Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
226 results
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
126
13 years ago
ThreatLens preview

ThreatLens

GitHubabdaullahag/threatlens

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

defensive-toolsincident-responseinformation-gathering+7
2522 days ago
Cortex preview

Cortex

GitHubthehive-project/cortex

Cortex: a Powerful Observable Analysis and Active Response Engine

digital-forensicsincident-responseinformation-gathering+5
1.6k3 months ago
XXERipper preview

XXERipper

GitHubkamalx06/xxeripper

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

api-security-testingdata-exfiltrationexploitation+9
1114 days ago
ruby-nmap preview

ruby-nmap

GitHubpostmodern/ruby-nmap

A Ruby interface to nmap, the exploration tool and security / port scanner. Allows automating nmap and parsing nmap XML files.

information-gatheringnetwork-mappingport-scanning+3
2989 months ago
Quickcheck-CVE-2025-55182-React-and-CVE-2025-66478-Next.js preview

Quickcheck-CVE-2025-55182-React-and-CVE-2025-66478-Next.js

GitHubbankkroll/quickcheck-cve-2025-55182-react-and-cve-2025-66478-next.js

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

code-analysisexploitationinformation-gathering+3
1210 months ago
GETROBARB preview

GETROBARB

GitHubhackingteamoficial/getrobarb

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

crawlerdns-analysisinformation-gathering+7
91 month ago
nmap preview

nmap

GitHubnmap/nmap

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

bluetooth-securitydatabase-securitydata-exfiltration+18
13.7k15h 7m ago
Halcyon-IDE preview

Halcyon-IDE

GitHubs4n7h0/halcyon-ide

First IDE for Nmap Script (NSE) Development.

network-securityscripting-automationutilities-frameworks+1
3596 years ago
gaia preview

gaia

GitHuboksuzkayra/gaia

Attack surface discovery and AI-assisted triage for security researchers. Endpoint & parameter mapping with actionable testing hints.

ai-securitycrawlerinformation-gathering+7
469 months ago
spoonmap preview

spoonmap

GitHubtrustedsec/spoonmap

Python wrapper around masscan and nmap for large-scale port discovery, host discovery, banner grabbing, and NSE-based vulnerability scanning across…

defensive-toolsinformation-gatheringnetwork-mapping+7
2088 days ago
ranwhat preview

ranwhat

GitHubmatijamiki/ranwhat

Flight recorder and secret scanner for AI coding agents. Reads what Claude Code, Codex, Gemini CLI and 9 more ran, and flags risky actions and leaked…

ai-securitydefensive-toolsidentity-management+7
13 days ago
CVE-2026-101110 preview

CVE-2026-101110

GitHubmurrez/cve-2026-101110

Python 3 PoC and mass exploit for CVE-2026-101110, an unauthenticated ORDER BY SQL injection in OrdaSoft Joomla Book Library <=6.4.6 via…

exploitationinformation-gatheringpenetration-testing+6
11 days ago
dj preview

dj

GitHubejfkdev/dj

Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source…

anti-botcrawlerfingerprint-spoofing+7
6011 days ago
celerystalk preview
Archived

celerystalk

GitHubsethsec/celerystalk

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

crawlerdns-subdomain-enumerationinformation-gathering+8
4005 years ago
LangAlpha preview

LangAlpha

GitHubginlix-ai/langalpha

Automated OSINT framework for reconnaissance, data harvesting, and threat intelligence gathering with modular crawlers, scanners, and extraction…

crawlerdata-exfiltrationinformation-gathering+6
1.8k11h 55m ago
HingeSDK preview

HingeSDK

GitHubreedgraff/hingesdk

Hinge Dating App SDK for python for lonely bored SWEs

crawlerdata-exfiltrationinformation-gathering+4
11810 months ago
RAGE preview

RAGE

GitHubtrustedsec/rage

Vendor-neutral NDJSON attack-graph format with node/edge taxonomy, AWS/GCP/Azure mappings, derivation rules, and an exposure DB for offensive…

cloud-securityconfiguration-auditingdefensive-tools+7
2224 days ago
Previous12…13Next