Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
log4j preview

log4j

GitHubhassaanahmad813/log4j

Multithreaded Python scanner that detects Log4Shell (CVE-2021-44228) by sending crafted HTTP requests with JNDI payloads and monitoring DNS callbacks…

dns-analysisexploitationinformation-gathering+2
4 years ago
ams-failopen preview

ams-failopen

GitHubjgoyd/ams-failopen

Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade,…

dns-analysisexploitationpenetration-testing+3
31 year ago
CVE-2021-23017 preview

CVE-2021-23017

GitHubmoften/cve-2021-23017

NGINX DNS Overflow Vulnerability Check - CVE-2021-23017 PoC

dns-analysisexploitationpenetration-testing+2
1 year ago
vuln-scanner preview

vuln-scanner

GitHubzappaboy/vuln-scanner

Vulnerability Assessment Scanner with Report Generation

api-security-testingcloud-securityconfiguration-auditing+9
125 days ago
py-log4shellscanner preview

py-log4shellscanner

GitHubscheibling/py-log4shellscanner

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

dns-analysisexploitationfuzzing+3
4 years ago
PY-Log4j-RCE-Scanner preview

PY-Log4j-RCE-Scanner

GitHubmrharshvardhan/py-log4j-rce-scanner

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

dns-analysisexploitationreconnaissance+3
43 years ago
NSE-scripts preview

NSE-scripts

GitHubpsc4re/nse-scripts

NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473

dns-analysisexploitationinformation-gathering+5
1625 years ago
log4j2burpscanner preview

log4j2burpscanner

GitHubjeromeyoung/log4j2burpscanner

CVE-2021-44228,log4j2 burp插件 Java版本,dnslog选取了非dnslog.cn域名

dns-analysisexploitationpenetration-testing+3
314 years ago
log4jcheck preview

log4jcheck

GitHubnorthwavesecurity/log4jcheck

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

dns-analysisexploitationinformation-gathering+3
1274 years ago
CVE-2026-48205 preview

CVE-2026-48205

GitHuboscerd/cve-2026-48205

Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via…

dns-analysisexploitationreconnaissance+2
12 months ago
CVE-2024-55211 preview

CVE-2024-55211

GitHubmicaelmaciel/cve-2024-55211

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

authentication-authorizationdns-analysisexploitation+3
211 months ago
CVE-2020-1350-Fix preview

CVE-2020-1350-Fix

GitHubsimeononsecurity/cve-2020-1350-fix

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

configuration-auditingdns-analysisincident-response+3
26 years ago
CallStranger preview

CallStranger

GitHubyunuscadirci/callstranger

Vulnerability checker for Callstranger (CVE-2020-12695)

data-exfiltrationdns-analysisiot-security+3
4035 years ago
nmap preview

nmap

GitHubnmap/nmap

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

bluetooth-securitydatabase-securitydata-exfiltration+18
13.7k1 day ago
MyLog4Shell preview

MyLog4Shell

GitHubkal1gh0st/mylog4shell

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

dns-analysisexploitationinformation-gathering+3
14 years ago
dRMM-CVE-2020-1350-response preview

dRMM-CVE-2020-1350-response

GitHubjmaddington/drmm-cve-2020-1350-response

Registry-based mitigation script for CVE-2020-1350 Windows DNS Server RCE vulnerability, applying Microsoft's recommended workaround without server…

configuration-auditingdns-analysisincident-response+2
6 years ago
vaas-cve-2015-5477 preview

vaas-cve-2015-5477

GitHubhmlio/vaas-cve-2015-5477

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

container-securitydns-analysiseducation+3
111 years ago
bug-bounty-reports-desai-vinayak preview

bug-bounty-reports-desai-vinayak

GitHubdesaivinayak449/bug-bounty-reports-desai-vinayak

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

cloud-securitycurated-resourcesdns-analysis+6
11 months ago
Previous123Next