Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1736 results
CLSIDFinder preview

CLSIDFinder

GitHub0xqn/clsidfinder

PowerShell enumeration script for discovering service-backed COM objects via CLSID/AppID correlation and activation testing.

information-gatheringlateral-movementpenetration-testing+3
3
5 months ago
CVE-2024-8856 preview

CVE-2024-8856

GitHubjenderal92/cve-2024-8856

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

information-gatheringreconnaissancevulnerability-analysis+2
22 months ago
SharpHound2 preview
Archived

SharpHound2

GitHubbloodhoundad/sharphound2

The Old BloodHound C# Ingestor (Deprecated)

information-gatheringpenetration-testingreconnaissance+1
5064 years ago
CVE-2026-8794 preview

CVE-2026-8794

GitHubh4zaz/cve-2026-8794

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

authenticationinformation-gatheringpenetration-testing+4
5 days ago
sterraxcyl preview
Archived

sterraxcyl

GitHubnovitae/sterraxcyl

Instagram OSINT tool to export and analyse followers | following with their details

crawlerinformation-gatheringosint+2
6832 years ago
DOGE preview
Archived

DOGE

GitHubpielco11/doge

Darknet Osint Graph Explorer

information-gatheringosintreconnaissance+1
1265 years ago
honeybits preview
Archived

honeybits

GitHub0x4d31/honeybits

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward…

information-gatheringlateral-movementosint-social-engineering+5
2787 years ago
Wordpresscan preview
Archived

Wordpresscan

GitHubswisskyrepo/wordpresscan

WPScan rewritten in Python + some WPSeku ideas

information-gatheringpassword-attacksreconnaissance+3
6525 years ago
laf preview
Archived

laf

GitHubtakeshixx/laf

Login Area Finder: scans host/s for login panels

information-gatheringpenetration-testingreconnaissance+2
1411 years ago
nse-exchange preview
Archived

nse-exchange

GitHubdiverto/nse-exchange

Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability

exploitationinformation-gatheringpenetration-testing+3
823 years ago
cve-2025-6907 preview
Archived

cve-2025-6907

GitHubbytereaper77/cve-2025-6907

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2025-6082 preview
Archived

CVE-2025-6082

GitHubbytereaper77/cve-2025-6082

Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)

exploitationinformation-gatheringpenetration-testing+3
11 year ago
Serein preview
Archived

Serein

GitHubw01fh4cker/serein

【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day…

crawlerexploitationinformation-gathering+6
1.3k3 years ago
bug-bounty-domains preview
Archived

bug-bounty-domains

GitHubarpsyndicate/bug-bounty-domains

Domains belonging to the most reputed public bug bounty programs. [NOT FOR NON-MONETARY OR PRIVATE PROGRAMS]

curated-resourcesinformation-gatheringosint+2
2271 year ago
OTE preview
Archived

OTE

GitHub3nock/ote

OSINT Template Engine

information-gatheringosintreconnaissance+1
57914 days ago
melody preview
Archived

melody

GitHubma111e/melody

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.

information-gatheringintrusion-detectionnetwork-security+5
1391 year ago
Injectus preview
Archived

Injectus

GitHubdubs3c/injectus

CRLF and open redirect fuzzer

fuzzinginformation-gatheringpenetration-testing+3
1134 years ago
Alfred preview
Archived

Alfred

GitHubpwnfuzz/alfred

WIP - Revamped Alfred [2.0]

exploitationinformation-gatheringpenetration-testing+4
401 year ago
Previous1…929394…97Next