Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2069 results
msiscan preview

msiscan

GitHubsec-consult/msiscan

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers

configuration-auditingpenetration-testingprivilege-escalation+2
129
2 years ago
ACEshark preview

ACEshark

GitHubt3l3machus/aceshark

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

configuration-auditinginformation-gatheringpenetration-testing+4
1501 year ago
heimdall_webserver preview

heimdall_webserver

GitHubmthbernardes/heimdall_webserver

It's a tool to manage vulnerables packages in your *nix server, in a centralized way

configuration-auditingvulnerability-analysisvulnerability-scanners
305 years ago
Find-WSUS preview

Find-WSUS

GitHubmubix/find-wsus

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

configuration-auditingdefensive-toolsinformation-gathering+2
4610 months ago
IntelligentProcessLifecycle preview

IntelligentProcessLifecycle

GitHubd3sre/intelligentprocesslifecycle

The Intelligent Process Lifecycle of Active Cyber Defenders

configuration-auditingcurated-resourceseducation+6
343 years ago
CVE-2023-36884-Scripts-for-Intune-Remediation-SCCM-Compliance-Baseline preview

CVE-2023-36884-Scripts-for-Intune-Remediation-SCCM-Compliance-Baseline

GitHubmaxwitat/cve-2023-36884-scripts-for-intune-remediation-sccm-compliance-baseline

The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection…

configuration-auditingdefensive-toolsincident-response+2
263 years ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubozergoker/cve-2021-40444

Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444

configuration-auditingeducationexploitation+2
184 years ago
CVE-2020-9289 preview

CVE-2020-9289

GitHubsynacktiv/cve-2020-9289

Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with…

configuration-auditingcryptographyencryption-decryption-tools+3
113 years ago
DisableSMBCompression preview

DisableSMBCompression

GitHubtechnion/disablesmbcompression

CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates

configuration-auditingincident-responsemisconfiguration+2
96 years ago
BlackLotus preview

BlackLotus

GitHubajf8729/blacklotus

BlackLotus aka CVE-2023-24932 Detection/Remediation Scripts for Intune, ConfigMgr, and generic use

cloud-securityconfiguration-auditingdevsecops+3
81 year ago
CVE-2026-33032 preview

CVE-2026-33032

GitHubbaba01hacker666/cve-2026-33032

Python proof-of-concept for CVE-2026-33032 that inspects nginx status and configs, then demonstrates unauthorized config write with reload to deploy…

configuration-auditingexploitationpenetration-testing+3
24 days ago
polkit-0.96-CVE-2021-4034 preview

polkit-0.96-CVE-2021-4034

GitHubsofire/polkit-0.96-cve-2021-4034

centos 6.10 rpm for fix polkit CVE-2021-4034; centos 6.10的rpm包,修复CVE-2021-4034 漏洞

configuration-auditingcurated-resourceseducation+1
84 years ago
nginx-rift-check preview

nginx-rift-check

GitHubcynepmyx/nginx-rift-check

Detects the CVE-2026-42945 rewrite pattern in nginx configs: rewrite with ? in the replacement plus an unnamed capture consumed in the same location

configuration-auditingstatic-analysisvulnerability-analysis+2
1 month ago
patch-CVE-2026-09881 preview

patch-CVE-2026-09881

GitHubgduma-phdata/patch-cve-2026-09881

Patch: Template injection RCE (Atlassian Confluence)

configuration-auditingdevsecopsvulnerability-analysis+1
21 days ago
CVE-2026-9055 preview

CVE-2026-9055

GitHubexecution-py/cve-2026-9055

Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

configuration-auditingcurated-resourceseducation+3
11 days ago
test_cve-2023-46747 preview

test_cve-2023-46747

GitHubnvansluis/test_cve-2023-46747

Python script to test F5 BIG-IP for CVE-2023-46747 and add an administrator account if vulnerable.

cloud-securityconfiguration-auditingexploitation+3
72 years ago
dirty-frag-check preview

dirty-frag-check

GitHubhaydenjames/dirty-frag-check

Read-only checker for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) Linux kernel local-root vulns

configuration-auditingdevsecopsincident-response+2
74 months ago
WordPress-CVE-2026-63030-Analysis preview

WordPress-CVE-2026-63030-Analysis

GitHubimxur/wordpress-cve-2026-63030-analysis

Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.

configuration-auditingdefensive-toolseducation+3
31 month ago
Previous1…959697…100Next