Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1161 results
CVE-2021-44228_scanner-main-Modified- preview

CVE-2021-44228_scanner-main-Modified-

GitHubalexpena5635/cve-2021-44228_scanner-main-modified-

Scans jar, war, and ear files for the presence of JndiLookup.class to detect applications vulnerable to CVE-2021-44228 (Log4Shell).

code-analysislog-analysisstatic-analysis+3
4 years ago
lightkeeper preview

lightkeeper

GitHubworksbutnottested/lightkeeper

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

binary-analysiscode-analysisdynamic-code-analysis+1
763 months ago
bip preview

bip

GitHubsynacktiv/bip

Object-oriented Python API to simplify interaction with IDA for reverse engineering, enabling plugin development and automation of disassembly…

binary-analysiscode-analysisreverse-engineering+2
2054 years ago
4062-1 preview

4062-1

GitHubngyanch/4062-1

CVE-2008-0128

code-analysisdevsecopssupply-chain-security+1
7 years ago
firstexecution preview

firstexecution

GitHubnccgroup/firstexecution

Collection of different ways to execute code outside of the expected entry points

binary-analysiscode-analysisexploitation+2
1613 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubcontrast-security-oss/cve-2021-44228

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

cloud-securitycode-analysisdevsecops+3
4 months ago
log4shell preview

log4shell

GitHubhozyx/log4shell

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

code-analysisdevsecopsstatic-analysis+3
4 years ago
log4shell-example preview

log4shell-example

GitHubchilit-nl/log4shell-example

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

code-analysiseducationexploitation+3
4 years ago
aura preview

aura

GitHubsourcecode-ai/aura

Python source code auditing and static analysis on a large scale

code-analysiseducationmalware-analysis+4
4932 years ago
CVE-2007-4559 preview

CVE-2007-4559

GitHubdepers-rus/cve-2007-4559

Proof-of-concept demonstrating CVE-2007-4559 path traversal in Python's tarfile module, allowing arbitrary file overwrite via malicious TAR archives.

code-analysiseducationexploitation+2
11 year ago
react-cve-2025-55182 preview

react-cve-2025-55182

GitHubamir-malek/react-cve-2025-55182

Detects and fixes CVE-2025-55182 (React2Shell) in React Server Components and Next.js apps. Scans package versions, suggests safe upgrades, and…

code-analysisdevsecopseducation+3
9 months ago
jenkinsci__workflow-cps-global-lib-plugin_CVE-2022-25174_544-vff04fa68714d preview

jenkinsci__workflow-cps-global-lib-plugin_CVE-2022-25174_544-vff04fa68714d

GitHubshoucheng3/jenkinsci__workflow-cps-global-lib-plugin_cve-2022-25174_544-vff04fa68714d

Exploit for CVE-2022-25174 in Jenkins Pipeline Shared Libraries plugin, demonstrating code injection via crafted library definitions for security…

code-analysisdevsecopseducation+2
1 year ago
HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892 preview

HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892

GitHubcertologists/http-request-for-php-object-injection-attack-on-cve-2023-41892

Demonstrates a PHP object injection attack targeting CVE-2023-41892, including exploitation techniques and mitigation strategies for securing PHP…

code-analysiseducationexploitation+2
2 years ago
CVE-2021-44228_scanner preview
Archived

CVE-2021-44228_scanner

GitHubcertcc/cve-2021-44228_scanner

Scanners for Jar files that may be vulnerable to CVE-2021-44228

code-analysisincident-responsestatic-analysis+3
3504 years ago
FindFunc preview

FindFunc

GitHubfelixber/findfunc

IDA Pro plugin for filtering functions by assembly patterns, byte sequences, string/name references, and size constraints, with rule-based search and…

binary-analysiscode-analysisdebuggers+2
36510 months ago
anteater preview
Archived

anteater

GitHubanteater/anteater

Anteater - CI/CD Gate Check Framework

code-analysisconfiguration-auditingdevsecops+6
1753 years ago
CVE-2022-22965_Spring4Shell preview

CVE-2022-22965_Spring4Shell

GitHubludovicpatho/cve-2022-22965_spring4shell

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

code-analysisexploitationpayload-development+3
24 years ago
CVE-2026-31431-old-python preview

CVE-2026-31431-old-python

GitHubgrishinpv/cve-2026-31431-old-python

Provides a ctypes wrapper for the splice syscall to enable exploitation of CVE-2026-31431 on Python versions below 3.10, tested on Python 3.7.3.

binary-exploitationcode-analysisexploitation+1
4 months ago
Previous1234…65Next