Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
61 results
monitor preview

monitor

GitHubbetterdb-inc/monitor

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

anomaly-detectiondatabase-securitylog-analysis
1.3k1 day ago
ecapture preview

ecapture

GitHubgojue/ecapture

Capture SSL/TLS plaintext with eBPF—no MITM proxy or custom CA installation. Supports Linux and Android on x86_64 and arm64.

android-securitydatabase-securitydynamic-analysis-sandboxing+3
15.5k20h 28m ago
prowler preview

prowler

GitHubprowler-cloud/prowler

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+10
15.0k20h 37m ago
EDRaser preview

EDRaser

GitHubsafebreach-labs/edraser

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

database-securitypost-exploitation
3712 years ago
mariadb-13-rce-lab preview

mariadb-13-rce-lab

GitHubdinosn/mariadb-13-rce-lab

MariaDB 13.0.1-rc RCE lab — priv-esc + heap UAF + JOP chain to system() as uid 999(mysql) on stock Docker image. Found with RAPTOR and…

binary-exploitationdatabase-securityexploitation+5
672 months ago
mssqlbof preview

mssqlbof

GitHubmazx0p/mssqlbof

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

authenticationcommand-and-controldatabase-security+8
996 months ago
sccmsqlclient preview

sccmsqlclient

GitHubsynacktiv/sccmsqlclient

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

database-securityexploitationinformation-gathering+6
324 months ago
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE preview

CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE

GitHubjakabakos/cve-2023-27524-apache-superset-auth-bypass-and-rce

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

authentication-authorizationcommand-and-controldatabase-security+5
283 years ago
CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit preview

CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit

GitHubt0x1cx/cve-2021-36396-moodle-time-based-sqli-exploit

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

database-securityeducationexploitation+3
222 years ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
21 month ago
o5logon-fetch preview

o5logon-fetch

GitHubhantwister/o5logon-fetch

Attempts to exploit CVE-2012-3137 on vulnerable Oracle servers

database-securityexploitationpassword-cracking+2
312 years ago
CVE-2025-59213 preview

CVE-2025-59213

GitHubsynacktiv/cve-2025-59213

Unauthenticated SQL injection exploit for Microsoft Configuration Manager (SCCM) 2503, enabling arbitrary SQL execution on the site database via the…

database-securityexploitationpenetration-testing+2
34 months ago
nosqli-flintcms preview

nosqli-flintcms

GitHubnisaruj/nosqli-flintcms

Blind noSQL injection case study lab based on CVE-2018-3783

ctfdatabase-securityeducation+3
43 years ago
CVE-2025-46817 preview

CVE-2025-46817

GitHubdwisiswant0/cve-2025-46817

Proof-of-concept for Redis Lua unpack integer overflow (CVE-2025-46817) demonstrating stack blow-up and potential RCE on Redis 8.2.1.

binary-exploitationdatabase-securityexploitation+2
31 year ago
CVE-2026-69084-PoC preview

CVE-2026-69084-PoC

GitHubboreas37/cve-2026-69084-poc

CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.

database-securityexploitationpenetration-testing+3
11 month ago
redis-post-exploitation preview

redis-post-exploitation

GitHubknqyf263/redis-post-exploitation

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

database-securityeducationexploitation+3
35 years ago
CVE-2024-55963 preview

CVE-2024-55963

GitHubsuperswan/cve-2024-55963

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

database-securityexploitationmisconfiguration+5
21 year ago
CVE-2025-10351-POC preview

CVE-2025-10351-POC

GitHubivansmc/cve-2025-10351-poc

Exploit for CVE-2025-10351. SQL Injection on Melis Platform Framework

database-securityexploitationinformation-gathering+3
17 months ago
Previous1234Next