Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
118 results
CVE-2022-41678 preview

CVE-2022-41678

GitHubmbadanoiu/cve-2022-41678

CVE-2022-41678: Dangerous MBeans Accessible via Jolokia API in Apache ActiveMQ

data-exfiltrationexploitationremote-access-tool+2
2
1 year ago
CVE-2025-25279 preview

CVE-2025-25279

GitHubnumanturle/cve-2025-25279

Proof-of-concept for CVE-2025-25279: path traversal in Mattermost Boards allows arbitrary file read via crafted import archive and board duplication.

data-exfiltrationexploitationinformation-gathering+3
41 year ago
Rogue-MySql-Server preview

Rogue-MySql-Server

GitHubal1ex/rogue-mysql-server

Rogue-MySql-Server

database-securitydata-exfiltrationexploitation+3
56 years ago
loki preview

loki

GitHubnccgroup/loki

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses

data-exfiltrationlateral-movementpenetration-testing+3
6310 years ago
POC-ES-File-Explorer-CVE-2019-6447 preview

POC-ES-File-Explorer-CVE-2019-6447

GitHubjulio-cfa/poc-es-file-explorer-cve-2019-6447

Bash PoC script exploiting CVE-2019-6447 in ES File Explorer to list files, photos, videos, apps, and download files from vulnerable Android devices.

android-securitydata-exfiltrationexploitation+3
4 years ago
CVE-2024-34693 preview

CVE-2024-34693

GitHubmr-r00t11/cve-2024-34693

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

database-securitydata-exfiltrationexploitation+3
2 years ago
CVE-2024-12849-Poc preview

CVE-2024-12849-Poc

GitHubnxploited/cve-2024-12849-poc

Exploit for CVE-2024-12849, an arbitrary file read vulnerability in WordPress Error Log Viewer plugin. Downloads sensitive files via unauthenticated…

data-exfiltrationexploitationpenetration-testing+2
1 year ago
ntfsDump preview

ntfsDump

GitHub3gstudent/ntfsdump

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

data-exfiltrationdata-recoverydigital-forensics+3
1195 years ago
ApacheSkywalking preview

ApacheSkywalking

GitHubvulnmachines/apacheskywalking

ApacheSKywalking SQLi to Read sensitive file

data-exfiltrationexploitationinformation-gathering+3
34 years ago
CVE-2024-36991-Tool preview

CVE-2024-36991-Tool

GitHubthestingr/cve-2024-36991-tool

This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive…

data-exfiltrationexploitationinformation-gathering+3
210 months ago
CVE-2024-56067 preview

CVE-2024-56067

GitHubrandomrobbiebf/cve-2024-56067

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download

data-exfiltrationmisconfigurationvulnerability-analysis+2
1 year ago
tweetable-polyglot-png preview

tweetable-polyglot-png

GitHubdavidbuchanan314/tweetable-polyglot-png

Pack up to 3MB of data into a tweetable PNG polyglot file.

data-exfiltrationosintsteganography
2.6k5 years ago
duckLogger preview

duckLogger

GitHubitsmmdoha/ducklogger

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

command-and-controldata-exfiltrationembedded-systems-security+8
874 months ago
http-protocol-exfil preview

http-protocol-exfil

GitHubricardojoserf/http-protocol-exfil

Exfiltrate files using the HTTP protocol version ("HTTP/1.0" is a 0 and "HTTP/1.1" is a 1)

data-exfiltrationnetwork-security
244 years ago
CVE-2022-26159-Ametys-Autocompletion-XML preview

CVE-2022-26159-Ametys-Autocompletion-XML

GitHubp0dalirius/cve-2022-26159-ametys-autocompletion-xml

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

crawlerdata-exfiltrationexploitation+3
144 years ago
SharpML preview

SharpML

GitHubhunniccyber/sharpml

Machine Learning Network Share Password Hunting Toolkit

data-exfiltrationinformation-gatheringmachine-learning+1
1286 years ago
CVE-2020-12116 preview

CVE-2020-12116

GitHubbeetlechunks/cve-2020-12116

Proof of concept code to exploit CVE-2020-12116: Unauthenticated arbitrary file read on ManageEngine OpManger.

data-exfiltrationexploitationinformation-gathering+3
306 years ago
CVE-2009-0229-PoC preview

CVE-2009-0229-PoC

GitHubzveriu/cve-2009-0229-poc

PoC for CVE-2009-0229 "Print Spooler Read File Vulnerability" LPE AFR (related to CVE-2020-1048)

data-exfiltrationexploitationlateral-movement+4
36 years ago
Previous1234567Next