Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
120 results
ThreatScraper preview

ThreatScraper

GitHubamorath/threatscraper

Python tool that queries the VirusTotal API to check file hashes against 70+ antivirus engines, schedules recurring scans, and exports detection…

information-gatheringmalware-analysisthreat-intelligence+1
7
3 years ago
git-dump preview

git-dump

GitHubjenderal92/git-dump

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and…

information-gatheringmisconfigurationpenetration-testing+3
14 months ago
cve-2020-1472 preview

cve-2020-1472

GitHubshanfenglan/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

exploitationlateral-movementpassword-attacks+3
25 years ago
CitrixBleedCVE-2026-8452-2025-5777 preview

CitrixBleedCVE-2026-8452-2025-5777

GitHubmaxprog-svg/citrixbleedcve-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

exploitationinformation-gatheringpenetration-testing+3
1 month ago
sarenka preview

sarenka

GitHubktzgraph/sarenka

OSINT tool - gets data from services like shodan, censys etc. in one app

crawlerdns-analysishash-analysis+4
6744 years ago
cve-2022-22976-bcrypt-skips-salt preview

cve-2022-22976-bcrypt-skips-salt

GitHubspring-io/cve-2022-22976-bcrypt-skips-salt

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

authenticationdatabase-securityencryption-decryption-tools+3
14 years ago
DPAT preview

DPAT

GitHubclr2of8/dpat

Domain Password Audit Tool for Pentesters

password-crackingpenetration-testingvulnerability-analysis
1.1k9 months ago
CosmicRakp preview

CosmicRakp

GitHubfin3ss3g0d/cosmicrakp

Go-based tool to exploit CVE-2013-4786 for dumping IPMI password hashes via RAKP authentication, supporting concurrent scanning of IP ranges or…

exploitationinformation-gatheringpassword-cracking+3
4210 months ago
lil-pwny preview

lil-pwny

GitHubpapermtn/lil-pwny

Fast offline auditing of Active Directory passwords using Python.

authenticationpassword-crackingvulnerability-analysis
1672 years ago
terrier preview

terrier

GitHubheroku/terrier

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

container-securityhash-analysissupply-chain-security+1
2284 months ago
ThreatLens preview

ThreatLens

GitHubabdaullahag/threatlens

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

defensive-toolsincident-responseinformation-gathering+7
2520 days ago
CVE-2026-89012 preview

CVE-2026-89012

GitHubfaceless0x7/cve-2026-89012

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

api-securitydata-exfiltrationexploitation+6
626 days ago
CVE-2021-29156 preview

CVE-2021-29156

GitHubguidepointsecurity/cve-2021-29156

Proof-of-concept exploit for CVE-2021-29156, an LDAP injection vulnerability in ForgeRock OpenAM v13.0.0, enabling character-by-character brute force…

exploitationinformation-gatheringpenetration-testing+2
43 years ago
hashID preview

hashID

GitHubpsypanda/hashid

Software to identify the different types of hashes -

forensicshash-analysisinformation-gathering+3
1.5k11 years ago
Pwdlyser preview

Pwdlyser

GitHubins1gn1a/pwdlyser

Pwdlyser is an all encompassing security auditing tool. This repo serves as the open-source base for the new version of Pwdlyser (previously…

password-attackspassword-crackingpenetration-testing+1
276 years ago
ms-photos_NTLM_Leak preview

ms-photos_NTLM_Leak

GitHubrubenformation/ms-photos_ntlm_leak

New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click

educationexploitationlateral-movement+4
20810 months ago
CVE-2025-52488 preview

CVE-2025-52488

GitHubsh4den/cve-2025-52488

This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes…

exploitationinformation-gatheringpassword-attacks+3
23 months ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubpolarisxsec/cve-2024-21413

Educational lab demonstrating CVE-2024-21413 exploitation in Outlook to leak NTLM hashes via malicious UNC links, with custom SMTP/POP3…

educationexploitationlabs-practice+3
11 year ago
Previous1234567Next