Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
60 results
scriptkiddi3 preview

scriptkiddi3

GitHubthecyberneh/scriptkiddi3

Automated reconnaissance and vulnerability detection tool that enumerates subdomains, collects URLs, and runs Nuclei scans to identify…

penetration-testingreconnaissancesubdomain-enumeration+1
152
2 years ago
Get-RBCD-Threaded preview

Get-RBCD-Threaded

GitHubfatrodzianko/get-rbcd-threaded

Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments

penetration-testingprivilege-escalationreconnaissance+1
1335 years ago
CVE-2026-8732-POC preview

CVE-2026-8732-POC

GitHubp3nt3st3r-star/cve-2026-8732-poc
exploitationinformation-gatheringpenetration-testing+4
82 months ago
OneForAll preview

OneForAll

GitHubshmilylty/oneforall

Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

dns-analysisinformation-gatheringosint+3
10.0k3 months ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k20 days ago
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k1 year ago
second-order preview

second-order

GitHubmhmdiaa/second-order

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

crawlerreconnaissancesubdomain-enumeration+2
4081 year ago
k8scout preview

k8scout

GitHubk8scout/k8scout

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

cloud-securitycontainer-securityinformation-gathering+8
2271 month ago
CVE-2026-27886-PoC-Account-Takeover preview

CVE-2026-27886-PoC-Account-Takeover

GitHubthesw0rd/cve-2026-27886-poc-account-takeover

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

exploitationinformation-gatheringpassword-attacks+4
22 months ago
CVE-2026-39912 preview

CVE-2026-39912

GitHubchocapikk/cve-2026-39912

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

authenticationexploitationinformation-gathering+4
24 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubhudzaifaharrantisi/cve-2026-8181

CVE-2026-8181 — Burst Statistics WordPress plugin Authentication Bypass (CVSS 9.8) to Admin Account Takeover. Mass scanner with FOFA/Shodan…

authenticationexploitationinformation-gathering+4
1 month ago
CVE-2025-15521 preview

CVE-2025-15521

GitHubnxploited/cve-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

authenticationexploitationinformation-gathering+5
14 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubxshadow-here/cve-2026-8181

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

authenticationexploitationinformation-gathering+6
13 months ago
bug-bounty-reports-desai-vinayak preview

bug-bounty-reports-desai-vinayak

GitHubdesaivinayak449/bug-bounty-reports-desai-vinayak

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

cloud-securitycurated-resourcesdns-analysis+6
9 months ago
CVE-2020-35847_CVE-2020-35848 preview

CVE-2020-35847_CVE-2020-35848

GitHubw33vils/cve-2020-35847_cve-2020-35848

CVE-2020-35847, CVE-2020-35848 : Account Takeover

exploitationinformation-gatheringpassword-attacks+3
3 years ago
Reconator preview

Reconator

GitHubgokulapap/reconator

Automated Recon for Pentesting & Bug Bounty

dns-subdomain-enumerationfuzzinginformation-gathering+6
4413 months ago
DepFuzzer preview

DepFuzzer

GitHubsynacktiv/depfuzzer
code-analysisosintreconnaissance+2
948 months ago
CVE-2026-27886-check preview

CVE-2026-27886-check

GitHubbishopfox/cve-2026-27886-check

Detect whether a Strapi instance is vulnerable to CVE-2026-27886 (unauthenticated boolean-oracle exfiltration of administrator secrets).

exploitationinformation-gatheringpenetration-testing+3
13 months ago
Previous1234Next