Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
99 results
CVE-2022-24693 preview

CVE-2022-24693

GitHublukejenkins/cve-2022-24693
embedded-systems-securityexploitationfirmware-analysis+6
31 year ago
ip-https-tools preview
Archived

ip-https-tools

GitHubtakeshixx/ip-https-tools

Tools for the IP over HTTPS (IP-HTTPS) Tunneling Protocol

dns-analysisnetwork-mappingnetwork-security+3
910 years ago
CVE-2019-5513-scanner preview

CVE-2019-5513-scanner

GitHubsudosu01/cve-2019-5513-scanner

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

exploitationinformation-gatheringpenetration-testing+3
2 months ago
livewire-vuln-scanner preview

livewire-vuln-scanner

GitHubjenderal92/livewire-vuln-scanner

Simple scanner to detect vulnerable Livewire installations.

information-gatheringreconnaissancevulnerability-analysis+3
2 months ago
VindicateTool preview

VindicateTool

GitHubrushyo/vindicatetool

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

defensive-toolsdns-analysisincident-response+4
614 years ago
samba-trans2open-exploit-report preview

samba-trans2open-exploit-report

GitHubbakr-ht/samba-trans2open-exploit-report

Exploitation report of the Samba Trans2Open vulnerability (CVE-2003-0201), including tools used, exploitation steps, and protection techniques to…

educationexploitationnetwork-mapping+6
211 months ago
Onionscan preview

Onionscan

GitLabn3ph0s/onionscan
crawlerdns-analysisemail-harvesting+4
4 years ago
CVE-2022-1386-FusionBuilder-SSRF preview

CVE-2022-1386-FusionBuilder-SSRF

GitHubfayassgit/cve-2022-1386-fusionbuilder-ssrf

Unauthenticated SSRF PoC in WordPress Fusion Builder <3.6.2 (CVE-2022-1386)

exploitationpenetration-testingreconnaissance+2
1 year ago
leaky-paths preview

leaky-paths

GitHubayoubfathi/leaky-paths

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…

curated-resourcesfuzzinginformation-gathering+3
1.2k4 months ago
karma_v2 preview

karma_v2

GitHubdheerajmadhukar/karma_v2

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

crawlerdns-subdomain-enumerationinformation-gathering+4
1.0k2 years ago
CVE-2026-33693 preview

CVE-2026-33693

GitHubsnailsploit/cve-2026-33693

CVE-2026-33693: SSRF via 0.0.0.0 Bypass in activitypub-federation-rust v4_is_invalid() (CVSS 6.5 Moderate)

educationexploitationpapers-research+3
3 months ago
Attacker-Group-Predictor preview

Attacker-Group-Predictor

GitHubomergunal/attacker-group-predictor

Tool to predict attacker groups from the techniques and software used

information-gatheringosintreconnaissance+1
495 years ago
Hale preview

Hale

GitHubpjlantz/hale

Botnet command & control monitor

command-and-controlincident-responseinformation-gathering+5
2024 years ago
RCE_CVE-2024-7954- preview

RCE_CVE-2024-7954-

GitHub0dayan0n/rce_cve-2024-7954-

The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and…

exploitationpenetration-testingreconnaissance+2
21 year ago
OSINT-SPY preview

OSINT-SPY

GitHubsharadkumar97/osint-spy

Performs OSINT scan on email/domain/ip_address/organization using OSINT-SPY. It can be used by Data Miners, Infosec Researchers, Penetration Testers…

cryptographydns-subdomain-enumerationemail-harvesting+5
1.5k6 years ago
porch-pirate preview

porch-pirate

GitHubwatchdogsecurity/porch-pirate

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

api-securityinformation-gatheringosint+4
4672 years ago
catsploit preview

catsploit

GitHubcatsploit/catsploit

Automated penetration testing tool using Cyber Attack Techniques Scoring (CATS) to select and execute optimal attack scenarios via Metasploit, Nmap,…

exploit-frameworksinformation-gatheringpenetration-testing+3
3212 years ago
goGetBucket preview

goGetBucket

GitHubglem0/gogetbucket

A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.

cloud-securityinformation-gatheringpenetration-testing+2
1167 years ago
Previous123456Next