Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
344 results
vbrute preview

vbrute

GitHubnccgroup/vbrute

Virtual host brute forcer

information-gatheringnetwork-mappingreconnaissance+1
2212 years ago
hashID preview

hashID

GitHubpsypanda/hashid

Software to identify the different types of hashes -

forensicshash-analysisinformation-gathering+3
1.5k11 years ago
ridenum preview

ridenum

GitHubtrustedsec/ridenum

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

authenticationinformation-gatheringnetwork-security+3
3176 years ago
hackerone preview

hackerone

GitHubbesioo/hackerone

Brute-force scraper for HackerOne disclosed reports via their public API, collecting report IDs, links, titles, and states for security research and…

educationinformation-gatheringosint+3
572 years ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
cve-2020-1472 preview

cve-2020-1472

GitHubmstxq17/cve-2020-1472

cve-2020-1472 复现利用及其exp

exploitationpassword-crackingpenetration-testing+3
1136 years ago
FavFreak preview

FavFreak

GitHubdevanshbatham/favfreak

Making Favicon.ico based Recon Great again !

crawlerhash-analysisinformation-gathering+3
1.3k3 years ago
FileWatchTower preview

FileWatchTower

GitHubiomoath/filewatchtower

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

digital-forensicsforensicshash-analysis+4
292 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubmoneertv/cve-2023-23397

CVE-2023-23397 C# PoC

exploitationpassword-crackingpayload-generation+3
13 years ago
BruteForce-to-KeePass preview

BruteForce-to-KeePass

GitHubund3sc0n0c1d0/bruteforce-to-keepass

This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting…

exploitationpassword-crackingpenetration-testing+1
63 years ago
Venom-JWT preview

Venom-JWT

GitHubz-bool/venom-jwt

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

exploitationfuzzingpassword-cracking+3
2881 year ago
CVE-2019-17240_Bludit-BF-Bypass preview

CVE-2019-17240_Bludit-BF-Bypass

GitHubcoldfusionx/cve-2019-17240_bludit-bf-bypass

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC

educationexploitationpassword-attacks+3
25 years ago
CVE-2024-21754-Forti-RCE preview

CVE-2024-21754-Forti-RCE

GitHubcybersecuritist/cve-2024-21754-forti-rce

Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

exploitationnetwork-securitypassword-cracking+2
22 years ago
https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubfathanahhidayati/https-github.com-xaitax-cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

email-securityexploitationpassword-cracking+4
2 years ago
ubuntu-privesc-lab preview

ubuntu-privesc-lab

GitHubvaibhavkrishna12004/ubuntu-privesc-lab

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

educationexploitationlabs-practice+8
6 months ago
SSHUsernameBruter-SSHUB preview

SSHUsernameBruter-SSHUB

GitHubjoeblacksecurity/sshusernamebruter-sshub

Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

exploitationnetwork-securitypassword-attacks+2
27 years ago
SimpleCTF-UpdatedExploit preview

SimpleCTF-UpdatedExploit

GitHubdh4nuj4/simplectf-updatedexploit

This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made…

exploitationpassword-crackingpenetration-testing+2
62 years ago
CVE-2024-3183-POC preview

CVE-2024-3183-POC

GitHubim10n/cve-2024-3183-poc

POC for CVE-2024-3183 (FreeIPA Rosting)

authenticationexploitationpassword-attacks+2
292 years ago
Previous1…456…20Next