Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
118 results
proxy-workbench preview

proxy-workbench

GitHubdavidvoitenko/proxy-workbench

Collects, checks and ranks public HTTP/SOCKS proxies against your own targets, then serves them via ranked exports, pools, a rotating gateway and a…

crawlergeneral-purpose-utilitiesinformation-gathering+5
12
4 days ago
dj preview

dj

GitHubejfkdev/dj

Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source…

anti-botcrawlerfingerprint-spoofing+7
527 days ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubmhtsec/cve-2026-85706

Python PoC for CVE-2026-85706, an unauthenticated path traversal in GitLab CE/EE Repository Commits API that leaks arbitrary local files via a…

data-exfiltrationexploitationinformation-gathering+5
1224 days ago
CVE-2026-56718 preview

CVE-2026-56718

GitHubhellkkid/cve-2026-56718

AJCloud AJY IPC Firmware Path Traversal via jdbhttpd

embedded-systems-securityexploitationiot-security+3
1 month ago
mousejack preview

mousejack

GitHubbastilleresearch/mousejack

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

exploitationfirmware-analysishardware-iot-security+3
1.4k8 years ago
fuzz.txt preview

fuzz.txt

GitHubbo0om/fuzz.txt

Potentially dangerous files

fuzzinginformation-gatheringpenetration-testing+3
3.4k2 months ago
czds preview

czds

GitHubmsadministrator/czds

A Python package to download Zone Files from the Centralized Zone Data Service hosted by ICAAN.

crawlerdns-analysisinformation-gathering+2
171 year ago
Combined-Wordlists preview

Combined-Wordlists

GitHub0xspade/combined-wordlists

A combined wordlists for files and directory discovery

curated-resourcesinformation-gatheringpenetration-testing+2
1325 years ago
EvilCrowRF_Custom_Firmware_CC1101_FlipperZero preview

EvilCrowRF_Custom_Firmware_CC1101_FlipperZero

GitHubh-rat/evilcrowrf_custom_firmware_cc1101_flipperzero

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

embedded-systems-securityhardware-hackinghardware-iot-security+5
6042 years ago
netscout preview

netscout

GitHubcaio-ishikawa/netscout

OSINT tool that finds domains, subdomains, directories, endpoints and files for a given seed URL.

crawlerdns-subdomain-enumerationinformation-gathering+3
1832 years ago
sccm-http-looter preview

sccm-http-looter

GitHubbadsectorlabs/sccm-http-looter

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

data-exfiltrationinformation-gatheringmisconfiguration+3
2162 years ago
adexplorersnapshot-rs preview

adexplorersnapshot-rs

GitHubt94j0/adexplorersnapshot-rs

Converts Active Directory Explorer snapshot (.dat) files into BloodHound CE JSON archives for graph-based AD attack-path analysis and reconnaissance.

identity-access-managementinformation-gatheringpenetration-testing+1
955 months ago
Gemini-api-key-hunter preview

Gemini-api-key-hunter

GitHubcoffinxp/gemini-api-key-hunter

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

api-securitycloud-securityinformation-gathering+5
732 months ago
BFScan preview

BFScan

GitHubblackfan/bfscan

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

android-securityapi-securityinformation-gathering+5
25710 months ago
JShunter preview

JShunter

GitHubcc1a2b/jshunter

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

api-securitydynamic-code-analysispenetration-testing+6
54015 days ago
juicy-php preview

juicy-php

GitHubrandomrobbiebf/juicy-php

Juicy-php - finds PHP info files with juicy information

information-gatheringreconnaissanceweb-security
16 years ago
loot-me preview

loot-me

GitHubrandomrobbiebf/loot-me

Collects files and commands post-exploitation, formats them into Markdown reports, and helps find sensitive information for red team reporting.

information-gatheringpenetration-testingpost-exploitation+2
6 years ago
grafana-unauth-file-read preview

grafana-unauth-file-read

GitHubvulnmachines/grafana-unauth-file-read

Exploit for Grafana LFI vulnerability CVE-2021-43798 enabling unauthorized file reading via path traversal in plugin endpoints.

exploitationinformation-gatheringpenetration-testing+3
44 years ago
Previous1234567Next