Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
macro_pack preview
Archived

macro_pack

GitHubsevagas/macro_pack

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

exploit-frameworkslateral-movementpayload-generation+6
2.3k
2 years ago
ptf preview

ptf

GitHubtrustedsec/ptf

The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.

exploit-frameworkspenetration-testing-frameworksscripting-automation+1
5.6k1 year ago
htbenum preview

htbenum

GitHubsolomonsklash/htbenum

A Linux enumeration script for Hack The Box

exploit-frameworksinformation-gatheringpenetration-testing+2
1926 years ago
pown preview

pown

GitHubpownjs/pown

Pown.js is a security testing an exploitation toolkit built on top of Node.js and NPM.

exploit-frameworkspenetration-testing-frameworksscripting-automation+1
2603 years ago
decker preview

decker

GitHubstevenaldinger/decker

Declarative penetration testing orchestration framework

exploit-frameworksinformation-gatheringpenetration-testing-frameworks+3
2967 years ago
wordpress-php-object-helper preview

wordpress-php-object-helper

GitHubrandomrobbiebf/wordpress-php-object-helper

Know a plugin has a php object exploit but need to find which lib to use?

exploit-frameworkspenetration-testingreconnaissance+3
33 years ago
URS preview

URS

GitHubjosephlai241/urs

Universal Reddit Scraper - A comprehensive Reddit scraping/archival command-line tool.

crawlerinformation-gatheringosint+1
1.0k1 month ago
SharePointSecurityMonitor preview

SharePointSecurityMonitor

GitHubpaolokappa/sharepointsecuritymonitor

A comprehensive PowerShell-based SharePoint security monitoring solution with CVE-2025-53770 protection, advanced DLL analysis, threat detection, and…

cloud-securityconfiguration-auditingforensics+8
11 year ago
CTF-Web-Exploitation preview

CTF-Web-Exploitation

GitHubarnavps/ctf-web-exploitation

A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced…

container-securityctfeducation+8
14 months ago
dromara__hutool_CVE-2018-17297_4-1-1111 preview

dromara__hutool_CVE-2018-17297_4-1-1111

GitHubshoucheng3/dromara__hutool_cve-2018-17297_4-1-1111

Comprehensive Java utility library providing modules for cryptography, HTTP client, caching, JSON, scripting, and captcha generation, simplifying…

captcha-bypasscryptographyencryption-decryption-tools+3
1 year ago
cve-2024-41110-checker preview

cve-2024-41110-checker

GitHubvvpoglazov/cve-2024-41110-checker

Parallel SSH-based scanner that detects CVE-2024-41110 in Docker installations, identifies vulnerable versions and AuthZ plugins, and generates a…

cloud-infrastructure-securityconfiguration-auditingcontainer-security+2
62 years ago
nebula preview

nebula

GitHubberylliumsec/nebula

AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.

ai-securityexploit-frameworksinformation-gathering+5
1.1k0 days ago
ezsploit preview

ezsploit

GitHubrand0m1ze/ezsploit

Linux bash script automation for metasploit

command-and-controlexploit-frameworkspayload-development+5
26910 years ago
Stracciatella preview

Stracciatella

GitHubmgeeky/stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

command-and-controlexploit-frameworksids-ips-evasion+7
5423 years ago
paragon preview

paragon

GitHubkcarretto/paragon

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

command-and-controlexploit-frameworkspayload-development+4
3042 years ago
msf-remote-console preview
Archived

msf-remote-console

GitHubqubasa/msf-remote-console

A remote msfconsole written in Python 2.7 to connect to the msfrcpd server of metasploit. This tool gives you the ability to load modules permanently…

command-and-controlexploit-frameworkspayload-development+3
577 years ago