Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
419 results
goLoL preview

goLoL

GitHubaaron-kidwell/golol

goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege…

binary-analysiseducationinformation-gathering+6
70
3 months ago
Http11Probe preview

Http11Probe

GitHubmda2av/http11probe

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

api-security-testingfuzzingmisconfiguration+2
306 days ago
PyADRecon preview

PyADRecon

GitHubl4rm4nd/pyadrecon

Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX +…

authenticationinformation-gatheringpenetration-testing+4
682 months ago
oversight preview

oversight

GitHubrakosn1cek/oversight

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

code-analysisdevsecopsdynamic-analysis-sandboxing+7
392 months ago
0xKern3lCrush preview

0xKern3lCrush

GitHubdeathshotxd/0xkern3lcrush

Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for…

educationexploitationmalware-analysis+4
557 months ago
heimdall_webserver preview

heimdall_webserver

GitHubmthbernardes/heimdall_webserver

It's a tool to manage vulnerables packages in your *nix server, in a centralized way

configuration-auditingvulnerability-analysisvulnerability-scanners
305 years ago
GhostLock-Galaxy preview

GhostLock-Galaxy

GitHubwxxsfxyzm/ghostlock-galaxy

Root your Galaxy using CVE-2026-43499

android-securitybinary-analysisexploitation+6
271 month ago
CVE-2022-46169-CACTI-1.2.22 preview

CVE-2022-46169-CACTI-1.2.22

GitHubfredbrave/cve-2022-46169-cacti-1.2.22

This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.

exploitationpayload-developmentpenetration-testing+2
423 years ago
vulnerable-container-hub preview

vulnerable-container-hub

GitHubowasp/vulnerable-container-hub

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

container-securityctfcurated-resources+4
313 years ago
deadair preview

deadair

GitHubbig-comfy/deadair

Finds the detection rules in your SIEM that are running blind

configuration-auditinglog-analysisvulnerability-analysis
2222 days ago
intentshield preview

intentshield

GitHubmattijsmoens/intentshield

Pre-execution intent verification for AI agents. Audits what your AI is about to do, not what it says. Zero dependencies, deterministic, hash-sealed.

ai-securityanomaly-detectioncode-analysis+9
211 month ago
fleet-cve-scanner preview

fleet-cve-scanner

GitHubboostedchaos/fleet-cve-scanner

An open-source, single-script CVE scanner for RMM-managed fleets. Pure PowerShell 7 — joins your RMM software inventory against NVD, CISA KEV, EPSS…

configuration-auditingincident-responselog-analysis+3
122 months ago
burpfox preview

burpfox

GitHubhalilkirazkaya/burpfox

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.

dynamic-analysis-sandboxingpenetration-testingvulnerability-analysis+3
237 months ago
intel-me-research preview

intel-me-research

GitHubjatinkapilaq1/intel-me-research

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

binary-analysisembedded-systems-securityfirmware-analysis+4
152 months ago
Pentagram-exploit-tester preview

Pentagram-exploit-tester

GitHubgeosn0w/pentagram-exploit-tester

A test app to check if your device is vulnerable to CVE-2021-30955

exploitationios-securitymobile-security+2
194 months ago
kcmapper preview

kcmapper

GitHubsynacktiv/kcmapper

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

authentication-authorizationconfiguration-auditingidentity-access-management+3
147 months ago
alibi preview

alibi

GitHubowasp-noir/alibi

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

api-securitycode-analysisconfiguration-auditing+7
1118 days ago
lightweight_static_analysis preview

lightweight_static_analysis

GitHubnccgroup/lightweight_static_analysis

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

code-analysiseducationpenetration-testing+4
136 years ago
Previous1234…24Next