Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
226 results
Vulnerability-Disclosures preview

Vulnerability-Disclosures

GitHubmandiant/vulnerability-disclosures

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

exploitationpenetration-testingred-teaming+3
220
2 days ago
pmg preview

pmg

GitHubsafedep/pmg

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

cloud-securitycontainer-securitydevsecops+6
4941 day ago
omnisci3nt preview

omnisci3nt

GitHubspyboy-productions/omnisci3nt

Omnisci3nt is an open-source web reconnaissance and intelligence tool for extracting deep technical insights from domains, including subdomains, SSL…

dns-analysisinformation-gatheringosint+6
3682 months ago
pulledpork preview

pulledpork

GitHubshirkdog/pulledpork

Pulled Pork for Snort and Suricata rule management (from Google code)

configuration-auditingintrusion-detectionnetwork-security+2
4425 years ago
shodanwave preview

shodanwave

GitHubjimywork/shodanwave

Shodanwave is a tool for exploring and obtaining information from Netwave IP Camera.

exploitationinformation-gatheringiot-security+5
2678 years ago
BucketLoot preview

BucketLoot

GitHubredhuntlabs/bucketloot

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

cloud-infrastructure-securitycloud-securityinformation-gathering+4
4467 months ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4061 year ago
rainmap-lite preview

rainmap-lite

GitHubcldrn/rainmap-lite

Rainmap Lite - Responsive web based interface that allows users to launch Nmap scans from their mobiles/tablets/web browsers!

network-mappingport-scanningvulnerability-scanners+1
2345 years ago
Minesweeper preview

Minesweeper

GitHubcodingo/minesweeper

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

cryptographythreat-intelligencevulnerability-scanners+1
2027 years ago
CVE-2024-6387-Vulnerability-Checker preview

CVE-2024-6387-Vulnerability-Checker

GitHubfilipi86/cve-2024-6387-vulnerability-checker

This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports.…

exploitationnetwork-securityvulnerability-scanners
1022 years ago
purify preview

purify

GitHubfaloker/purify

All-in-one tool for managing vulnerability reports from AppSec pipelines

code-analysisdevsecopsvulnerability-scanners
1085 years ago
In-Spectre-Meltdown preview

In-Spectre-Meltdown

GitHubviralmaniar/in-spectre-meltdown

This tool allows to check speculative execution side-channel attacks that affect many modern processors and operating systems designs. CVE-2017-5754…

exploitationhardware-securityvulnerability-analysis+1
958 years ago
DracOS preview

DracOS

GitHubscreetsec/dracos

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

educationexploitationforensics+8
589 years ago
CVE-2020-5902-Scanner preview

CVE-2020-5902-Scanner

GitHubaqhmal/cve-2020-5902-scanner

Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.

exploitationinformation-gatheringpenetration-testing+3
553 years ago
Hx0-HawkEye preview

Hx0-HawkEye

GitHubasaotomo/hx0-hawkeye

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

ai-securityapi-security-testingctf+7
602 months ago
scripts-nse preview

scripts-nse

GitHubdanilabs/scripts-nse

Some NSE scripts to search information from routers

exploitationinformation-gatheringnetwork-security+4
3610 years ago
Config-Exploiter preview

Config-Exploiter

GitHubcyb0r9/config-exploiter

Automated tool to dump config.php files from vulnerable Joomla and WordPress websites using known exploit modules (com_joomanager, revslider).

information-gatheringvulnerability-scannersweb-application-exploitation
397 years ago
DblTekGoIPPwn preview

DblTekGoIPPwn

GitHubjacobmisirian/dbltekgoippwn

Tool to check if an IP of a DblTek GoIP is vulnerable to a challenge-response login system, send SMS messages from the system, execute remote…

command-and-controlexploitationpenetration-testing+2
636 years ago
Previous123…13Next