Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
344 results
FaceBrute preview

FaceBrute

GitHubemerinohdz/facebrute

Facebook brute forcer script

authenticationpassword-attackspenetration-testing+2
2814 years ago
certReport preview

certReport

GitHubsquiblydoo/certreport

A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.

hash-analysismalware-analysisthreat-intelligence
406 months ago
LabS4U2Self preview

LabS4U2Self

GitHubotterhacker/labs4u2self

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

authentication-authorizationdatabase-securityeducation+5
314 years ago
YARAify preview

YARAify

GitHubabusech/yaraify

Open YARA scan- and search engine

hash-analysismalware-analysisstatic-analysis+1
271 year ago
BruteForce-to-KeePass preview

BruteForce-to-KeePass

GitHubund3sc0n0c1d0/bruteforce-to-keepass

This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting…

exploitationpassword-crackingpenetration-testing+1
63 years ago
hikvision_brute preview

hikvision_brute

GitHubnanotrash/hikvision_brute

Brute Hikvision CAMS with CVE-2021-36260 Exploit

exploitationiot-securitypassword-attacks+3
33 years ago
WP-Contest-Gallery-28.1.4-Exploit preview

WP-Contest-Gallery-28.1.4-Exploit

GitHubcerberusmrxi/wp-contest-gallery-28.1.4-exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

exploitationpassword-crackingpayload-development+4
12 months ago
SSHUsernameBruter-SSHUB preview

SSHUsernameBruter-SSHUB

GitHubjoeblacksecurity/sshusernamebruter-sshub

Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473

exploitationnetwork-securitypassword-attacks+2
27 years ago
Penetration-Testing-Walkthrough-Hacksudo-Thor preview

Penetration-Testing-Walkthrough-Hacksudo-Thor

GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

ctfeducationexploitation+8
5 months ago
network-security-snort preview

network-security-snort

GitHubtaisa456/network-security-snort

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

defensive-toolseducationexploitation+6
4 months ago
apache-web-log-analysis-lab preview

apache-web-log-analysis-lab

GitHubpedrofbrm/apache-web-log-analysis-lab

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

educationlabs-practicelog-analysis+1
5 months ago
siem-threat-detection-lab preview

siem-threat-detection-lab

GitHubsarjanpatel22/siem-threat-detection-lab

Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE…

defensive-toolseducationincident-response+6
3 months ago
ZipRarHunter preview

ZipRarHunter

GitLabs_r_e_e_r_a_j/ziprarhunter

ZipRarHunter is a powerful command-line ethical hacking tool designed to crack passwords of ZIP and RAR archive files using a wordlist.

password-attackspassword-crackingpenetration-testing+1
15 months ago
ubuntu-privesc-lab preview

ubuntu-privesc-lab

GitHubvaibhavkrishna12004/ubuntu-privesc-lab

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

educationexploitationlabs-practice+8
6 months ago
HotelDruid-CVE-2021-42949 preview

HotelDruid-CVE-2021-42949

GitHubdhammon/hoteldruid-cve-2021-42949

Exploit for CVE-2021-42949 in HotelDruid v3.0.3, demonstrating predictable session token generation and authentication bypass via brute force.

authenticationexploitationpenetration-testing+2
4 years ago
CVE-2020-27747 preview

CVE-2020-27747

GitHubjet-pentest/cve-2020-27747

Possible Account Takeover | Brute Force Ability

authenticationexploitationpassword-attacks+2
5 years ago
bloodit preview

bloodit

GitHubbrunosergi/bloodit

Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

authenticationexploitationpenetration-testing+2
5 years ago
kippo-g0tmi1k preview
Archived

kippo-g0tmi1k

GitHubg0tmi1k/kippo-g0tmi1k

Medium-interaction SSH honeypot that logs brute force attacks and full attacker shell interactions, with customization options to reduce…

defensive-toolsincident-responseinformation-gathering+4
1312 years ago
Previous1…789…20Next