Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
rxerium-templates preview

rxerium-templates

GitHubrxerium/rxerium-templates

Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities.

curated-resourcesinformation-gatheringpenetration-testing+5
194
1 month ago
Custom-Nuclei-Templates preview

Custom-Nuclei-Templates

GitHubk3ystr0k3r/custom-nuclei-templates

A list of custom Nuclei templates you can use for your scans.

reconnaissancevulnerability-scannersweb-security
76 months ago
TarantuBench preview

TarantuBench

GitHubtrivulzianus/tarantubench

The full repo of all the labs available as part of the benchmark

authentication-authorizationctfeducation+6
23 months ago
BlueTeam-Tools preview

BlueTeam-Tools

GitHuba-poc/blueteam-tools

Tools and Techniques for Blue Team / Incident Response

curated-resourcesdata-recoverydefensive-tools+8
4.4k1 month ago
pentest-ai-agents preview

pentest-ai-agents

GitHub0xsteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

ai-securitycloud-securityeducation+8
2.1k4 days ago
WMD preview

WMD

GitHubthomastjdev/wmd

Python framework for IT security tools

exploit-frameworksinformation-gatheringpassword-cracking+8
2689 years ago
Bountystrike-sh preview

Bountystrike-sh

GitHubbountystrike/bountystrike-sh

Poor (rich?) man's bug bounty pipeline https://dubell.io

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
2913 years ago
nuclei-templates-labs preview

nuclei-templates-labs

GitHubprojectdiscovery/nuclei-templates-labs

Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀

ctfcurated-resourcesdevsecops+8
1341 year ago
zap-api-rust preview

zap-api-rust

GitHubzaproxy/zap-api-rust
api-securitypenetration-testingvulnerability-scanners+3
152 years ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
CVE-2024-32030-Nuclei-Template preview

CVE-2024-32030-Nuclei-Template

GitHubhuseyinstif/cve-2024-32030-nuclei-template
exploitationpenetration-testingremote-access-tool+2
12 years ago
Loki preview

Loki

GitHubneo23x0/loki

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

digital-forensicsforensicshash-analysis+5
3.8k7 months ago
ioc-scanner-CVE-2019-19781 preview

ioc-scanner-CVE-2019-19781

GitHubcitrix/ioc-scanner-cve-2019-19781

Indicator of Compromise Scanner for CVE-2019-19781

digital-forensicsforensicsincident-response+5
586 years ago
micros_honeypot preview

micros_honeypot

GitHubcymmetria/micros_honeypot

MICROS Honeypot is a low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications…

defensive-toolsincident-responsevulnerability-scanners+1
187 years ago
log4j-ioc-detector preview

log4j-ioc-detector

GitHubsantosomar/log4j-ioc-detector

A Simple Log4j Indicator of Compromise Linux Detector

incident-responseioc-managementlog-analysis+2
174 years ago
jsp-webshell-scanner preview

jsp-webshell-scanner

GitHubrespondiq/jsp-webshell-scanner

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

code-analysisdigital-forensicsforensics+6
12 months ago
CVE-2026-0257 preview

CVE-2026-0257

GitHubgrayxploit/cve-2026-0257

GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes…

authenticationincident-responseinformation-gathering+6
12 months ago
wp2shell-compromise-scanner-plugin preview

wp2shell-compromise-scanner-plugin

GitHubeyesecurity/wp2shell-compromise-scanner-plugin

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

database-securitydigital-forensicsforensics+5
1 month ago
Previous1234Next