Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
39 results
BloodHound preview

BloodHound

GitHubspecterops/bloodhound

Six Degrees of Domain Admin

defensive-toolsidentity-access-managementinformation-gathering+4
3.3k
12h 47m ago
BloodBash preview

BloodBash

GitHubsquidsec/bloodbash

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

cloud-securityconfiguration-auditingidentity-access-management+6
4061 day ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+7
80.2k11 days ago
WinPEAS-nu11 preview

WinPEAS-nu11

GitHubnu11secur1ty/winpeas-nu11
configuration-auditingeducationinformation-gathering+7
1 month ago
cve-2026-11837-ansible-posix-authorized-key preview

cve-2026-11837-ansible-posix-authorized-key

GitHubm8seven/cve-2026-11837-ansible-posix-authorized-key

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

code-analysisconfiguration-auditingdevsecops+3
11 month ago
DLLHijackHunter preview

DLLHijackHunter

GitHubghostvectoracademy/dllhijackhunter

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

binary-analysisdynamic-code-analysiseducation+8
3962 months ago
litespeed-cpanel-cve-2026-54420-fix preview

litespeed-cpanel-cve-2026-54420-fix

GitHubmahfuzreham/litespeed-cpanel-cve-2026-54420-fix
cloud-securityconfiguration-auditingdefensive-tools+7
12 months ago
CVE-2026-6356 preview

CVE-2026-6356

GitHubpenguinsecq/cve-2026-6356

Exploit PoC of CVE-2026-6356

educationexploitationpenetration-testing+3
3 months ago
AD_Miner preview

AD_Miner

GitHubad-security/ad_miner

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

configuration-auditingeducationinformation-gathering+6
1.6k5 months ago
Anvil preview

Anvil

GitHubshellkraft/anvil

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

binary-analysisexploitationpenetration-testing+5
375 months ago
htb-ctf-walkthroughs preview

htb-ctf-walkthroughs

GitLabrootsecnz/htb-ctf-walkthroughs

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

ctfeducationexploitation+6
5 months ago
Chrono-Drip-Temporal-Viscosity-Exploitation-Framework-CVE-2022-0847 preview

Chrono-Drip-Temporal-Viscosity-Exploitation-Framework-CVE-2022-0847

GitHubsimoesctt/chrono-drip-temporal-viscosity-exploitation-framework-cve-2022-0847

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

binary-exploitationeducationexploitation+8
6 months ago
React2Shell-CVE-Lab preview

React2Shell-CVE-Lab

GitHubxxxtectationxxx/react2shell-cve-lab

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

container-securityctfeducation+6
18 months ago
Session-Persistence-After-Enabling-2FA-CVE-2025-60425 preview

Session-Persistence-After-Enabling-2FA-CVE-2025-60425

GitHubaakashtyal/session-persistence-after-enabling-2fa-cve-2025-60425
authenticationexploitationpenetration-testing+3
10 months ago
CVE-2024-36886 preview

CVE-2024-36886

GitHubabubakar-shahid/cve-2024-36886
dynamic-code-analysiseducationexploitation+5
11 months ago
Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets- preview

Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-

GitHubartemcyberlab/project-project-chimera-exploiting-a-modern-wordpress-xxe-to-pillage-secrets-

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

educationexploitationinformation-gathering+8
10 years ago
CVE-2025-25621 preview

CVE-2025-25621

GitHubarmaansidana2003/cve-2025-25621
educationmisconfigurationpenetration-testing+3
1 year ago
CVE-2025-25617 preview

CVE-2025-25617

GitHubarmaansidana2003/cve-2025-25617
educationexploitationpenetration-testing+3
1 year ago
Previous123Next