Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
99 results
CVE-2023-35813 preview

CVE-2023-35813

GitHubher3ticavi/cve-2023-35813

CVE-2023-35813 is a proof-of-concept used to determine if an instance of Sitecore is vulnerable by analyzing a server Response Header for…

exploitationpenetration-testingreconnaissance+2
3
4 months ago
discover preview

discover

GitHubleebaird/discover

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

api-security-testingcloud-securitycontainer-security+9
3.9k1 day ago
xnLinkFinder preview

xnLinkFinder

GitHubxnl-h4ck3r/xnlinkfinder

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

crawlerinformation-gatheringpenetration-testing+3
1.6k5 months ago
ESP-RFID-Tool preview

ESP-RFID-Tool

GitHubrfidtool/esp-rfid-tool

A tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed directly into an existing…

embedded-systems-securityfuzzinghardware-hacking+5
5803 years ago
nullinux preview

nullinux

GitHubm8sec/nullinux

Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through…

information-gatheringnetwork-securitypenetration-testing+1
5782 years ago
pymeta preview

pymeta

GitHubm8sec/pymeta

Utility to download and extract document metadata from an organization. This technique can be used to identify: domains, usernames, software/version…

information-gatheringosintpenetration-testing+1
5252 years ago
leprechaun preview

leprechaun

GitHubvonahisec/leprechaun

This tool is used to map out the network data flow to help penetration testers identify potentially valuable targets.

network-mappingpenetration-testingpost-exploitation+1
2454 years ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

penetration-testingreconnaissancescripting-automation+2
105 months ago
Freak-Scanner preview

Freak-Scanner

GitHubscottjpack/freak-scanner

Multithreaded FREAK scanner, used to detect SSL EXP Ciphers, vulnerable to CVE-2015-0204

information-gatheringnetwork-securitypenetration-testing+2
411 years ago
reverse-ip-new-api preview

reverse-ip-new-api

GitHubjenderal92/reverse-ip-new-api

This tool is used to perform reverse IP lookups— searching for all domains hosted on one IP address.

information-gatheringnetwork-mappingosint+1
32 months ago
shell-history-leaks preview

shell-history-leaks

GitHubcappricio-securities/shell-history-leaks

This tool is used to find shell history leaking

information-gatheringpenetration-testingreconnaissance+2
22 years ago
phpinfo-files-leaks preview

phpinfo-files-leaks

GitHubcappricio-securities/phpinfo-files-leaks

This tool is used to find php info page

information-gatheringmisconfigurationpenetration-testing+4
12 years ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
7 months ago
dr_robot preview
Archived

dr_robot

GitHubsandialabs/dr_robot

This tool can be used to enumerate the subdomains associated with a company by aggregating the results of multiple OSINT (Open Source Intelligence)…

container-securitydns-analysisdns-subdomain-enumeration+5
1433 years ago
parameth preview
Archived

parameth

GitHubmak-/parameth

This tool can be used to brute discover GET and POST parameters

information-gatheringpenetration-testingreconnaissance+3
1.4k6 years ago
spb preview

spb

GitHubiknowjason/spb

Shortest Path Bridging (SPB-Mac) vulnerability testing scripts. Used in a network pentest to enumerate a new vuln (CVE-2016-2783) in Avaya VOSS…

exploitationnetwork-securitypenetration-testing+3
27 years ago
Crips preview

Crips

GitHubmanisso/crips

IP Tools To quickly get information about IP Address's, Web Pages and DNS records.

dns-analysisinformation-gatheringnetwork-mapping+2
5018 years ago
Just-Metadata preview

Just-Metadata

GitHubredsiege/just-metadata

Just-Metadata is a tool that gathers and analyzes metadata about IP addresses. It attempts to find relationships between systems within a large…

information-gatheringosintreconnaissance+1
6337 years ago
Previous123456Next