Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
75 results
laf preview

laf

GitHubioactive/laf

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

cryptographyexploitationfuzzing+5
188
4 years ago
PurpleLlama preview

PurpleLlama

GitHubmeta-llama/purplellama

Set of tools to assess and improve LLM security.

adversarial-attackai-securitycode-analysis+4
4.4k25 days ago
sitedorks preview

sitedorks

GitHubzarcolio/sitedorks

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

dns-subdomain-enumerationinformation-gatheringosint+3
1.1k24 days ago
sandbox-attacksurface-analysis-tools preview

sandbox-attacksurface-analysis-tools

GitHubgoogleprojectzero/sandbox-attacksurface-analysis-tools

Set of tools to analyze Windows sandboxes for exposed attack surface.

defensive-toolsdynamic-analysis-sandboxingexploitation+4
2.3k10 months ago
wvctf preview

wvctf

GitHubsyn-4ck/wvctf

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

ctfeducationlabs-practice+3
12 years ago
ripple20 preview

ripple20

GitHubcorelight/ripple20

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

anomaly-detectionintrusion-detectioniot-security+3
324 years ago
CloudPrivs preview

CloudPrivs

GitHubabstractclass/cloudprivs

Determine privileges from cloud credentials via brute-force testing.

cloud-securityinformation-gatheringpenetration-testing+2
691 month ago
gethspoit preview

gethspoit

GitHubkarmahostage/gethspoit

Finding Ethereum nodes which are vulnerable to RPC-attacks

cryptographyinformation-gatheringnetwork-security+2
3110 years ago
CVE-2023-33381-MitraStar-GPT-2741GNAC preview

CVE-2023-33381-MitraStar-GPT-2741GNAC

GitHubduality084/cve-2023-33381-mitrastar-gpt-2741gnac

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

binary-analysisembedded-systems-securityexploitation+4
133 years ago
CVE-2010-1205 preview

CVE-2010-1205

GitHubmk219533/cve-2010-1205

sample exploit of buffer overflow in libpng

binary-exploitationeducationexploitation+2
415 years ago
CVE-2022-33679_Checker preview

CVE-2022-33679_Checker

GitHubsoy-oreocato/cve-2022-33679_checker

Lightweight Python checker that tests Active Directory credentials for exposure to CVE-2022-33679 (Kerberos AS-REP roast without pre-authentication).…

authenticationinformation-gatheringpenetration-testing+2
11 months ago
DjVuLibre-poc-CVE-2025-53367 preview

DjVuLibre-poc-CVE-2025-53367

GitHubkevinbackhouse/djvulibre-poc-cve-2025-53367

Proof-of-concept exploit for CVE-2025-53367, a vulnerability in the DjVuLibre library. Demonstrates exploitation of a memory corruption bug in DjVu…

binary-analysiscode-analysisexploitation+3
1 year ago
Tyr preview

Tyr

GitLabcyberactivity/tyr

Tools collection to explore CVE and theirs associated data.

information-gatheringthreat-intelligenceutilities-frameworks+1
4 months ago
MFASweep preview

MFASweep

GitHubdafthack/mfasweep

A tool for checking if MFA is enabled on multiple Microsoft Services

authenticationcloud-securitypenetration-testing+2
1.7k5 months ago
svg-cheatsheet preview

svg-cheatsheet

GitHuballanlw/svg-cheatsheet

A cheatsheet for exploiting server-side SVG processors.

curated-resourceseducationinformation-gathering+4
8056 years ago
Grafana-Final-Scanner preview

Grafana-Final-Scanner

GitHubzierax/grafana-final-scanner

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

configuration-auditinginformation-gatheringvulnerability-analysis+3
24414h 37m ago
CVE-2023-4863 preview

CVE-2023-4863

GitHubmistymntncop/cve-2023-4863

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

binary-analysiscode-analysiseducation+2
3172 years ago
chromium-exploit-dev preview

chromium-exploit-dev

GitHubpetitoto/chromium-exploit-dev

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits

binary-exploitationcommand-and-controlexploitation+5
3085 months ago
Previous12345Next