Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
129 results
social-engineer-toolkit preview

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

exploit-frameworksinformation-gatheringpayload-generation+5
15.2k2 months ago
UPnP-Pentest-Toolkit preview

UPnP-Pentest-Toolkit

GitHubnccgroup/upnp-pentest-toolkit

UPnP Pentest Toolkit for Windows

exploitationhardware-iot-securitynetwork-security+5
26111 years ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisinformation-gathering+7
8.0k1 month ago
sandbox-attacksurface-analysis-tools preview

sandbox-attacksurface-analysis-tools

GitHubgoogleprojectzero/sandbox-attacksurface-analysis-tools

Set of tools to analyze Windows sandboxes for exposed attack surface.

defensive-toolsdynamic-analysis-sandboxingexploitation+4
2.3k9 months ago
Tunna preview

Tunna

GitHubsecforce/tunna

Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled…

ids-ips-evasionpenetration-testingred-teaming+1
1.3k5 years ago
HopLa preview

HopLa

GitHubsynacktiv/hopla

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

ai-securityapi-security-testingpayload-generation+3
8364 months ago
blackboxprotobuf preview

blackboxprotobuf

GitHubnccgroup/blackboxprotobuf

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

binary-analysisdigital-forensicsmobile-app-pentesting+3
7314 months ago
sippts preview

sippts

GitHubpepelux/sippts

Set of tools to audit SIP based VoIP Systems

exploitationfuzzinginformation-gathering+6
5711 month ago
PXEThief preview

PXEThief

GitHubmwr-cybersec/pxethief

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

exploitationinformation-gatheringpassword-attacks+5
4342 years ago
zscan preview

zscan

GitHubzyylhn/zscan

Zscan a scan blasting tool set

exploitationnetwork-mappingpassword-attacks+4
5392 years ago
leakScraper preview

leakScraper

GitHubacceis/leakscraper

LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help…

data-exfiltrationinformation-gatheringosint+2
4507 years ago
cotopaxi preview

cotopaxi

GitHubsamsung/cotopaxi

Set of tools for security testing of Internet of Things devices using specific network IoT protocols

fuzzingiot-securitynetwork-security+2
3625 years ago
laf preview

laf

GitHubioactive/laf

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

cryptographyexploitationfuzzing+5
1873 years ago
WMIExec preview

WMIExec

GitHubwkl-sec/wmiexec

Set of python scripts which perform different ways of command execution via WMI protocol.

command-and-controldata-exfiltrationlateral-movement+2
1683 years ago
ftw preview

ftw

GitHubcoreruleset/ftw

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

devsecopspenetration-testingvulnerability-scanners+2
1424 years ago
XIP preview

XIP

GitHubimmunit/xip

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

ids-ips-evasioninformation-gatheringpenetration-testing+2
777 years ago
SCOPE preview

SCOPE

GitHubtayontech/scope

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

ai-securitycloud-infrastructure-securitycloud-security+8
542 months ago
OpenSSL-CCS-Inject-Test preview

OpenSSL-CCS-Inject-Test

GitHubtripwire/openssl-ccs-inject-test

This script is designed for detection of vulnerable servers (CVE-2014-0224.) in a wide range of configurations. It attempts to negotiate using each…

exploitationnetwork-securitypenetration-testing+2
3912 years ago
Previous12…8Next