Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
naabu preview

naabu

GitHubprojectdiscovery/naabu

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

information-gatheringnetwork-mappingpenetration-testing+3
6.3k
3 days ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.9k4 days ago
CVE-2026-84434 preview

CVE-2026-84434

GitHubmurrez/cve-2026-84434

Python PoC scanner and exploit for CVE-2026-84434, an unauthenticated arbitrary file upload in Gravity Forms <=3.1.0.4 via hidden File Upload fields.…

exploitationpenetration-testingreconnaissance+5
5 days ago
RAGE preview

RAGE

GitHubtrustedsec/rage

Vendor-neutral NDJSON attack-graph format with node/edge taxonomy, AWS/GCP/Azure mappings, derivation rules, and an exposure DB for offensive…

cloud-securityconfiguration-auditingdefensive-tools+7
219 days ago
Empire preview

Empire

GitHubbc-security/empire

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

adversarial-attackcommand-and-controldata-exfiltration+16
5.3k16 days ago
TTPForge preview

TTPForge

GitHubfacebookincubator/ttpforge

The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).

adversarial-attackincident-responsepenetration-testing-frameworks+2
4441 month ago
overload preview
Archived

overload

GitHubgoncalopolido/overload

A network stress testing tool for simulating high traffic loads.

network-securitypenetration-testingred-teaming+2
4322 months ago
mapchar preview

mapchar

GitHubpwnfo/mapchar

Generate wordlists using pattern logic and expressions.

password-attackspassword-crackingpayload-generation+2
233 months ago
Pi-Zero-2W-Bad-USB preview

Pi-Zero-2W-Bad-USB

GitHubpsycostea/pi-zero-2w-bad-usb

Configure your Pi Zero 2W to be a BadUSB

ctfeducationembedded-systems-security+6
394 months ago
scan-shai-hulud preview

scan-shai-hulud

GitHubqi-scape/scan-shai-hulud

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

forensicsincident-responseioc-management+6
14 months ago
copy_fail_mitigation preview

copy_fail_mitigation

GitHubvorkampfer/copy_fail_mitigation

This script will attempt to mitigate the copy_fail attack. CVE-2026-31431

configuration-auditingdefensive-toolsscripting-automation+1
4 months ago
SecureOps-Lab preview

SecureOps-Lab

GitHubjdormannn/secureops-lab

Performed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force…

configuration-auditingeducationincident-response+5
5 months ago
AutoWIFI preview

AutoWIFI

GitHubmomenbasel/autowifi

Wireless penetration testing framework. Automates WPA/WPA2/WEP/WPS attacks - recon to exploitation in one command. aircrack-ng + hashcat + PMKID.

exploitationinformation-gatheringpassword-attacks+7
635 months ago
amass preview

amass

GitHubowasp-amass/amass

In-depth attack surface mapping and asset discovery

data-exfiltrationdns-analysisdns-fuzzing+10
15.2k5 months ago
burpflow preview

burpflow

GitHubcappricio-securities/burpflow

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

penetration-testingreconnaissancescripting-automation+2
116 months ago
Hash-Eye preview

Hash-Eye

GitHubishaklaz/hash-eye

**HashEye** is a powerful Python CLI tool for instantly detecting and analyzing hash types. It provides detailed information about hash formats,…

cryptographyhash-analysispassword-cracking+3
7 months ago
gaia preview

gaia

GitHuboksuzkayra/gaia

Attack surface discovery and AI-assisted triage for security researchers. Endpoint & parameter mapping with actionable testing hints.

ai-securitycrawlerinformation-gathering+7
468 months ago
BurpSuite-Grand-Master-Tools preview

BurpSuite-Grand-Master-Tools

GitHubnu11secur1ty/burpsuite-grand-master-tools

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

penetration-testingreconnaissancescripting-automation+3
210 months ago
Previous123Next