Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
794 results
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

api-securityapi-security-testingcrawler+12
16.8k9 days ago
zipbrk preview

zipbrk

GitHubkvesel/zipbrk

Zip file format fuzzer and multi-tool.

binary-analysiscryptographyencryption-decryption-tools+4
124 months ago
zip-shotgun preview

zip-shotgun

GitHubjpiechowka/zip-shotgun

Utility script to test zip file upload functionality (and possible extraction of zip files) for vulnerabilities (aka Zip Slip)

payload-generationpenetration-testingvulnerability-analysis+1
337 years ago
static-analysis preview

static-analysis

GitHubanalysis-tools-dev/static-analysis

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

code-analysiscurated-resourcesdevsecops+5
14.8k14 days ago
ludus_crushftp_cve-2025-31161_sim preview

ludus_crushftp_cve-2025-31161_sim

GitHubrufflabs/ludus_crushftp_cve-2025-31161_sim

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

ctfeducationexploitation+5
3 months ago
CVE-2024-52510 preview

CVE-2024-52510

GitHubd-xuan/cve-2024-52510

Proof-of-concept exploit for CVE-2024-52510 demonstrating signature bypass in Nextcloud's E2EEv2 protocol, enabling server-side decryption of…

cloud-securitycryptographyencryption-decryption-tools+3
22 years ago
CVE-2026-34990-poc preview

CVE-2026-34990-poc

GitHub0xc4rc3l/cve-2026-34990-poc

Python PoC reproducing the CUPS 2.4.16 local-printer flaw: captures the Local auth token via a rogue IPP endpoint, creates a file:// printer, and…

defensive-toolsexploitationpenetration-testing+2
18 days ago
IPA preview

IPA

GitHubseekbytes/ipa

GUI analyzer for deep-diving into PDF files. Detect malicious payloads, understand object relationships, and extract key information for threat…

binary-analysisdefensive-toolsdigital-forensics+6
8822 years ago
IntelOwl preview

IntelOwl

GitHubintelowlproject/intelowl

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

curated-resourcesdigital-forensicsdynamic-analysis-sandboxing+14
4.7k1 month ago
so-crates preview

so-crates

GitHubdougburks/so-crates

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

container-securitydigital-forensicseducation+8
6157 days ago
ics-forensics-tools preview

ics-forensics-tools

GitHubmicrosoft/ics-forensics-tools

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

digital-forensicsforensicsincident-response+2
3741 year ago
apkprobe preview

apkprobe

GitHubwadingporque/apkprobe

APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

android-securityinformation-gatheringmobile-security+5
510 months ago
ndaal_public_SBOM_Auditor preview

ndaal_public_SBOM_Auditor

GitLabvpierre/ndaal_public_sbom_auditor

Offline single-binary web app that ingests CycloneDX, SPDX and syft SBOMs, runs an ensemble of CVE scanners, enriches findings with EPSS, CISA-KEV…

configuration-auditingdefensive-toolsdevsecops+7
12 days ago
terrier preview

terrier

GitHubheroku/terrier

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

container-securityhash-analysissupply-chain-security+1
2274 months ago
CVE-2023-24059 preview

CVE-2023-24059

GitHubgmh5225/cve-2023-24059

Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January…

curated-resourceseducationexploitation+2
3 years ago
View8 preview

View8

GitHubsuleram/view8

Decompiles serialized V8 bytecode (JSC files) into high-level readable JavaScript-like code, with support for multiple V8 versions, tree output, and…

binary-analysismalware-analysisreverse-engineering+2
3792 months ago
Exploitarium-Detections preview

Exploitarium-Detections

GitHubethan-andrews/exploitarium-detections

KQL detection rules for Microsoft Sentinel and Defender XDR covering the bikini/exploitarium anonymous disclosure — a personal research archive of…

educationincident-responseintrusion-detection+3
5022 days ago
Network_Assessment preview

Network_Assessment

GitHubalperenugurlu/network_assessment

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

anomaly-detectionintrusion-detectionnetwork-security+2
1473 years ago
Previous12…45Next