Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.9k2 days ago
brutus preview

brutus

GitHubpraetorian-inc/brutus

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

authenticationexploitationinformation-gathering+7
3274 days ago
godirb preview

godirb

GitHubmycode83/godirb

Fast and easy-to-use directory brute-forcer written in Go.

fuzzinginformation-gatheringpenetration-testing+3
521 days ago
Exploit-CVE-2023-6063-PoC-Vuln preview

Exploit-CVE-2023-6063-PoC-Vuln

GitHubzhairiazzeddine/exploit-cve-2023-6063-poc-vuln

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

exploitationpassword-crackingpenetration-testing+4
29 days ago
WP-Contest-Gallery-28.1.4-Exploit preview

WP-Contest-Gallery-28.1.4-Exploit

GitHubcerberusmrxi/wp-contest-gallery-28.1.4-exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

exploitationpassword-crackingpayload-development+4
12 months ago
py-network-scanner preview

py-network-scanner

GitHubanonymous121029034720384234234/py-network-scanner

Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and…

educationexploitationids-ips-evasion+6
11 year ago
malwarescanner preview

malwarescanner

GitHubpassword123456/malwarescanner

Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…

hash-analysisincident-responsemalware-analysis+1
901 year ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4081 year ago
clamtk preview

clamtk

GitLabdave_m/clamtk

An easy to use, light-weight, on-demand virus scanner for Linux systems. For additional help, see the <a…

defensive-toolshash-analysisincident-response+3
1002 years ago
DirDar preview

DirDar

GitHubm4dm0e/dirdar

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

information-gatheringpenetration-testingvulnerability-scanners+1
4532 years ago
VTScanner preview

VTScanner

GitHubsamhaxr/vtscanner

A comprehensive Python-based security tool for file scanning, malware detection, and analysis in an ever-evolving cyber landscape.

hash-analysisinformation-gatheringmalware-analysis+1
1123 years ago
hikvision_brute preview

hikvision_brute

GitHubnanotrash/hikvision_brute

Brute Hikvision CAMS with CVE-2021-36260 Exploit

exploitationiot-securitypassword-attacks+3
33 years ago
insect preview

insect

GitHubnu11secur1ty/insect

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

fuzzinginformation-gatheringpenetration-testing+3
3 years ago
BruteX preview

BruteX

GitHub1n3/brutex

Automatically brute force all services running on a target.

information-gatheringpassword-attackspenetration-testing+1
2.3k3 years ago
lazyrecon preview

lazyrecon

GitHubstorenth/lazyrecon

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

fuzzingosintpenetration-testing+4
1473 years ago
log4j-checker preview

log4j-checker

GitHuboccamsec/log4j-checker

Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.

code-analysishash-analysisincident-response+3
44 years ago
pathprober preview
Archived

pathprober

GitHubxchopath/pathprober

Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once

information-gatheringpenetration-testingreconnaissance+3
475 years ago
extended-ssrf-search preview

extended-ssrf-search

GitHubdamian89/extended-ssrf-search

Smart ssrf scanner using different methods like parameter brute forcing in post and get...

fuzzingpenetration-testingvulnerability-scanners+1
2745 years ago
Previous12Next