Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
167 results
sdnpwn preview

sdnpwn

GitHubsmythtech/sdnpwn

An SDN penetration testing toolkit

exploitationnetwork-securitypenetration-testing+2
1151 year ago
CVE-2021-4044 preview

CVE-2021-4044

GitHubphirojshah/cve-2021-4044
educationnetwork-securityscripting-automation+1
1 year ago
cbrutekrag preview

cbrutekrag

GitHubmatricali/cbrutekrag

Penetration tests on SSH servers using brute force or dictionary attacks. Written in C.

network-securitypassword-attackspenetration-testing
1752 years ago
atomic-operator preview
Archived

atomic-operator

GitHubswimlane/atomic-operator

A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.

cloud-securitydefensive-toolseducation+3
1562 years ago
web-application-firewall- preview

web-application-firewall-

GitHubnithylesh/web-application-firewall-

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

educationexploitationids-ips-evasion+5
32 years ago
huskyCI preview

huskyCI

GitHubglobocom/huskyci

Performing security tests inside your CI

code-analysisdevsecopssecret-detection+2
5962 years ago
Aggressor-Aggregator preview

Aggressor-Aggregator

GitHubgmh5225/aggressor-aggregator

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

penetration-testing-frameworksred-teamingscripting-automation
2 years ago
CoercedPotatoRDLL preview

CoercedPotatoRDLL

GitHubsokarepo/coercedpotatordll

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

exploitationpayload-developmentpenetration-testing+4
2272 years ago
Mindmaps preview

Mindmaps

GitHubsynacktiv/mindmaps

Azure mindmap for penetration tests

cloud-securitycurated-resourceseducation+3
2332 years ago
CVE-2023-47119 preview

CVE-2023-47119

GitHubbaadmaro/cve-2023-47119

A POC for CVE-2023-47119

educationexploitationlabs-practice+2
22 years ago
dirhunt preview

dirhunt

GitHubnekmo/dirhunt

Find web directories without bruteforce

crawlerinformation-gatheringpenetration-testing+2
2.0k3 years ago
msdat preview

msdat

GitHubquentinhardy/msdat

MSDAT: Microsoft SQL Database Attacking Tool

database-securityexploitationinformation-gathering+3
1.0k3 years ago
PurpleKeep preview

PurpleKeep

GitHubretrospected/purplekeep

Providing Azure pipelines to create an infrastructure and run Atomic tests.

cloud-securityeducationincident-response+4
533 years ago
CMD_Bypass_Assessment preview

CMD_Bypass_Assessment

GitHubalperenugurlu/cmd_bypass_assessment

PowerShell script that automatically tests CMD bypass methods on Windows, evaluates results, calculates a security score, and provides hardening…

configuration-auditingdefensive-toolseducation+1
113 years ago
Wordpress-Vulnerability-Identification-Scripts preview

Wordpress-Vulnerability-Identification-Scripts

GitHubthatonesecguy/wordpress-vulnerability-identification-scripts

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

exploitationinformation-gatheringreconnaissance+2
23 years ago
ftw preview
Archived

ftw

GitHubfastly/ftw

Framework for Testing WAFs (FTW!)

devsecopspenetration-testingvulnerability-scanners+2
2633 years ago
OffensiveNotion preview
Archived

OffensiveNotion

GitHubmttaggart/offensivenotion

Notion as a platform for offensive operations

command-and-controlpayload-developmentpenetration-testing-frameworks+6
1.2k3 years ago
forbiddenpass preview

forbiddenpass

GitHubgotr00t0day/forbiddenpass

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

penetration-testingwaf-bypassweb-application-exploitation+1
2013 years ago
Previous1…567…10Next