Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
oversight preview

oversight

GitHubrakosn1cek/oversight

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

code-analysisdevsecopsdynamic-analysis-sandboxing+7
39
1 month ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubgrupooruss/cve-2024-6387

Python script to scan and secure SSH configurations against the CVE-2024-6387 race condition vulnerability, with automated LoginGraceTime adjustment…

configuration-auditingnetwork-securitypenetration-testing+3
22 years ago
CVE-2024-3094-checker preview

CVE-2024-3094-checker

GitHubhazemkya/cve-2024-3094-checker

Bash script to detect and remediate CVE-2024-3094, a critical supply-chain vulnerability in the XZ Utils library, with automatic safe version…

misconfigurationscripting-automationsupply-chain-security+2
2 years ago
CVE-2023-26209 preview

CVE-2023-26209

GitHubchessredoffsec/cve-2023-26209

Python script with a Tkinter GUI for sending automated payloads of configurable size to a login endpoint, designed for educational testing of server…

educationexploitationpenetration-testing+3
1 year ago
CVE-2023-26208 preview

CVE-2023-26208

GitHubchessredoffsec/cve-2023-26208

Python script with GUI for automated payload testing against login endpoints, designed for educational exploitation simulation and vulnerability…

educationexploitationpenetration-testing+3
11 year ago
CVE-2022-29056 preview

CVE-2022-29056

GitHubchessredoffsec/cve-2022-29056

Automated Python script with GUI for testing login endpoint responses with configurable payload sizes, designed for educational security testing and…

educationexploitationpenetration-testing+2
11 year ago
OpenSSH-CVE-2024-6387-Fix preview

OpenSSH-CVE-2024-6387-Fix

GitHubalmogopp/openssh-cve-2024-6387-fix

A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary…

cloud-securityconfiguration-auditingdevsecops+3
2 years ago
wordreaper preview

wordreaper

GitHubnemorous/wordreaper

📜 Scrape targeted wordlists for password cracking using CSS selectors

crawlerctfinformation-gathering+5
514 months ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1217 months ago
NotaMy preview

NotaMy

GitHubimprojtech/notamy

Terminal-based note manager with hierarchical tagging and file linking

educationinformation-gatheringpenetration-testing+3
116 months ago
raspberrypi-setup preview

raspberrypi-setup

GitHubatao/raspberrypi-setup

Ansible playbook for rapid Raspberry Pi setup with modular roles for wireless security testing, RFID/NFC tools, SDR, Docker, Tor proxy, and standard…

general-purpose-utilitieshardware-iot-securityrfid-nfc-tools+2
537 days ago
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
12713 years ago
scant3r preview

scant3r

GitHubmindpatch/scant3r

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…

penetration-testingscripting-automationvulnerability-scanners+2
6863 days ago
Hacknetics preview

Hacknetics

GitHubice-wzl/hacknetics

Contained is all my reference material for my OSCP / Red Teaming. Designed to be a one stop shop for code, guides, command syntax, and high level…

curated-resourceseducationlearning-paths-courses+3
11323 days ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.0k1 month ago
naabu preview

naabu

GitHubprojectdiscovery/naabu

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

information-gatheringnetwork-mappingpenetration-testing+3
6.2k2 days ago