Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
Zeek-Intelligence-Feeds preview

Zeek-Intelligence-Feeds

GitHubcriticalpathsecurity/zeek-intelligence-feeds

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

command-and-controlintrusion-detectionnetwork-security+3
399
15h 53m ago
IG-Detective preview

IG-Detective

GitHubshredzwho/ig-detective

OSINT tool researched and designed to hunt down IG handles

educationfingerprint-spoofingforensics+7
1523 days ago
querytool preview

querytool

GitHuboryon-osint/querytool

Querytool is an OSINT framework based on Google Spreadsheet. With this tool you can perform complex search of terms, people, email addresses, files…

curated-resourceseducationinformation-gathering+3
3187 days ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
28 days ago
EvilFontTool preview

EvilFontTool

GitHubdoctoreww/evilfonttool

A font-based deception tool for red teaming, security research, and whatever else.

adversarial-attackai-securityeducation+3
30611 days ago
poc-CVE-2026-64638- preview

poc-CVE-2026-64638-

GitHubmohwahyudi/poc-cve-2026-64638-

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

exploitationpayload-generationpenetration-testing+5
12 days ago
tookie-osint preview

tookie-osint

GitHubalfredredbird/tookie-osint

Tookie is a advanced OSINT information gathering tool that finds social media accounts based on inputs.

information-gatheringosintosint-social-engineering+2
2.8k1 month ago
007-TheBond preview

007-TheBond

GitHubdeadshot0x7/007-thebond

This Script will help you to gather information about your victim or friend.

dns-subdomain-enumerationeducationemail-harvesting+5
1.5k1 month ago
Blind-Trust-CVE-2024-21413-Research preview

Blind-Trust-CVE-2024-21413-Research

GitHubh1ssbl1tz/blind-trust-cve-2024-21413-research

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

educationemail-securityexploitation+7
1 month ago
osintnet-public preview

osintnet-public

GitHubosintnet/osintnet-public

OsintNET is a browser-based OSINT platform for domain intelligence, website risk scanning, SERP discovery, image intelligence and AI image detection.

ai-securitydigital-forensicsdns-analysis+8
12 months ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+7
3.9k2 months ago
RedRoot preview

RedRoot

GitHubagampreet-singh/redroot

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

ctfexploit-frameworksfuzzing+9
174 months ago
URL_CHECKER preview

URL_CHECKER

GitHubmannansainicyber/url_checker
api-security-testingeducationmachine-learning+3
15 months ago
365-Stealer preview

365-Stealer

GitHubalteredsecurity/365-stealer

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

cloud-securitypenetration-testingphishing+1
5855 months ago
longtongue preview

longtongue

GitHubedoardottt/longtongue

Generate customized Password/Passphrase wordlist based on target information

information-gatheringpassword-attackspassword-cracking+1
1095 months ago
AzureADEnumeration preview

AzureADEnumeration

GitHublogisek/azureadenumeration

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

cloud-infrastructure-securitycloud-securitydns-analysis+6
796 months ago
DraculaOS preview

DraculaOS

GitHubemrekybs/draculaos

Dracula OS is a Linux operating system meticulously designed for OSINT (Open Source Intelligence) and Cyber ​​Intelligence missions.

curated-resourceseducationemail-harvesting+9
948 months ago
whoami-project preview

whoami-project

GitHubowerdogan/whoami-project

Whoami provides enhanced privacy, anonymity for Debian and Arch based linux distributions

anti-botdefensive-toolsids-ips-evasion+4
2.3k1 year ago
Previous123Next