Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
cangibrina preview

cangibrina

GitHubfnk0c/cangibrina

A fast and powerfull dashboard (admin) finder

information-gatheringreconnaissancevulnerability-scanners+1
239
7 years ago
ubuntu-privesc-lab preview

ubuntu-privesc-lab

GitHubvaibhavkrishna12004/ubuntu-privesc-lab

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

educationexploitationlabs-practice+8
5 months ago
Penetration-Testing-Walkthrough-Hacksudo-Thor preview

Penetration-Testing-Walkthrough-Hacksudo-Thor

GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

ctfeducationexploitation+8
4 months ago
py-network-scanner preview

py-network-scanner

GitHubanonymous121029034720384234234/py-network-scanner

Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and…

educationexploitationids-ips-evasion+6
111 months ago
hackerone preview

hackerone

GitHubbesioo/hackerone

Brute-force scraper for HackerOne disclosed reports via their public API, collecting report IDs, links, titles, and states for security research and…

educationinformation-gatheringosint+3
562 years ago
cve-2026-8697 preview

cve-2026-8697

GitHubitzmetanjim/cve-2026-8697

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

educationexploitationhardware-iot-security+7
13 months ago
subdomain3 preview

subdomain3

GitHubyanxiu0614/subdomain3

A new generation of tool for discovering subdomains( ip , cdn and so on)

dns-subdomain-enumerationinformation-gatheringpenetration-testing+1
7106 years ago
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.7k13h 21m ago
aiodnsbrute preview

aiodnsbrute

GitHubblark/aiodnsbrute

Python 3.5+ DNS asynchronous brute force utility

dns-subdomain-enumerationinformation-gatheringosint+3
6757 years ago
Bluto preview

Bluto

GitHubdarryllane/bluto

DNS Recon | Brute Forcer | DNS Zone Transfer | DNS Wild Card Checks | DNS Wild Card Brute Forcer | Email Enumeration | Staff Enumeration |…

dns-analysisdns-subdomain-enumerationemail-harvesting+3
6696 years ago
ridenum preview

ridenum

GitHubtrustedsec/ridenum

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

authenticationinformation-gatheringnetwork-security+3
3156 years ago
ScrapPY preview

ScrapPY

GitHubrosesecurity/scrappy

Python utility that scrapes PDFs to generate targeted wordlists for brute force, forced browsing, and dictionary attacks, with word frequency,…

information-gatheringpassword-attackspenetration-testing+2
2234 days ago
bofhound preview

bofhound

GitHubfortalice/bofhound

Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel

information-gatheringpenetration-testingreconnaissance
4102 years ago
BRC4-BOF-Artillery preview

BRC4-BOF-Artillery

GitHubparanoidninja/brc4-bof-artillery

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

command-and-controlencryption-decryption-toolshash-analysis+5
15210 months ago
lrs-pager-systems-bruteforce preview

lrs-pager-systems-bruteforce

GitHubjimilinuxguy/lrs-pager-systems-bruteforce

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

embedded-systems-securityexploitationhardware-hacking+4
523 years ago
vbrute preview

vbrute

GitHubnccgroup/vbrute

Virtual host brute forcer

information-gatheringnetwork-mappingreconnaissance+1
2212 years ago
hikvision_brute preview

hikvision_brute

GitHubnanotrash/hikvision_brute

Brute Hikvision CAMS with CVE-2021-36260 Exploit

exploitationiot-securitypassword-attacks+3
33 years ago
CVE-2024-53591 preview

CVE-2024-53591

GitHubaljoharasubaie/cve-2024-53591

Proof-of-concept for CVE-2024-53591, demonstrating domain enumeration via brute force on Seclore's login page to identify internal services.

information-gatheringpenetration-testingreconnaissance+2
1 year ago
Previous123Next