Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
56 results
WebSecProbe preview

WebSecProbe

GitHubspyboy-productions/websecprobe

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.

misconfigurationpenetration-testingvulnerability-scanners+2
185
8 months ago
AIDOR preview

AIDOR

GitHubabdulahadthecyber-pixel/aidor

Bash-based automated IDOR vulnerability scanner that detects insecure direct object references by enumerating numerical parameters and analyzing HTTP…

information-gatheringpenetration-testingreconnaissance+2
378 months ago
s3reverse preview

s3reverse

GitHubhahwul/s3reverse

The format of various s3 buckets is convert in one format. for bugbounty and security testing.

cloud-securityinformation-gatheringmisconfiguration+1
913 years ago
DependencyCheck preview

DependencyCheck

GitHubdependency-check/dependencycheck

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

devsecopssupply-chain-securityvulnerability-analysis+1
7.7k13h 1m ago
Dracnmap preview

Dracnmap

GitHubscreetsec/dracnmap

Dracnmap is an open source program which is using to exploit the network and gathering information with nmap help. Nmap command comes with lots of…

information-gatheringnetwork-mappingpenetration-testing+2
1.4k8 years ago
Zeus-Scanner preview

Zeus-Scanner

GitHubekultek/zeus-scanner

Advanced reconnaissance utility

captcha-bypassinformation-gatheringport-scanning+4
9997 years ago
puncia preview

puncia

GitHubarpsyndicate/puncia

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

exploit-frameworksinformation-gatheringosint+6
66417 days ago
graphql-cop preview

graphql-cop

GitHubdolevf/graphql-cop

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

api-securityapi-security-testingdynamic-code-analysis+5
69310 months ago
HikvisionExploiter preview

HikvisionExploiter

GitHubtamim1089/hikvisionexploiter

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

command-and-controlencryption-decryption-toolsexploitation+8
3849 months ago
nuclearpond preview

nuclearpond

GitHubdevsecopsdocs/nuclearpond

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

cloud-securitydevsecopsnetwork-security+2
1963 years ago
X-Recon preview

X-Recon

GitHubjoshkar/x-recon

A utility for detecting webpage inputs and conducting XSS scans.

crawlerinformation-gatheringreconnaissance+4
1715 months ago
kubolt preview

kubolt

GitHubaveronesis/kubolt

Kubolt utility for scanning public kubernetes clusters

cloud-securitycontainer-securitymisconfiguration+3
1105 years ago
Ivanti-Connect-Around-Scan preview

Ivanti-Connect-Around-Scan

GitHubseajaysec/ivanti-connect-around-scan

Mitigation validation utility for the Ivanti Connect Around attack chain. Runs multiple checks. CVE-2023-46805, CVE-2024-21887.

exploitationinformation-gatheringpenetration-testing+3
122 years ago
nuclearpond-OFJAAAH preview

nuclearpond-OFJAAAH

GitHubkingofbugbounty/nuclearpond-ofjaaah

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

cloud-securitydevsecopsvulnerability-scanners+1
102 years ago
CVE-2026-64600 preview

CVE-2026-64600

GitHubdebajyoti0-0/cve-2026-64600

A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel…

configuration-auditingdefensive-toolsexploitation+3
61 month ago
cve-2026-41940-tool preview

cve-2026-41940-tool

GitHubnull200ok/cve-2026-41940-tool

A comprehensive Python utility to **detect**, **scan in bulk**, and **exploit** the critical authentication bypass vulnerability (CVE-2026-41940) in…

exploitationinformation-gatheringpayload-development+5
44 months ago
CVE-2024-3094_xz_check preview

CVE-2024-3094_xz_check

GitHubhackerhermanos/cve-2024-3094_xz_check

This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as…

educationscripting-automationsupply-chain-security+2
92 years ago
CVE-2026-23918 preview

CVE-2026-23918

GitHubhackervlogofficial/cve-2026-23918

This is a proactive tool for security auditing. For your GitHub repository, you’ll want a description that highlights its safety (non-intrusive) and…

configuration-auditingdevsecopsnetwork-security+2
14 months ago
Previous1234Next