Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
local-mcp preview

local-mcp

GitHubfan-67/local-mcp

A lightweight stdio-based MCP server for local file system operations — read, write, edit, search, exec for AI assistants. Specially optimized for…

exploitationgeneral-purpose-utilitiesscripting-automation+2
3 months ago
CVE-2024-3094-Checker preview

CVE-2024-3094-Checker

GitHubthetorjancaptain/cve-2024-3094-checker

The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.

configuration-auditinggeneral-purpose-utilitiesscripting-automation+2
2 years ago
metashield-clean-up-sdk-python preview

metashield-clean-up-sdk-python

GitHubelevenpaths/metashield-clean-up-sdk-python

Python SDK for removing hidden metadata from files (PDF, Office, images) to protect privacy and prevent data leakage via automated cleaning workflows.

data-recoveryprivacyscripting-automation+1
28 years ago
Interlace preview

Interlace

GitHubcodingo/interlace

Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.

penetration-testingreconnaissancescripting-automation+1
1.3k1 year ago
chomp-scan preview

chomp-scan

GitHubsolomonsklash/chomp-scan

A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.

dns-analysisinformation-gatheringpenetration-testing+6
3946 years ago
Stracciatella preview

Stracciatella

GitHubmgeeky/stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

command-and-controlexploit-frameworksids-ips-evasion+7
5444 years ago
decker preview

decker

GitHubstevenaldinger/decker

Declarative penetration testing orchestration framework

exploit-frameworksinformation-gatheringpenetration-testing-frameworks+3
2967 years ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubtiktb8/cve-2022-29072

Powershell to mitigate CVE-2022-29072

defensive-toolsexploitationincident-response+2
64 years ago
Fix-WinVerifyTrustSignatureValidationVuln preview

Fix-WinVerifyTrustSignatureValidationVuln

GitHubcybercondor/fix-winverifytrustsignaturevalidationvuln

Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332

configuration-auditinggeneral-purpose-utilitiesmisconfiguration+2
33 years ago
log4j-fix-CVE-2021-44228 preview

log4j-fix-CVE-2021-44228

GitHubchandru-gunasekaran/log4j-fix-cve-2021-44228

Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228

general-purpose-utilitiesmisconfigurationscripting-automation+2
24 years ago
React2Shell-CVE-2025-55182-Detector preview

React2Shell-CVE-2025-55182-Detector

GitHubgarethmsheldon/react2shell-cve-2025-55182-detector

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

code-analysisscripting-automationsupply-chain-security+3
19 months ago
Automate_Exploit_CVE-2022-44268 preview

Automate_Exploit_CVE-2022-44268

GitHubj0ey17/automate_exploit_cve-2022-44268

An exploit automation script that builds upon the work of Voidzone security.

data-exfiltrationexploitationpenetration-testing+3
1 year ago
Aggressor-Aggregator preview

Aggressor-Aggregator

GitHubgmh5225/aggressor-aggregator

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

penetration-testing-frameworksred-teamingscripting-automation
2 years ago
log4v-vuln-check preview

log4v-vuln-check

GitHubrv4l3r3/log4v-vuln-check

This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).

information-gatheringlog-analysisport-scanning+3
4 years ago
CVE-2021-44228---detection-with-PowerShell preview

CVE-2021-44228---detection-with-PowerShell

GitHubintel-xeon/cve-2021-44228---detection-with-powershell

PowerShell-based scanner to detect Log4j CVE-2021-44228 vulnerability by searching directories and log files for exploitation indicators.

information-gatheringlog-analysisscripting-automation+2
4 years ago
dpapi-toolkit preview

dpapi-toolkit

GitHubcrypt0p3g/dpapi-toolkit

Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI +…

digital-forensicsencryption-decryption-toolsforensics+7
173 days ago
CVE-2017-9798 preview
Archived

CVE-2017-9798

GitHubnitrado/cve-2017-9798

Checks a shared hosting environment for CVE-2017-9798

misconfigurationscripting-automationvulnerability-analysis+1
39 years ago
ir-rescue preview

ir-rescue

GitHubdiogo-fernan/ir-rescue

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

digital-forensicsdisk-forensicsforensics+6
4885 years ago
Previous1234Next