Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
264 results
dpapi-toolkit preview

dpapi-toolkit

GitHubcrypt0p3g/dpapi-toolkit

Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI +…

digital-forensicsencryption-decryption-toolsforensics+7
28
8 days ago
evillimiter-ng preview

evillimiter-ng

GitHubkevincrrl/evillimiter-ng

EvilLimiter Next Generation: monitor, analyze and limit the bandwidth

information-gatheringnetwork-mappingnetwork-security+3
33 days ago
TransparentTorProxy preview

TransparentTorProxy

GitHubonyks-os/transparenttorproxy

A Linux CLI utility that transparently routes all system traffic through the Tor network using nftables. It enables rapid IP rotation and easy…

command-and-controldefensive-toolsdns-analysis+6
442 days ago
Oihk-pentesting preview

Oihk-pentesting

GitHubbroskigx/oihk-pentesting

Autonomous multi-agent AI penetration-testing engine: a governed tool sandbox, an immutable evidence-and-validation gate, and a reproducible…

ai-securityeducationexploit-frameworks+7
45 days ago
CVE-Exploit-Research-Development preview

CVE-Exploit-Research-Development

GitHubfaizanali8232/cve-exploit-research-development

A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with…

command-and-controleducationexploitation+6
6 months ago
CVE-2026-89274 preview

CVE-2026-89274

GitHubmurrez/cve-2026-89274

Python PoC scanner and exploit for CVE-2026-89274, an unauthenticated arbitrary shortcode execution flaw in WP Recipe Maker <=10.8.1 via recipe…

exploitationpenetration-testingscripting-automation+4
212 days ago
CVE-2026-92229 preview

CVE-2026-92229

GitHubmurrez/cve-2026-92229

Python 3 PoC scanner and exploit for CVE-2026-92229, an unauthenticated arbitrary shortcode execution flaw in Forminator WordPress plugin versions…

exploitationpenetration-testingscripting-automation+4
512 days ago
ZX-DDoS preview

ZX-DDoS

GitHubmrgoofydev/zx-ddos

Python-based DDoS stress testing tool for educational and authorized network security evaluation, supporting configurable workers and request counts.

educationgeneral-purpose-utilitiesnetwork-security+3
5112 days ago
CVE-2021-43798-Grafana-path-traversal-tester preview

CVE-2021-43798-Grafana-path-traversal-tester

GitHubelsanose01/cve-2021-43798-grafana-path-traversal-tester

Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.

exploitationpenetration-testingscripting-automation+4
1 year ago
Grafana-Plugin-Enumerator-CVE-2021-43798 preview

Grafana-Plugin-Enumerator-CVE-2021-43798

GitHubsqu1shification/grafana-plugin-enumerator-cve-2021-43798

Bash-based scanner that enumerates Grafana plugin IDs and tests for CVE-2021-43798 directory traversal by attempting to read /etc/passwd or win.ini…

exploitationinformation-gatheringpenetration-testing+4
14 days ago
F31 preview

F31

GitHubgmh5225/f31

Tool for hiding Kali Linux on the network

anti-botdefensive-toolsfingerprint-spoofing+6
32 years ago
Agent-Reach preview

Agent-Reach

GitHubpanniantong/agent-reach

Give your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.

ai-securitycrawlergeneral-purpose-utilities+5
87.0k16 days ago
CanoP preview

CanoP

GitHubopenbreach/canop

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

ai-securitycode-analysisdefensive-tools+7
418 days ago
ADRecon preview

ADRecon

GitHubadrecon/adrecon

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

defensive-toolsdigital-forensicsincident-response+6
9831 year ago
CVE-2026-80099 preview

CVE-2026-80099

GitHubwayang1337/cve-2026-80099

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

exploitationinformation-gatheringpassword-attacks+7
119 days ago
ThreatLens preview

ThreatLens

GitHubabdaullahag/threatlens

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

defensive-toolsincident-responseinformation-gathering+7
2513 days ago
domain-enumeration-sicarius preview

domain-enumeration-sicarius

GitHubgmh5225/domain-enumeration-sicarius

Another tool for subdomain enumeration with some magics 🧙🏻‍♂️

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+5
3 years ago
CVE-2026-18351 preview

CVE-2026-18351

GitHubjohenlastgen-jlg/cve-2026-18351

Mass exploit tool for CVE-2026-18351, an unauthenticated arbitrary file upload to RCE in Elementor Forms <= 1.6.0, with passive probing, shell…

exploitationpayload-developmentpenetration-testing+5
121 days ago
Previous12…15Next