Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
112 results
CVE-1999-0524-POC preview

CVE-1999-0524-POC

GitHubbiontdv/cve-1999-0524-poc

Multi-threaded ICMP timestamp scanner that detects hosts vulnerable to CVE-1999-0524 by sending Type 13 requests and analyzing Type 14 replies,…

exploitationinformation-gatheringnetwork-security+3
1
1 month ago
Prommetrix preview

Prommetrix

GitHubepsylon/prommetrix

A utility for extracting system and application metrics from unprotected Prometheus Node Exporter HTTP endpoints, used to identify misconfigurations…

cloud-securityinformation-gatheringmisconfiguration+4
52 years ago
minipwner preview

minipwner

GitHubnicholasadamou/minipwner

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

exploitationids-ips-evasioninformation-gathering+8
731 year ago
citrixmash_scanner preview

citrixmash_scanner

GitHubawesome-security/citrixmash_scanner

A fast multi threaded scanner for Citrix ADC (NetScaler) CVE-2019-19781 - Citrixmash

exploitationids-ips-evasionpenetration-testing+3
6 years ago
Antecursor preview

Antecursor

GitLabantecursor/antecursor

Autonomous, modular open-hardware system for network reconnaissance, man-in-the-middle data collection, and automated exploitation with remote C2…

command-and-controlexploitationhardware-iot-security+5
57 years ago
SystemVulnerabilityChecklist_Project4_Decodelabs preview

SystemVulnerabilityChecklist_Project4_Decodelabs

GitHubirsaattiquecyber/systemvulnerabilitychecklist_project4_decodelabs

System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active…

configuration-auditingeducationlabs-practice+5
24 days ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
38.9k17h 30m ago
pentagi preview

pentagi

GitHubvxcontrol/pentagi

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

ai-securityeducationexploit-frameworks+6
22.0k19 days ago
Seatbelt preview

Seatbelt

GitHubghostpack/seatbelt

C# host-survey tool for offensive and defensive security, performing extensive safety checks on Windows systems including user, system, and network…

defensive-toolsinformation-gatheringpenetration-testing+6
4.7k1 year ago
RootHelper preview

RootHelper

GitHubnullarray/roothelper

A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.

exploitationinformation-gatheringpayload-generation+6
5055 years ago
PXEThief preview

PXEThief

GitHubmwr-cybersec/pxethief

Toolset for extracting credentials from Microsoft ConfigMgr/SCCM Operating System Deployment via PXE boot attacks, including password cracking,…

exploitationinformation-gatheringpassword-attacks+5
4342 years ago
Zetsu preview

Zetsu

GitHubchaelsoo/zetsu

A personal RAG system for offensive security knowledge

educationexploitationinformation-gathering+8
17613 days ago
RadareEye preview

RadareEye

GitHubsouravbaghz/radareeye

Tool for especially scanning nearby devices and execute a given command on its own system while the target device comes in range.

bluetooth-securityiot-securityreconnaissance+3
3844 years ago
Wonka preview

Wonka

GitHubshac0x/wonka

Windows tool for extracting Kerberos tickets from the LSA cache, supporting SYSTEM impersonation, session discovery, and targeted ticket dumping for…

authenticationinformation-gatheringpenetration-testing+3
1752 months ago
Syborg preview

Syborg

GitHubmilindpurswani/syborg

Recursive DNS Subdomain Enumerator with dead-end avoidance system (BETA)

dns-analysisdns-subdomain-enumerationinformation-gathering+1
1465 years ago
sccm-http-looter preview

sccm-http-looter

GitHubbadsectorlabs/sccm-http-looter

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

data-exfiltrationinformation-gatheringmisconfiguration+3
2161 year ago
OneLogicalMyth_Shell preview

OneLogicalMyth_Shell

GitHubnccgroup/onelogicalmyth_shell

HTA-based post-exploitation shell for breakout assessments. Provides file explorer, system reconnaissance, AD enumeration, and file transfer…

command-and-controldata-exfiltrationpenetration-testing+3
1114 years ago
Enumprotections_BOF preview

Enumprotections_BOF

GitHuboctoberfest7/enumprotections_bof

A BOF to enumerate system process, their protection levels, and more.

information-gatheringpenetration-testingpost-exploitation+4
1261 year ago
Previous1234567Next