Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
437 results
CVE-2017-9798 preview
Archived

CVE-2017-9798

GitHubnitrado/cve-2017-9798

Checks a shared hosting environment for CVE-2017-9798

misconfigurationscripting-automationvulnerability-analysis+1
39 years ago
nginx-mitigate-log4shell preview

nginx-mitigate-log4shell

GitHubinfiniroot/nginx-mitigate-log4shell

Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script

defensive-toolsmisconfigurationscripting-automation+2
384 years ago
Fix-CVE-2021-44228 preview

Fix-CVE-2021-44228

GitHubalexandreheroux/fix-cve-2021-44228

Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/

misconfigurationscripting-automationsupply-chain-security+2
64 years ago
CVE-2024-3094-checker preview

CVE-2024-3094-checker

GitHubhazemkya/cve-2024-3094-checker

Bash script to detect and remediate CVE-2024-3094, a critical supply-chain vulnerability in the XZ Utils library, with automatic safe version…

misconfigurationscripting-automationsupply-chain-security+2
2 years ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1268 months ago
RatRace preview

RatRace

GitHubbogdanticu88/ratrace

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

api-security-testingdevsecopsexploitation+5
106 months ago
spiderfoot preview

spiderfoot

GitHubsmicallef/spiderfoot

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

dns-analysisemail-harvestinginformation-gathering+9
23.1k2 years ago
wuzz preview

wuzz

GitHubasciimoo/wuzz

Interactive cli tool for HTTP inspection

general-purpose-utilitiesscripting-automationweb-proxies-interception
10.7k2 months ago
h3-cli preview

h3-cli

GitHubhorizon3ai/h3-cli

CLI tool for the Horizon3.ai API

cloud-securitydevsecopspenetration-testing-frameworks+3
2614 days ago
ZX-DDoS preview

ZX-DDoS

GitHubmrgoofydev/zx-ddos

Python-based DDoS stress testing tool for educational and authorized network security evaluation, supporting configurable workers and request counts.

educationgeneral-purpose-utilitiesnetwork-security+3
5218 days ago
badger-builder preview

badger-builder

GitHubtw1sm/badger-builder

badger-builder is an AI-assisted tool for generating dynamic Brute Ratel C4 profiles

command-and-controlpayload-developmentred-teaming+1
541 year ago
afot preview

afot

GitHubharris21/afot

Automation Forensics Tool for Windows

digital-forensicsforensicshash-analysis+3
459 years ago
azpim preview

azpim

GitHubtapanmeena/azpim

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

authentication-authorizationcloud-infrastructure-securitycloud-security+3
77 months ago
F31 preview

F31

GitHubgmh5225/f31

Tool for hiding Kali Linux on the network

anti-botdefensive-toolsfingerprint-spoofing+6
32 years ago
CVE-2026-18351 preview

CVE-2026-18351

GitHubjohenlastgen-jlg/cve-2026-18351

Mass exploit tool for CVE-2026-18351, an unauthenticated arbitrary file upload to RCE in Elementor Forms <= 1.6.0, with passive probing, shell…

exploitationpayload-developmentpenetration-testing+5
127 days ago
UAP-protocol preview

UAP-protocol

GitHubrajsidwadkar/uap-protocol

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

api-securityauthentication-authorizationcloud-security+8
13 months ago
domain-enumeration-sicarius preview

domain-enumeration-sicarius

GitHubgmh5225/domain-enumeration-sicarius

Another tool for subdomain enumeration with some magics 🧙🏻‍♂️

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+5
3 years ago
CVE-2021-43798-Grafana-path-traversal-tester preview

CVE-2021-43798-Grafana-path-traversal-tester

GitHubelsanose01/cve-2021-43798-grafana-path-traversal-tester

Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.

exploitationpenetration-testingscripting-automation+4
1 year ago
Previous12…25Next