Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
88 results
reverse-engineering-browser preview

reverse-engineering-browser

GitHubsunghoojung/reverse-engineering-browser

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

code-analysisdebuggersdynamic-analysis-sandboxing+9
5
1 day ago
cve-2026-80428-ctf preview

cve-2026-80428-ctf

GitHubshivammittal2403/cve-2026-80428-ctf

Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.

container-securityctfdynamic-analysis-sandboxing+5
17 days ago
meowEye preview

meowEye

GitHubeslam3kl/meoweye

MeowEye is a real-time scanner for identifying multiple web vulnerabilities in live applications.

dynamic-analysis-sandboxingfuzzingpenetration-testing+3
31 year ago
CVE-2025-55182-Exploit-PoC-Scanner preview

CVE-2025-55182-Exploit-PoC-Scanner

GitHubzemarkhos/cve-2025-55182-exploit-poc-scanner

Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and…

command-and-controldynamic-analysis-sandboxingeducation+7
210 months ago
nginx-cve-2026-42945-poc preview

nginx-cve-2026-42945-poc

GitHubforxiucn/nginx-cve-2026-42945-poc

Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via…

binary-exploitationcontainer-securitydynamic-analysis-sandboxing+5
14 months ago
CVE-2026-2587-Exploit-POC preview

CVE-2026-2587-Exploit-POC

GitHubbhanunamikaze/cve-2026-2587-exploit-poc

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

code-analysisdynamic-analysis-sandboxingeducation+6
14 months ago
CVE-2019-18935 preview

CVE-2019-18935

GitHubalanbarret/cve-2019-18935

Nuclei template and validation scripts for detecting CVE-2019-18935, a critical .NET deserialization RCE in Telerik UI for ASP.NET AJAX, with…

dynamic-analysis-sandboxingeducationexploitation+4
110 months ago
CVE-2025-4427-CVE-2025-4428 preview

CVE-2025-4427-CVE-2025-4428

GitHubrxerium/cve-2025-4427-cve-2025-4428

Detection for CVE-2025-4427 and CVE-2025-4428

code-analysisdynamic-analysis-sandboxingexploitation+3
11 months ago
Fermion preview

Fermion

GitHubfuzzysecurity/fermion

Fermion, an electron wrapper for Frida & Monaco.

android-securitybinary-analysisdebuggers+4
7031 year ago
snapchange preview

snapchange

GitHubawslabs/snapchange

Lightweight fuzzing of a memory snapshot using KVM

debuggersdynamic-analysis-sandboxingdynamic-code-analysis+3
4722 years ago
WSSAT preview

WSSAT

GitHubyalcinyolalan/wssat

WEB SERVICE SECURITY ASSESSMENT TOOL

api-security-testingdynamic-analysis-sandboxinginformation-gathering+3
3885 years ago
JAW preview

JAW

GitHubsoheilkhodayari/jaw

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

code-analysiscrawlerdatabase-security+5
1187 months ago
poc-cve-2025-55182 preview

poc-cve-2025-55182

GitHubkoadt/poc-cve-2025-55182

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

code-analysisctfdynamic-analysis-sandboxing+7
156 months ago
Next.js-RSC-RCE-Scanner-Burp-Suite-Extension preview

Next.js-RSC-RCE-Scanner-Burp-Suite-Extension

GitHubtobiasguta/next.js-rsc-rce-scanner-burp-suite-extension

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

dynamic-analysis-sandboxingexploitationpenetration-testing+3
2310 months ago
log4j-Scan-Burpsuite preview

log4j-Scan-Burpsuite

GitHubsnow0715/log4j-scan-burpsuite

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

dynamic-analysis-sandboxingexploitationpenetration-testing+3
134 years ago
agentsh preview

agentsh

GitHubcanyonroad/agentsh

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

ai-securityauthentication-authorizationcloud-security+7
38918 days ago
Vega preview

Vega

GitHubsubgraph/vega

Subgraph Vega

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
36210 years ago
LLMMap preview

LLMMap

GitHubhellsender01/llmmap

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

ai-securityapi-security-testingdynamic-analysis-sandboxing+6
2076 months ago
Previous12345Next