-nuclei-template
exploitationpenetration-testingremote-access-tool+2
12 years ago
spiderfoot preview

spiderfoot

GitHubsmicallef/spiderfoot

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

dns-analysisemail-harvestinginformation-gathering+7
21.2k2 years ago
Detect-It-Easy preview

Detect-It-Easy

GitHubhorsicq/detect-it-easy

Program for determining types of files for Windows, Linux and MacOS.

binary-analysisdigital-forensicsforensics+7
11.4k16h 21m ago
OneForAll preview

OneForAll

GitHubshmilylty/oneforall

Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

dns-analysisinformation-gatheringosint+3
10.0k3 months ago
Kunyu preview

Kunyu

GitHubknownsec/kunyu

Kunyu, more efficient corporate asset collection

information-gatheringnetwork-mappingosint+5
1.1k1 year ago
PE-Linux preview

PE-Linux

GitHubsafebuffer/pe-linux

Linux privilege escalation auditing tool that automates system enumeration, kernel vulnerability checks, password collection, log analysis, and cron…

information-gatheringpenetration-testingprivilege-escalation
1877 years ago
HoneyProxy preview

HoneyProxy

GitHubmhils/honeyproxy

This project is now part of @mitmproxy.

forensicsnetwork-securitypacket-sniffing-analysis+3
1969 years ago
Ledger preview

Ledger

GitHubshellkraft/ledger

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

command-and-controlincident-responselog-analysis+5
273 months ago
CVE-2025-31702 preview

CVE-2025-31702

GitHubitres-labs/cve-2025-31702

Repository with tools, exploits, and material associated with the analysis and discovery process of CVE-2025-31702 and other related security issues.

digital-forensicsexploitationincident-response+3
108 months ago
ZeroLogon-Exploitation-Check preview

ZeroLogon-Exploitation-Check

GitHubyossisassi/zerologon-exploitation-check

quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual…

exploitationincident-responseinformation-gathering+3
75 years ago
fetch-broker-conf preview

fetch-broker-conf

GitHubvulncheck-oss/fetch-broker-conf

A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246

exploitationincident-responseinformation-gathering+3
52 years ago
Previous1…9101112Next