Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
7458 results
nmap preview

nmap

GitHubullaakut/nmap

Idiomatic Go library for invoking a network scanner binary, enabling host discovery, port scanning, service/OS detection, and scripted vulnerability…

information-gatheringnetwork-mappingnetwork-security+3
1.1k
5 days ago
WPScan preview

WPScan

GitHubalessiodallapiazza/wpscan

WordPress security scanner that enumerates vulnerable plugins, themes, and users to identify misconfigurations and known vulnerabilities for…

information-gatheringpenetration-testingreconnaissance+3
3113 years ago
xpfarm preview

xpfarm

GitHuba3-n/xpfarm

Free XP on bug bounty, vulnerability scanning by wrapping well maintained tools, to perform automated tests. Alongside AI agents for binary analysis,…

ai-securitybinary-analysiseducation+6
444 months ago
omigood preview

omigood

GitHubmarcosimioni/omigood

OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team,…

cloud-securityexploitationinformation-gathering+3
204 years ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubrandomrobbiebf/cve-2024-10924

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
41 year ago
BAS-Guardian preview
Archived

BAS-Guardian

GitHubspinfosecurity/bas-guardian

Free BACnet/BMS vulnerability scanner for building automation systems. Detects CVE-2026-3611 (CVSS 10.0), CVE-2026-24060, and exposed HVAC/BAS…

defensive-toolsinformation-gatheringiot-security+6
122 days ago
Bug-Bounty-Arsenal-v.3 preview

Bug-Bounty-Arsenal-v.3

GitHubfoxvr-sudo/bug-bounty-arsenal-v.3

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

api-security-testingcrawlerdevsecops+8
1212 days ago
dirtycups preview

dirtycups

GitHubjimi2x/dirtycups

UDP-based scanner for CVE-2024-47176 that validates CUPS vulnerability by creating a local socket listener and triggering target responses.

exploitationnetwork-securitypenetration-testing+2
4 months ago
nray preview

nray

GitHubnray-scanner/nray

nray distributed port scanner

information-gatheringnetwork-mappingnetwork-security+3
1581 year ago
KisMac2 preview
Archived

KisMac2

GitHubigrsoft/kismac2

KisMAC is a free, open source wireless stumbling and security tool for Mac OS X.

information-gatheringnetwork-mappingpacket-sniffing-analysis+6
9178 years ago
NINJA-PingU preview
Archived

NINJA-PingU

GitHubowasp/ninja-pingu

High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

embedded-systems-securityinformation-gatheringnetwork-mapping+3
777 years ago
ronin preview

ronin

GitHubronin-rb/ronin

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

cryptographyctfdns-analysis+9
7588 months ago
SOC-Multitool preview

SOC-Multitool

GitHubzdhenard42/soc-multitool

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

incident-responseinformation-gatheringosint+1
4221 year ago
CVE-2026-23918-Elite-Auditor preview

CVE-2026-23918-Elite-Auditor

GitHubqassam-315/cve-2026-23918-elite-auditor

Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and…

information-gatheringpenetration-testingreconnaissance+3
64 months ago
SecurityManageFramwork preview

SecurityManageFramwork

GitHubwe1h0/securitymanageframwork

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management,…

configuration-auditingnetwork-mappingpassword-cracking+4
4316 years ago
hackersh preview

hackersh

GitHubikotler/hackersh

A free and open source command-line shell and scripting language designed especially for security testing

penetration-testingpenetration-testing-frameworksscripting-automation+3
12613 years ago
Refloow-Geo-Forensics preview

Refloow-Geo-Forensics

GitHubrefloow/refloow-geo-forensics

❤️ Free batch image & video geolocation digital forensics tool. Automatically extract EXIF data, visualize GPS coordinates on maps, and reconstruct…

digital-forensicseducationforensics+4
2211 day ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
16 days ago
Previous12…100Next