Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
317 results
TCASVS preview

TCASVS

GitHubowasp/tcasvs

OWASP Thick Client Application Security Verification Standard

code-analysisconfiguration-auditingcryptography+5
301 month ago
pivit preview

pivit

GitHubcashapp/pivit
authenticationcryptographyhardware-security
1002 months ago
CVE-2026-36522 preview

CVE-2026-36522

GitHubdeepwoodssec/cve-2026-36522

CVE-2026-36522: unauthenticated NaN injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CWE-1287, DoS/integrity)

embedded-systems-securityexploitationfuzzing+3
2 months ago
CVE-2026-10795-Lab preview

CVE-2026-10795-Lab

GitHubrootdirective-sec/cve-2026-10795-lab
authentication-authorizationeducationexploitation+3
2 months ago
EDRChoker preview

EDRChoker

GitHubtwosevenonet/edrchoker

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

defensive-toolsids-ips-evasionpersistence-mechanisms+3
3102 months ago
SCOPE preview

SCOPE

GitHubtayontech/scope

AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

ai-securitycloud-infrastructure-securitycloud-security+8
542 months ago
CorelightForSentinelOne preview

CorelightForSentinelOne

GitHubcorelight/corelightforsentinelone

Corelight Dashboards and Parsers for Sentinel One Singularity

defensive-toolslog-analysisnetwork-security
62 months ago
uefi-firmware-parser preview

uefi-firmware-parser

GitHubtheopolis/uefi-firmware-parser

Parse BIOS/Intel ME/UEFI firmware related structures: Volumes, FileSystems, Files, etc

binary-analysisembedded-systems-securityfirmware-analysis+2
9202 months ago
social-engineer-toolkit preview

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

exploit-frameworksinformation-gatheringpayload-generation+5
15.2k2 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubimsre9/cve-2026-42945
binary-exploitationeducationexploitation+3
3 months ago
cve-2026-34473-unauthenticated-dos-zte-routers preview

cve-2026-34473-unauthenticated-dos-zte-routers

GitHubminanagehsalalma/cve-2026-34473-unauthenticated-dos-zte-routers

Technical breakdown of CVE-2026-34473, an unauthenticated denial of service affecting 17+ ZTE router models.

embedded-systems-securityexploitationfirmware-analysis+2
23 months ago
CVE-2024-37054-MLflow-reverse-shell preview

CVE-2024-37054-MLflow-reverse-shell

GitHubspydomain/cve-2024-37054-mlflow-reverse-shell
exploitationpayload-generationpenetration-testing+3
3 months ago
monikerlinktest preview

monikerlinktest

GitHubkaihaochen04/monikerlinktest

cve-2024-21413

exploitationpassword-crackingpenetration-testing+3
3 months ago
nginx-cve-2026-42945-check preview

nginx-cve-2026-42945-check

GitHubbyezero/nginx-cve-2026-42945-check

Local read-only scanner for CVE-2026-42945 (NGINX Rift) that checks NGINX, OpenResty, and Tengine instances for vulnerable rewrite configurations…

configuration-auditingscripting-automationstatic-analysis+3
3 months ago
Tyr preview

Tyr

GitLabcyberactivity/tyr

Tools collection to explore CVE and theirs associated data.

information-gatheringthreat-intelligenceutilities-frameworks+1
3 months ago
auditd preview

auditd

GitHubneo23x0/auditd

Best Practice Auditd Configuration

configuration-auditingdefensive-toolsforensics+3
1.9k3 months ago
SharkMCP preview

SharkMCP

GitHubweirdmachine64/sharkmcp

A swiss-knife MCP server for analysing PCAP files

ctfdigital-forensicseducation+6
733 months ago
CVE-2025-2563 preview

CVE-2025-2563

GitHubnxploited/cve-2025-2563

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

educationexploitationpayload-development+5
4 months ago
Previous1…345…18Next