Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1915 results
lazyrecon preview

lazyrecon

GitHubstorenth/lazyrecon

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

fuzzingosintpenetration-testing+4
1496 months ago
insightsnexus preview

insightsnexus

GitHubcyberintel-labs/insightsnexus

OSINT Graph Investigation Application

curated-resourcesdns-subdomain-enumerationeducation+7
349 months ago
scan4all preview

scan4all

GitHubghosttroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

dns-subdomain-enumerationexploit-frameworksfuzzing+9
6.2k2 years ago
seccubus preview

seccubus

GitHubseccubus/seccubus

Easy automated vulnerability scanning, reporting and analysis

defensive-toolslog-analysisnetwork-mapping+5
7097 years ago
porch-pirate preview

porch-pirate

GitHubwatchdogsecurity/porch-pirate

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

api-securityinformation-gatheringosint+4
4792 years ago
project-black preview

project-black

GitHubc0rv4x/project-black

Pentest/BugBounty progress control with scanning modules

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
2796 years ago
ID-entify preview

ID-entify

GitHubbillyv4/id-entify

Search for information related to domain: Emails - IP addresses - Sub-Domains - Information on WEB technology - Type of Firewall - NS and MX records.

dns-analysisemail-harvestinginformation-gathering+4
1156 years ago
unwaf preview

unwaf

GitHubmmarting/unwaf

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
1877 months ago
network-security-lab preview

network-security-lab

GitHubamirmuhammadmarvi/network-security-lab

Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2

configuration-auditingeducationexploitation+7
3 months ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubcert-lv/cve-2020-0688

Scans networks for Microsoft Exchange servers vulnerable to CVE-2020-0688, using zmap for host discovery and TLS/version fingerprinting to identify…

exploitationinformation-gatheringpenetration-testing+3
86 years ago
NSE_CVE-2025-55182 preview

NSE_CVE-2025-55182

GitHubjahaziellem/nse_cve-2025-55182

Nmap NSE script for scanning React2Shell (CVE-2025-55182)

educationexploitationpayload-generation+5
19 months ago
PenBox preview

PenBox

GitHubx3omdax/penbox

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

exploitationfuzzinginformation-gathering+8
5389 years ago
axiom preview

axiom

GitHubpry0cc/axiom

The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf,…

cloud-infrastructure-securitynetwork-securitypenetration-testing+4
4.4k1 year ago
cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS preview

cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS

GitHubartofscripting-zz/cmty-ssl-heartbleed-cve-2014-0160-http-https

Detects the Heartbleed vulnerability (CVE-2014-0160) in OpenSSL on HTTP and HTTPS services via version checking, with guidance for using nmap,…

exploitationnetwork-securitypenetration-testing+3
7 years ago
xpfarm preview

xpfarm

GitHubcanuk40/xpfarm

Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

ai-securitybinary-analysisexploit-frameworks+7
1956 months ago
pcap-burp preview

pcap-burp

GitHubnccgroup/pcap-burp

Pcap importer for Burp

network-forensicspacket-sniffing-analysispenetration-testing+2
1145 years ago
CVE-2026-23869-Exploit preview

CVE-2026-23869-Exploit

GitHubcybertechajju/cve-2026-23869-exploit

Automated exploit tool for CVE-2026-23869, a remote DoS in React Server Components. Includes PoC, Nuclei template, and scanning scripts for detection…

exploitationpenetration-testingreconnaissance+3
95 months ago
fscan preview

fscan

GitHubshadow1ng/fscan

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

educationexploitationlateral-movement+9
14.6k11 days ago
Previous123…100Next