Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
297 results
osiris preview

osiris

GitHubsimplifaisoul/osiris

Open Source Global Intelligence Platform - Real-Time OSINT Dashboard - A Palantir Alternative - …

dns-analysisinformation-gatheringnetwork-mapping+7
9.8k
3 days ago
Argus preview

Argus

GitHubdivinelabio/argus

The Ultimate Information Gathering Toolkit

crawlerdns-subdomain-enumerationemail-harvesting+8
4.2k9 months ago
Magnohost-Vulnerabilities-pentest preview

Magnohost-Vulnerabilities-pentest

GitHub0ord/magnohost-vulnerabilities-pentest

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

exploitationinformation-gatheringnetwork-security+8
14 months ago
AgrusScanner preview

AgrusScanner

GitHubnybaywatch/agrusscanner

Windows network reconnaissance scanner with ping sweeps, TCP port scanning, and deep AI/ML service detection for finding shadow AI, rogue LLM…

ai-securitydefensive-toolsinformation-gathering+6
147 days ago
OmniSec-Hex preview

OmniSec-Hex

GitHubvighnesh91/omnisec-hex

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

ai-securitybinary-analysisfuzzing+9
13 days ago
KUMO-Domain-Recon-Tool preview

KUMO-Domain-Recon-Tool

GitHubkarim852/kumo-domain-recon-tool

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

dns-analysisinformation-gatheringosint+8
486 days ago
metasploit-pentest-report preview

metasploit-pentest-report

GitHubronankongala/metasploit-pentest-report

Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings…

ctfcurated-resourceseducation+7
25 days ago
Simple Pentesting preview

Simple Pentesting

GitLabsakispat/simple-pentesting

An educational Python toolkit for authorized penetration testing: threaded port scanner, subdomain & directory enumeration, banner grabber and host…

educationinformation-gatheringnetwork-mapping+7
11 days ago
sunset-noontide-pentesting preview

sunset-noontide-pentesting

GitHubzales2004/sunset-noontide-pentesting

Description Professional penetration testing assessment of the Sunset: Noontide VulnHub machine, covering reconnaissance, service enumeration,…

ctfeducationexploitation+9
11 days ago
voidsec-proxy preview

voidsec-proxy

GitHubvoidsecsoftwares/voidsec-proxy

Multi-module offensive security toolkit for SOCKS5 proxy chaining, port scanning, DNS enumeration, hash cracking, reverse shell generation,…

data-exfiltrationdigital-forensicsdns-subdomain-enumeration+8
415 days ago
Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation preview

Metasploitable2-Reconnaissance-and-UnrealIRCd-Backdoor-Exploitation

GitHubrhimavanth32-max/metasploitable2-reconnaissance-and-unrealircd-backdoor-exploitation

End-to-end recon and exploitation of a known backdoor (CVE-2010-2075) on Metasploitable2 using Nmap and Metasploit.

ctfeducationexploitation+7
13 days ago
edu-recon preview

edu-recon

GitHubyeee3642/edu-recon

Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web…

educationexploitationinformation-gathering+8
14 days ago
Jozini-network-scanner preview

Jozini-network-scanner

GitHubmngunibanda1-prog/jozini-network-scanner

Python-based network scanner with port scanning, banner grabbing, and RouterOS CVE mapping for vulnerability identification and reporting.

educationinformation-gatheringnetwork-security+3
18 days ago
w12scan-client preview

w12scan-client

GitHubw-digital-scanner/w12scan-client

Network asset discovery and scanning client that integrates nmap and masscan for large-scale asset identification, port scanning, and vulnerability…

information-gatheringnetwork-mappingnetwork-security+3
2153 years ago
pentx-vapt-skill preview

pentx-vapt-skill

GitHubyashas-13/pentx-vapt-skill

Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC

exploitationinformation-gatheringpenetration-testing+6
228 days ago
portscan-CVE-2026-41940 preview

portscan-CVE-2026-41940

GitHubamirrezamarzban/portscan-cve-2026-41940

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

information-gatheringnetwork-securitypenetration-testing+3
14 months ago
tscan preview

tscan

GitHubcumakurt/tscan

Python-based scanner that detects and exploits CVE-2026-24061 telnetd authentication bypass, enabling root shell access on vulnerable GNU Inetutils…

educationexploitationnetwork-security+4
17 months ago
sdwan-scanner-CVE-2026-20127 preview

sdwan-scanner-CVE-2026-20127

GitHubabrahamsurf/sdwan-scanner-cve-2026-20127

Cisco SD-WAN Exposure & Potential Vulnerability Scanner (Passive Fingerprinting) 2026

cloud-infrastructure-securityinformation-gatheringnetwork-security+3
6 months ago
Previous12…17Next