Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
115 results
learn365 preview

learn365

GitHubharsh-bothra/learn365

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.

api-securitycloud-securitycurated-resources+5
1.7k
4 years ago
sitedorks preview

sitedorks

GitHubzarcolio/sitedorks

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

dns-subdomain-enumerationinformation-gatheringosint+3
1.1k2 days ago
GlacierCTF2023_writeups preview

GlacierCTF2023_writeups

GitHublosfuzzys/glacierctf2023_writeups

Curated CTF writeup collection for GlacierCTF 2023 covering pwn, rev, web, crypto, and smart contract challenges with solutions and educational…

binary-exploitationcryptographyctf+4
162 years ago
spiderfoot preview

spiderfoot

GitHubsmicallef/spiderfoot

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

dns-analysisemail-harvestinginformation-gathering+7
21.2k2 years ago
SpiderSuite preview

SpiderSuite

GitHubspidersuite/spidersuite

Advanced cross-platform web crawler for security professionals, enabling automated reconnaissance, information gathering, and OSINT data collection…

crawlerinformation-gatheringosint+2
9737 days ago
HoneyProxy preview

HoneyProxy

GitHubmhils/honeyproxy

This project is now part of @mitmproxy.

forensicsnetwork-securitypacket-sniffing-analysis+3
1969 years ago
ioc-scanner-CVE-2019-19781 preview

ioc-scanner-CVE-2019-19781

GitHubcitrix/ioc-scanner-cve-2019-19781

Indicator of Compromise Scanner for CVE-2019-19781

digital-forensicsforensicsincident-response+5
586 years ago
micros_honeypot preview

micros_honeypot

GitHubcymmetria/micros_honeypot

MICROS Honeypot is a low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications…

defensive-toolsincident-responsevulnerability-scanners+1
187 years ago
exchange-0days-202103 preview

exchange-0days-202103

GitHubsgnls/exchange-0days-202103

IoC determination for exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.

digital-forensicsexploitationincident-response+3
55 years ago
citrix-logchecker preview

citrix-logchecker

GitHubcertat/citrix-logchecker

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

incident-responselog-analysisnetwork-security+3
52 years ago
jsp-webshell-scanner preview

jsp-webshell-scanner

GitHubrespondiq/jsp-webshell-scanner

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

code-analysisdigital-forensicsforensics+6
12 months ago
CVE-2026-0257 preview

CVE-2026-0257

GitHubgrayxploit/cve-2026-0257

GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes…

authenticationincident-responseinformation-gathering+6
12 months ago
wp2shell-compromise-scanner-plugin preview

wp2shell-compromise-scanner-plugin

GitHubeyesecurity/wp2shell-compromise-scanner-plugin

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

database-securitydigital-forensicsforensics+5
1 month ago
drupal-check preview

drupal-check

GitHubhestat/drupal-check

Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600

forensicsincident-responselog-analysis+2
28 years ago
PAN-OS-CVE-2024-3400-Command-Injection-Investigation preview

PAN-OS-CVE-2024-3400-Command-Injection-Investigation

GitHubzedocun/pan-os-cve-2024-3400-command-injection-investigation

Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on…

digital-forensicsincident-responselog-analysis+3
14 months ago
CVE-2023-47529 preview

CVE-2023-47529

GitHubrandomrobbiebf/cve-2023-47529

Cloud Templates & Patterns collection <= 1.2.2 - Sensitive Information Exposure via Log File

exploitationinformation-gatheringlog-analysis+3
12 years ago
ZeroPoint preview

ZeroPoint

GitHubgmh5225/zeropoint

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

defensive-toolsexploitationincident-response+3
1 year ago
ToolShellFinder preview

ToolShellFinder

GitHubzach115th/toolshellfinder

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

digital-forensicsforensicsincident-response+5
8 months ago
Previous1234567Next