Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
sippts preview

sippts

GitHubpepelux/sippts

Set of tools to audit SIP based VoIP Systems

exploitationfuzzinginformation-gathering+6
5712 months ago
cotopaxi preview

cotopaxi

GitHubsamsung/cotopaxi

Set of tools for security testing of Internet of Things devices using specific network IoT protocols

fuzzingiot-securitynetwork-security+2
3625 years ago
tool-29489 preview

tool-29489

GitHubprasad-1808/tool-29489

This Tool is used to check for CVE-2023-29489 Vulnerability in the provided URL with the set of payloads available

exploitationinformation-gatheringpenetration-testing+2
2 years ago
reconftw preview

reconftw

GitHubsix2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

cloud-securitydns-analysisdns-subdomain-enumeration+11
8.1k10 days ago
OpenSSL-CCS-Inject-Test preview

OpenSSL-CCS-Inject-Test

GitHubtripwire/openssl-ccs-inject-test

This script is designed for detection of vulnerable servers (CVE-2014-0224.) in a wide range of configurations. It attempts to negotiate using each…

exploitationnetwork-securitypenetration-testing+2
3912 years ago
coreruleset preview

coreruleset

GitHubcoreruleset/coreruleset

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

anti-botids-ips-evasionmisconfiguration+4
3.3k10h 2m ago
CVE-2022-33679_Checker preview

CVE-2022-33679_Checker

GitHubsoy-oreocato/cve-2022-33679_checker

Lightweight Python checker that tests Active Directory credentials for exposure to CVE-2022-33679 (Kerberos AS-REP roast without pre-authentication).…

authenticationinformation-gatheringpenetration-testing+2
11 months ago
ICMP-Timestamp-POC preview

ICMP-Timestamp-POC

GitHubransc0rp1on/icmp-timestamp-poc

A reconnaissance tool to detect CVE-1999-0524 (ICMP Timestamp Disclosure) by automating timestamp extraction via nping or hping3. Converts raw ICMP…

exploitationinformation-gatheringnetwork-security+3
0 years ago
doublepulsar-detection-script preview

doublepulsar-detection-script

GitHubwithsecurelabs/doublepulsar-detection-script

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

incident-responseintrusion-detectionmalware-analysis+2
1.0k9 years ago
krane preview

krane

GitHubappvia/krane

Kubernetes RBAC static analysis & visualisation tool

cloud-securityconfiguration-auditingstatic-analysis+1
7457 days ago
Grafana-Final-Scanner preview

Grafana-Final-Scanner

GitHubzierax/grafana-final-scanner

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

configuration-auditinginformation-gatheringvulnerability-analysis+3
24414h 39m ago
CVE-2020-11019 preview

CVE-2020-11019

GitHublixterclarixe/cve-2020-11019

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an…

curated-resourceseducationinformation-gathering+2
3 years ago
packetfence preview

packetfence

GitHubinverse-inc/packetfence

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

authentication-authorizationconfiguration-auditingdefensive-tools+6
1.7k12h 48m ago
coraza preview

coraza

GitHubcorazawaf/coraza

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

api-securityapi-security-testingdefensive-tools+7
3.8k7 days ago
faraday_zap preview

faraday_zap

GitHubinfobyte/faraday_zap

Zap Extension for collaboration in Faraday

api-security-testingpenetration-testingvulnerability-scanners+2
26 months ago
nanwinata-CVE-2024-52301 preview

nanwinata-CVE-2024-52301

GitHubfckoo/nanwinata-cve-2024-52301

Scans for CVE-2024-52301, an argument injection vulnerability in Laravel, using subfinder and httpx to identify affected web applications.

exploitationinformation-gatheringreconnaissance+2
1 year ago
CVE-2021-44228---detection-with-PowerShell preview

CVE-2021-44228---detection-with-PowerShell

GitHubintel-xeon/cve-2021-44228---detection-with-powershell

PowerShell-based scanner to detect Log4j CVE-2021-44228 vulnerability by searching directories and log files for exploitation indicators.

information-gatheringlog-analysisscripting-automation+2
4 years ago
Detect-CVE-2019-19781 preview

Detect-CVE-2019-19781

GitHubcastaldio86/detect-cve-2019-19781

Detects if a server is vulnerable to CVE-2019-19781 by checking a specified IP address, providing a quick security assessment for this known…

information-gatheringnetwork-securityreconnaissance+2
6 years ago