Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
nuclei-wordfence-cve preview

nuclei-wordfence-cve

GitHubtopscoder/nuclei-wordfence-cve

80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

crawlerexploitationinformation-gathering+3
1.3k
5h 5m ago
openshield preview

openshield

GitHubowasp/openshield

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

cloud-securityconfiguration-auditingcryptography+4
562 days ago
bugsy preview

bugsy

GitHubmobb-dev/bugsy

Automatic security vulnerability remediation for your code.

ai-securitycode-analysisdevsecops+2
6918 days ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
26 days ago
nelson preview

nelson

GitHubswelljoe/nelson

Finding vulnerabilities through dumb brute force

ai-securitycode-analysiseducation+3
551 month ago
reverse-ip-new-api preview

reverse-ip-new-api

GitHubjenderal92/reverse-ip-new-api

This tool is used to perform reverse IP lookups— searching for all domains hosted on one IP address.

information-gatheringnetwork-mappingosint+1
33 months ago
POC_CVE-2026-41940 preview

POC_CVE-2026-41940

GitHubimbas007/poc_cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

command-and-controlexploitationpenetration-testing+3
4 months ago
Lfi-Space preview

Lfi-Space

GitHubcapture0x/lfi-space

Automated Local File Inclusion (LFI) vulnerability scanner with Google Dork search and targeted URL scan modes for web application security testing.

information-gatheringpenetration-testingvulnerability-scanners+1
1124 months ago
SSH-Snake preview
Archived

SSH-Snake

GitHubmegamansec/ssh-snake

SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.

information-gatheringlateral-movementnetwork-mapping+5
2.3k5 months ago
RDWAtool preview

RDWAtool

GitHubp0dalirius/rdwatool

A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application

information-gatheringpassword-attacksreconnaissance+1
1228 months ago
erl_mouse preview

erl_mouse

GitHubm0usem0use/erl_mouse

python script to find vulnerable targets of CVE-2025-32433

exploitationinformation-gatheringnetwork-mapping+3
51 year ago
Sububy preview

Sububy

GitHuba3h1nt/sububy

Modular subdomain enumeration suite with certificate transparency, DNS brute-force, and API-based discovery. Includes post-enumeration modules for…

dns-subdomain-enumerationinformation-gatheringosint+2
71 year ago
Enumprotections_BOF preview

Enumprotections_BOF

GitHuboctoberfest7/enumprotections_bof

A BOF to enumerate system process, their protection levels, and more.

information-gatheringpenetration-testingpost-exploitation+4
1261 year ago
CVE-2024-9166 preview

CVE-2024-9166

GitHubandrysqui/cve-2024-9166

A vulnerability scanner that searches for the CVE-2024-9166 vulnerability on websites, more info about this vulnerability here:…

exploitationinformation-gatheringpenetration-testing+3
41 year ago
sh00t preview

sh00t

GitHubpavanw3b/sh00t

Security Testing is not as simple as right click > Scan. It's messy, a tough game. What if you had missed to test just that one thing and had to…

educationpenetration-testingutilities-frameworks+2
2762 years ago
zizzania preview

zizzania

GitHubcyrus-and/zizzania

Automated DeAuth attack

information-gatheringpenetration-testingwi-fi-auditing+1
3202 years ago
evildork preview

evildork

GitHubfricciolosa-red-team/evildork

Automated Google dorking tool for extracting leaked secrets, personal information, and subdomains from a target domain or individual, outputting…

dns-subdomain-enumerationinformation-gatheringosint+2
953 years ago
scrying preview

scrying

GitHubnccgroup/scrying

A tool for collecting RDP, web and VNC screenshots all in one place

information-gatheringnetwork-securitypenetration-testing+2
4753 years ago
Previous12Next