Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
131 results
cve-2020-13777 preview

cve-2020-13777

GitHub0xxon/cve-2020-13777

Zeek script to detect servers vulnerable to CVE-2020-13777

dns-analysisintrusion-detectionnetwork-security+2
4
11 months ago
log4j-urlscanner preview

log4j-urlscanner

GitHubwoahd/log4j-urlscanner

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading

dns-analysisexploitationinformation-gathering+3
14 years ago
log4j preview

log4j

GitHubhassaanahmad813/log4j

Multithreaded Python scanner that detects Log4Shell (CVE-2021-44228) by sending crafted HTTP requests with JNDI payloads and monitoring DNS callbacks…

dns-analysisexploitationinformation-gathering+2
4 years ago
MyLog4Shell preview

MyLog4Shell

GitHubkal1gh0st/mylog4shell

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

dns-analysisexploitationinformation-gathering+3
14 years ago
py-log4shellscanner preview

py-log4shellscanner

GitHubscheibling/py-log4shellscanner

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

dns-analysisexploitationfuzzing+3
4 years ago
UltraViolet preview

UltraViolet

GitHubyakushstanislav/ultraviolet

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

dns-analysisincident-responseiot-security+6
4413 days ago
CVE-2026-34835-Black-box-Analysis preview

CVE-2026-34835-Black-box-Analysis

GitHubcyber-note/cve-2026-34835-black-box-analysis

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

dns-analysiseducationpenetration-testing+3
62 months ago
CVE-2026-42527 preview

CVE-2026-42527

GitHuboscerd/cve-2026-42527

Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel

data-exfiltrationdns-analysisexploitation+3
1 month ago
cve-2026-5950-bind9-resolver-dos preview

cve-2026-5950-bind9-resolver-dos

GitHubbillybaraja/cve-2026-5950-bind9-resolver-dos

Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX).

defensive-toolsdns-analysiseducation+3
12 months ago
CallStranger preview

CallStranger

GitHubyunuscadirci/callstranger

Vulnerability checker for Callstranger (CVE-2020-12695)

data-exfiltrationdns-analysisiot-security+3
4045 years ago
dnspooq preview

dnspooq

GitHubknqyf263/dnspooq

DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685)

dns-analysiseducationexploitation+2
1015 years ago
NSE-scripts preview

NSE-scripts

GitHubpsc4re/nse-scripts

NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473

dns-analysisexploitationinformation-gathering+5
1625 years ago
log4shell-tools preview

log4shell-tools

GitHubalexbakker/log4shell-tools

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

dns-analysisexploitationpenetration-testing+3
862 years ago
CVE-2020-8617 preview

CVE-2020-8617

GitHubknqyf263/cve-2020-8617

Proof-of-concept exploit for CVE-2020-8617 targeting BIND DNS servers via TKEY transaction abuse, with Docker-based lab environment for testing.

dns-analysiseducationexploitation+2
456 years ago
CVE-2023-50387 preview

CVE-2023-50387

GitHubknqyf263/cve-2023-50387

Educational proof-of-concept for the DNSSEC KeyTrap vulnerability (CVE-2023-50387) with a Docker-based lab environment to demonstrate algorithmic…

dns-analysiseducationexploitation+3
452 years ago
CVE-2016-2776 preview

CVE-2016-2776

GitHubinfobyte/cve-2016-2776

CVE-2016-2776

dns-analysisexploitationexploit-frameworks+2
279 years ago
log4j2burpscanner preview

log4j2burpscanner

GitHubjeromeyoung/log4j2burpscanner

CVE-2021-44228,log4j2 burp插件 Java版本,dnslog选取了非dnslog.cn域名

dns-analysisexploitationpenetration-testing+3
324 years ago
ntpscanner preview

ntpscanner

GitHubdani87/ntpscanner

Scans NTP servers for CVE-2013-5211 NTP DDOS amplification vulnerability.

dns-analysisinformation-gatheringnetwork-security+2
1511 years ago
Previous12…8Next