Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
97 results
JKS-private-key-cracker-hashcat preview

JKS-private-key-cracker-hashcat

GitHubfloyd-fuh/jks-private-key-cracker-hashcat

Nail in the JKS coffin - Cracking passwords of private key entries in a JKS file

cryptographypassword-crackingvulnerability-analysis
188
6 years ago
Kousei preview

Kousei

GitHubnu11secur1ty/kousei

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

exploitationpassword-crackingpayload-generation+6
38 days ago
lil-pwny preview

lil-pwny

GitHubpapermtn/lil-pwny

Fast offline auditing of Active Directory passwords using Python.

authenticationpassword-crackingvulnerability-analysis
1672 years ago
hashID preview

hashID

GitHubpsypanda/hashid

Software to identify the different types of hashes -

forensicshash-analysisinformation-gathering+3
1.5k11 years ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubnaxg/cve-2020-1472

CVE-2020-1472复现流程

exploitationpassword-crackingpenetration-testing+3
45 years ago
CVE-2020-15367 preview

CVE-2020-15367

GitHubinflixim4be/cve-2020-15367

Exploit for CVE-2020-15367: brute-force authentication attack against Venki Supravizio BPM 10.1.2 login page, leveraging user enumeration to gain…

authenticationexploitationpassword-attacks+2
6 years ago
py3webfuzz preview

py3webfuzz

GitHubjangelesg/py3webfuzz

A Python3 module to assist in fuzzing web applications

fuzzingpayload-generationpenetration-testing+2
572 years ago
munin preview

munin

GitHubneo23x0/munin

Online hash checker for Virustotal and other services

hash-analysisinformation-gatheringmalware-analysis+3
85617 days ago
BruteForce-to-KeePass preview

BruteForce-to-KeePass

GitHubund3sc0n0c1d0/bruteforce-to-keepass

This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting…

exploitationpassword-crackingpenetration-testing+1
63 years ago
CVE-2024-39211 preview

CVE-2024-39211

GitHubartemy-ccrsky/cve-2024-39211

User Enumeration vulnerability in Kaiten (workflow management system)

information-gatheringosintpassword-attacks+3
71 year ago
CVE-2026-77771 preview

CVE-2026-77771

GitHubpervinzahidli/cve-2026-77771

Advisory for CVE-2026-77771, a 2FA bypass in the miniOrange WordPress plugin via session-scoped OTP lockout, with impact analysis and remediation…

authenticationdefensive-toolseducation+2
27 days ago
ubuntu-privesc-lab preview

ubuntu-privesc-lab

GitHubvaibhavkrishna12004/ubuntu-privesc-lab

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

educationexploitationlabs-practice+8
6 months ago
icebreaker preview

icebreaker

GitHubdanmcinerney/icebreaker

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

password-crackingpenetration-testingpost-exploitation+3
1.2k7 years ago
sarenka preview

sarenka

GitHubktzgraph/sarenka

OSINT tool - gets data from services like shodan, censys etc. in one app

crawlerdns-analysishash-analysis+4
6744 years ago
stegcrack preview

stegcrack

GitHubb4shfire/stegcrack

Exploit script for CVE-2021-27211

binary-analysiscryptographyexploitation+3
64 years ago
patator preview

patator

GitHublanjelot/patator

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

authenticationdns-analysishash-analysis+6
3.9k1 year ago
cisco-SNMP-enumeration preview

cisco-SNMP-enumeration

GitHubnccgroup/cisco-snmp-enumeration

Automated Cisco SNMP Enumeration, Brute Force, Configuration Download and Password Cracking

configuration-auditinginformation-gatheringnetwork-security+3
22610 years ago
CVE-2024-4956 preview

CVE-2024-4956

GitHubfin3ss3g0d/cve-2024-4956

Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

exploitationhash-analysispassword-cracking+3
91 year ago
Previous123456Next