Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
5129 results
vuln-list-redhat preview

vuln-list-redhat

GitHubaquasecurity/vuln-list-redhat

Red Hat security advisories

information-gatheringthreat-feeds-aggregatorsthreat-intelligence+1
156h 52m ago
cve-2016-1764 preview

cve-2016-1764

GitHubmoloch--/cve-2016-1764

Extraction of iMessage Data via XSS

data-exfiltrationexploitationinformation-gathering+4
5110 years ago
CloudPrivs preview

CloudPrivs

GitHubabstractclass/cloudprivs

Determine privileges from cloud credentials via brute-force testing.

cloud-securityinformation-gatheringpenetration-testing+2
691 month ago
CVE-2021-43008-AdminerRead preview

CVE-2021-43008-AdminerRead

GitHubp0dalirius/cve-2021-43008-adminerread

Exploit tool for CVE-2021-43008 Adminer 1.0 up to 4.6.2 Arbitrary File Read vulnerability

exploitationinformation-gatheringpenetration-testing+3
852 years ago
Apache-Struts-Shodan-Exploit preview

Apache-Struts-Shodan-Exploit

GitHub649/apache-struts-shodan-exploit

This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.

exploitationinformation-gatheringpenetration-testing+3
568 years ago
RFCpwn preview

RFCpwn

GitHubicryo/rfcpwn

An enumeration and exploitation toolkit using RFC calls to SAP

exploitationinformation-gatheringpassword-cracking+2
406 years ago
reportly preview

reportly

GitHubsap8899/reportly

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

cloud-securityidentity-access-managementincident-response+2
963 years ago
GDir-Thief preview

GDir-Thief

GitHubantman1p/gdir-thief

Red Team tool for exfiltrating the target organization's Google People Directory that you have access to, via Google's API.

data-exfiltrationinformation-gatheringosint+1
585 years ago
AutoBrowser preview

AutoBrowser

GitHubel3ct71k/autobrowser

AutoBrowser Screenshot

information-gatheringpenetration-testingreconnaissance+1
499 years ago
mapsdumper preview

mapsdumper

GitHubtegal1337/mapsdumper

Dump place details from Google Maps like phone,email,website,and reviews

crawleremail-harvestinginformation-gathering+1
721 year ago
CVE-2024-47176-Scanner preview

CVE-2024-47176-Scanner

GitHubmalwaretech/cve-2024-47176-scanner

A simple scanner for identifying vulnerable cups-browsed instances on your network

exploitationinformation-gatheringnetwork-security+3
661 year ago
netstat2neo4j preview

netstat2neo4j

GitHubtrinitor/netstat2neo4j

create cypher create statements for neo4j out of netstat files from multiple machines

information-gatheringlog-analysisnetwork-forensics
415 years ago
PyADRecon preview

PyADRecon

GitHubl4rm4nd/pyadrecon

Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX +…

authenticationinformation-gatheringpenetration-testing+4
682 months ago
Firebase-Extractor preview

Firebase-Extractor

GitHubviperbluff/firebase-extractor

A tool written in python for scraping firebase data

data-exfiltrationinformation-gatheringmobile-security+2
436 years ago
CVE-2026-34908-check preview

CVE-2026-34908-check

GitHubbishopfox/cve-2026-34908-check

Safely detect whether a UniFi OS Server is vulnerable to CVE-2026-34908

exploitationinformation-gatheringpenetration-testing+3
663 months ago
InfraHunter preview

InfraHunter

GitHubmontysecurity/infrahunter

Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.

information-gatheringosintphishing-tools+2
642 years ago
Forerunner preview

Forerunner

GitHubjasondrawdy/forerunner

Fast and extensible network scanning library featuring multithreading, ping probing, and scan fetchers.

information-gatheringnetwork-mappingport-scanning+2
396 years ago
Egresser preview

Egresser

GitHubcyberisltd/egresser

Client/server scripts designed to test outbound (egress) firewall rules.

information-gatheringnetwork-securitypenetration-testing+2
3713 years ago
Previous1…959697…100Next