Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
PowerUpSQL preview

PowerUpSQL

GitHubnetspi/powerupsql

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

configuration-auditingdatabase-securityinformation-gathering+4
2.7k
1 year ago
mssqlproxy preview

mssqlproxy

GitHubblackarrowsec/mssqlproxy

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

database-securitylateral-movementpenetration-testing+1
7745 years ago
mssqlbof preview

mssqlbof

GitHubmazx0p/mssqlbof

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

authenticationcommand-and-controldatabase-security+8
1004 months ago
SQLC2 preview

SQLC2

GitHubnetspi/sqlc2

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

cloud-securitycommand-and-controldatabase-security+3
753 years ago
MSSQLand preview

MSSQLand

GitHubn3rada/mssqland

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

configuration-auditingdatabase-securityimpersonation-tools+6
7526 days ago
carina preview

carina

GitHubcodelatteid/carina

Webshell, Virtual Private Server (VPS) and cPanel Database

command-and-controldatabase-securitypenetration-testing+1
383 years ago
audit_couchdb preview

audit_couchdb

GitHubiriscouch/audit_couchdb

Detect security issues, large or small, in a CouchDB server

configuration-auditingdatabase-securitymisconfiguration+1
3714 years ago
xolo preview

xolo

GitHubetlownoise/xolo

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…

database-securityinformation-gatheringpenetration-testing
195 years ago
audit_couchdb preview

audit_couchdb

GitHubjhs/audit_couchdb

Detect security issues in an Apache CouchDB server

configuration-auditingdatabase-securityinformation-gathering+3
1612 years ago
CVE-2024-34693 preview

CVE-2024-34693

GitHubmbadanoiu/cve-2024-34693

CVE-2024-34693: Server Arbitrary File Read in Apache Superset

database-securitydata-exfiltrationexploitation+3
102 years ago
CVE-2008-5416 preview

CVE-2008-5416

GitHubsecforce/cve-2008-5416

Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection

database-securityexploitationpenetration-testing+2
39 years ago
CVE-2010-3600-PythonHackOracle11gR2 preview

CVE-2010-3600-PythonHackOracle11gR2

GitHublaitrungminhduc/cve-2010-3600-pythonhackoracle11gr2

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).

database-securityexploitationpenetration-testing+1
28 years ago
POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0 preview

POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0

GitHubheavyghost-le/poc_sql_injection_in_parse_server_prior_6.5.7_-_7.1.0

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

database-securityexploitationinformation-gathering+3
110 months ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
sqlwinds preview

sqlwinds

GitHubblue0x1/sqlwinds

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

configuration-auditingdatabase-securitydata-exfiltration+7
11 months ago
postgres-bruteforcer preview

postgres-bruteforcer

GitHubrandomrobbiebf/postgres-bruteforcer

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

authenticationdatabase-securityexploitation+2
3 years ago
MultiExploit preview

MultiExploit

GitHubvesu-nights/multiexploit

CVE-2023-21173 Exploit - Remote Code Execution in SQL Server 2022

authenticationdatabase-securityexploitation+3
1 year ago
CVE-2024-34693 preview

CVE-2024-34693

GitHubmr-r00t11/cve-2024-34693

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

database-securitydata-exfiltrationexploitation+3
2 years ago
Previous123Next