Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
LdapRelayScan preview

LdapRelayScan

GitHubzyn3rgy/ldaprelayscan

Check for LDAP protections regarding the relay of NTLM authentication

authenticationconfiguration-auditinginformation-gathering+5
531
1 year ago
CVE-2022-46169_unauth_remote_code_execution preview

CVE-2022-46169_unauth_remote_code_execution

GitHubsvchost9913/cve-2022-46169_unauth_remote_code_execution

Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0

authentication-authorizationcommand-and-controlexploitation+3
3 years ago
CVE-2023-0297 preview

CVE-2023-0297

GitHubhazeyez/cve-2023-0297

Unauthenticated remote code execution exploit for PyLoad versions below 0.5.0b3.dev31. Designed for security auditing of vulnerable instances.

exploitationpenetration-testingremote-access-tool+2
3 years ago
CSPBypass preview

CSPBypass

GitHubrenniepak/cspbypass

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

configuration-auditingcurated-resourcesmisconfiguration+4
7145 days ago
gpoParser preview

gpoParser

GitHubsynacktiv/gpoparser

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

configuration-auditinginformation-gatheringlateral-movement+7
3724 months ago
SAPKiln preview

SAPKiln

GitHubowasp/sapkiln

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

configuration-auditinglateral-movementosint+3
303 years ago
CVE-2026-33829 preview

CVE-2026-33829

GitHubseguridadentrerios/cve-2026-33829

Automated Bash script to passively audit Windows assets for CVE-2026-33829 search: protocol handler vulnerability using tcpdump and SMB connection…

exploitationnetwork-securitypenetration-testing+2
2 months ago
IAMActionHunter preview

IAMActionHunter

GitHubrhinosecuritylabs/iamactionhunter

An AWS IAM policy statement parser and query tool.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+4
2001 year ago
FuegoTest preview

FuegoTest

GitHub0zer0d4y/fuegotest

A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.

configuration-auditingexploitationinformation-gathering+3
2 years ago
cnappgoat preview

cnappgoat

GitHubtenable/cnappgoat

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

cloud-infrastructure-securitycloud-securityctf+5
2962 years ago
modifyCertTemplate preview

modifyCertTemplate

GitHubfortalice/modifycerttemplate

ADCS cert template modification and ACL enumeration

authenticationconfiguration-auditingexploitation+3
1453 years ago
Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763- preview

Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-

GitHubartemcyberlab/project-exploiting-a-vulnerability-in-fuel-cms-cve-2018-16763-

The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical…

exploitationpenetration-testingred-teaming+3
1 year ago
EAST preview
Archived

EAST

GitHubjsa2/east

Extensible Azure Security Tool - Documentation

cloud-infrastructure-securitycloud-securityconfiguration-auditing+4
843 years ago
DSCourier preview

DSCourier

GitHubdylandavis1/dscourier

Proof-of-concept tool leveraging WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries, enabling EDR bypass for…

configuration-auditingdefensive-toolspenetration-testing+3
2112 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

api-securitycloud-securityconfiguration-auditing+7
25 months ago
WindowsDACLEnumProject preview

WindowsDACLEnumProject

GitHubnccgroup/windowsdaclenumproject

A collection of tools to enumerate and analyse Windows DACLs

configuration-auditingdefensive-toolsmisconfiguration+3
11111 years ago
wafparan01d3 preview

wafparan01d3

GitHubalt3kx/wafparan01d3

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

configuration-auditingdefensive-toolspenetration-testing+2
244 years ago
Check-Point-Trusted-Access-Review preview

Check-Point-Trusted-Access-Review

GitHubwadesweaponshed/check-point-trusted-access-review

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

cloud-securityconfiguration-auditingmisconfiguration+3
1 month ago
Previous123Next