Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
282 results
pwninit preview

pwninit

GitHubio12/pwninit

Automates setup of binary exploitation challenges by patching ELF binaries, fetching matching linkers, unstripping libc, and generating pwntools…

binary-exploitationctfexploitation+2
1.1k
1 month ago
CVE-2018-15473-Exploit preview

CVE-2018-15473-Exploit

GitHubrhynorater/cve-2018-15473-exploit

Exploit written in Python for CVE-2018-15473 with threading and export formats

exploitationinformation-gatheringpenetration-testing+3
5342 years ago
vt-py preview

vt-py

GitHubvirustotal/vt-py

The official Python 3 client library for VirusTotal

information-gatheringmalware-analysisscripting-automation+2
78110 months ago
exploit-writing-for-oswe preview

exploit-writing-for-oswe

GitHubrizemon/exploit-writing-for-oswe

Tips on how to write exploit scripts (faster!)

curated-resourceseducationpayload-development+4
5992 years ago
chomp-scan preview

chomp-scan

GitHubsolomonsklash/chomp-scan

A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.

dns-analysisinformation-gatheringpenetration-testing+6
3946 years ago
quiver preview

quiver

GitHubstevemcilwain/quiver

Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.

exploitationinformation-gatheringpenetration-testing+4
2166 years ago
paragon preview

paragon

GitHubkcarretto/paragon

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

command-and-controlexploit-frameworkspayload-development+4
3042 years ago
aardwolf preview

aardwolf

GitHubskelsec/aardwolf

Asynchronous RDP client for Python (headless)

authenticationinformation-gatheringlateral-movement+5
23921 days ago
Hacknetics preview

Hacknetics

GitHubice-wzl/hacknetics

Contained is all my reference material for my OSCP / Red Teaming. Designed to be a one stop shop for code, guides, command syntax, and high level…

curated-resourceseducationlearning-paths-courses+3
1161 month ago
Reconky-Automated_Bash_Script preview

Reconky-Automated_Bash_Script

GitHubshivamrai2003/reconky-automated_bash_script

Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which…

information-gatheringosintpenetration-testing+5
2043 years ago
autopwn preview

autopwn

GitHubnccgroup/autopwn

Specify targets and run sets of tools against them

penetration-testingpenetration-testing-frameworksreconnaissance+2
3887 years ago
AggressorAssessor preview

AggressorAssessor

GitHubredsiege/aggressorassessor

Aggressor scripts for phases of a pen test or red team assessment

information-gatheringpenetration-testingreconnaissance+3
1832 years ago
pown preview

pown

GitHubpownjs/pown

Pown.js is a security testing an exploitation toolkit built on top of Node.js and NPM.

exploit-frameworkspenetration-testing-frameworksscripting-automation+1
2603 years ago
harpoon preview

harpoon

GitHubprofessionallyevil/harpoon

A collection of scripts, and tips and tricks for hacking k8s clusters and containers.

cloud-securitycontainer-securityexploitation+5
1451 year ago
bashacks preview

bashacks

GitHubmerces/bashacks

A set of functions to increase productivity while hacking with Bash

encryption-decryption-toolsgeneral-purpose-utilitieshash-analysis+3
2115 months ago
powerob preview

powerob

GitHubcwolff411/powerob

An on-the-fly Powershell script obfuscator meant for red team engagements. Built out of necessity.

payload-generationpenetration-testingred-teaming+1
1454 years ago
BYOSI preview

BYOSI

GitHuboldkingcone/byosi

Evade EDR's the simple way, by not touching any of the API's they hook.

payload-generationpenetration-testingred-teaming+1
1962 months ago
Kali-Setup preview

Kali-Setup

GitHubraikia/kali-setup

Script for Kali that adds a bunch of tools and customizes it to be much better

penetration-testingscripting-automationutilities-frameworks
1905 years ago
Previous1234…16Next