Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
569 results
Zerologon_CVE-2020-1472 preview

Zerologon_CVE-2020-1472

GitHubjolynngsc/zerologon_cve-2020-1472

Step-by-step lab guide for simulating, detecting, and mitigating the Zerologon vulnerability (CVE-2020-1472) on Windows Server 2016 using Kali Linux…

educationexploitationlabs-practice+2
2 years ago
FuegoTest preview

FuegoTest

GitHub0zer0d4y/fuegotest

A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.

configuration-auditingexploitationinformation-gathering+3
2 years ago
CVE-2014-6271 preview

CVE-2014-6271

GitHubbrandaoo/cve-2014-6271

Checks if a website is vulnerable to the Shellshock (CVE-2014-6271) Bash vulnerability by sending crafted requests and reporting the result.

exploitationinformation-gatheringpenetration-testing+2
3 years ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
186 days ago
adnullenum preview

adnullenum

GitHubcrypt0p3g/adnullenum

One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.

defensive-toolsinformation-gatheringnetwork-security+5
377 days ago
SprayingToolkit preview
Archived

SprayingToolkit

GitHubbyt3bl33d3r/sprayingtoolkit

Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient

email-harvestinginformation-gatheringosint-social-engineering+4
1.6k3 years ago
CVE-2023-6241 preview
Archived

CVE-2023-6241

GitHubs1204it/cve-2023-6241

CVE-2023-6241 for Pixel 8

android-securitybinary-exploitationexploitation+3
171 year ago
aztarna preview
Archived

aztarna

GitHubaliasrobotics/aztarna

aztarna, a footprinting tool for robots.

embedded-systems-securityhardware-iot-securityinformation-gathering+7
922 months ago
Magnohost-Vulnerabilities-pentest preview

Magnohost-Vulnerabilities-pentest

GitHub0ord/magnohost-vulnerabilities-pentest

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

exploitationinformation-gatheringnetwork-security+8
14 months ago
nse-log4shell preview
Archived

nse-log4shell

GitHubdiverto/nse-log4shell

Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)

dns-analysisexploitationnetwork-security+3
3534 years ago
SimpleEmailSpoofer preview
Archived

SimpleEmailSpoofer

GitHublunarca/simpleemailspoofer

A simple Python CLI to spoof emails.

email-securityosint-social-engineeringpenetration-testing+3
5634 years ago
KnockKnock preview
Archived

KnockKnock

GitHuboptiv/knockknock

Enumerate valid users within Microsoft Teams and OneDrive with clean output.

authenticationcloud-securityinformation-gathering+3
621 year ago
CrawlBox preview
Archived

CrawlBox

GitHubabaykan/crawlbox

Easy way to brute-force web directory.

crawlerinformation-gatheringpenetration-testing+3
1647 years ago
nodesub preview
Archived

nodesub

GitHubpikpikcu/nodesub

Nodesub is a command-line tool for finding subdomains in bug bounty programs

dns-analysisdns-subdomain-enumerationinformation-gathering+3
1442 years ago
firebase preview
Archived

firebase

GitHubfrancesc-h/firebase

Exploiting misconfigured firebase databases

crawlerdata-exfiltrationdns-subdomain-enumeration+5
1247 years ago
findom-xss preview
Archived

findom-xss

GitHubdwisiswant0/findom-xss

A fast DOM based XSS vulnerability scanner with simplicity.

dynamic-code-analysisinformation-gatheringpenetration-testing+3
8713 years ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubyasouxken/cve-2026-41940-poc

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

authenticationcommand-and-controlexploitation+7
3 days ago
CVE-2026-41089-Netlogon-RCE-PoC preview

CVE-2026-41089-Netlogon-RCE-PoC

GitHubgillarchnganasan2735/cve-2026-41089-netlogon-rce-poc

Automate Netlogon CVE-2026-41089 validation and defensive testing through integrated AI security workflows, enabling rapid risk assessment and…

defensive-toolseducationexploitation+5
3 days ago
Previous1…303132Next