Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
282 results
dumper preview

dumper

GitHubelkirrs/dumper

CLI utility for creating encrypted database backups (PostgreSQL, MySQL, MongoDB) with support for multiple storage backends (SFTP, S3, Azure), SSH…

cloud-securitydata-recoveryencryption-decryption-tools+2
87
6 months ago
vbsmin preview

vbsmin

GitHubnoraj/vbsmin

VBScript minifier

payload-generationscripting-automationweb-application-exploitation
258 days ago
anubis-fetch preview

anubis-fetch

GitHubfzakaria/anubis-fetch

Like curl, but it gets past Anubis and Cloudflare bot-walls.

anti-botfingerprint-spoofingscripting-automation+3
321 month ago
exocomp preview

exocomp

GitHubcookiengineer/exocomp

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

ai-securitycode-analysiseducation+8
1619h 48m ago
CVE-2018-2628-MultiThreading preview

CVE-2018-2628-MultiThreading

GitHubaedoo/cve-2018-2628-multithreading

WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreading

exploitationinformation-gatheringpenetration-testing+3
158 years ago
kali-preseed-examples preview

kali-preseed-examples

GitLabkalilinux/recipes/kali-preseed-examples

Preseed configuration examples and guides for automated, hands-off Kali Linux installation, including partitioning, package selection, and boot…

curated-resourceseducationscripting-automation
211 year ago
pmg preview

pmg

GitHubmindpatch/pmg

Extract parameters/paths from urls

information-gatheringreconnaissancescripting-automation+2
176 years ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
71 month ago
API-SPY-API-PROBE preview

API-SPY-API-PROBE

GitHubaustinjump-sec/api-spy-api-probe

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

api-security-testingcrawlerinformation-gathering+4
53 months ago
RatRace preview

RatRace

GitHubbogdanticu88/ratrace

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

api-security-testingdevsecopsexploitation+5
104 months ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubtiktb8/cve-2022-29072

Powershell to mitigate CVE-2022-29072

defensive-toolsexploitationincident-response+2
64 years ago
alexafaraday preview

alexafaraday

GitHubinfobyte/alexafaraday

Alexa skill example for Faraday API

api-security-testingpenetration-testingscripting-automation+2
57 years ago
MCPwnfluence preview

MCPwnfluence

GitHubplutosecurity/mcpwnfluence

Information about CVE-2026-27825 & CVE-2026-27826 discovered by Pluto Security and a bash script for identifying vulnerable mcp-atlassian instances…

configuration-auditingdevsecopseducation+3
76 months ago
cve-2022-42889-jmeter preview

cve-2022-42889-jmeter

GitHubqainsights/cve-2022-42889-jmeter

Script to handle CVE 2022-42889

general-purpose-utilitiesscripting-automationsupply-chain-security+1
73 years ago
cve-2024-41110-checker preview

cve-2024-41110-checker

GitHubvvpoglazov/cve-2024-41110-checker

Parallel SSH-based scanner that detects CVE-2024-41110 in Docker installations, identifies vulnerable versions and AuthZ plugins, and generates a…

cloud-infrastructure-securityconfiguration-auditingcontainer-security+2
62 years ago
CVE-2024-3094 preview

CVE-2024-3094

GitHubyuma-tsushima07/cve-2024-3094

A script to detect if xz is vulnerable - CVE-2024-3094

general-purpose-utilitiesmisconfigurationscripting-automation+2
42 years ago
CVE-2018-19788 preview

CVE-2018-19788

GitHubd4gh0s7/cve-2018-19788

Ansible role to audit and test systems for CVE-2018-19788 (PolicyKit privilege escalation) with automated user provisioning and exploit verification.

configuration-auditingexploitationpenetration-testing+3
37 years ago
ban-exploitable-bitcoin-nodes preview

ban-exploitable-bitcoin-nodes

GitHubiioch/ban-exploitable-bitcoin-nodes

Ban all denial-of-service vulnerability exploitable nodes from your node CVE-2018-17144

defensive-toolsgeneral-purpose-utilitiesnetwork-security+2
27 years ago
Previous1…91011…16Next