Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
186 results
EternalView preview

EternalView

GitHubrpranshu/eternalview

EternalView is an all in one basic information gathering and vulnerability assessment tool

dns-analysiseducationinformation-gathering+4
151
6 years ago
CVE-2025-60791 preview

CVE-2025-60791

GitHubsmarttfoxx/cve-2025-60791

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound…

debuggerseducationexploitation+3
210 months ago
SSI-CVE-2022-21661 preview

SSI-CVE-2022-21661

GitHubwellingtonespindula/ssi-cve-2022-21661

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.

educationexploitationlabs-practice+3
62 years ago
CVE-2026-6356 preview

CVE-2026-6356

GitHubpenguinsecq/cve-2026-6356

Exploit PoC of CVE-2026-6356

educationexploitationpenetration-testing+3
3 months ago
CVE-2014-2383-LFI-to-RCE-Escalation preview

CVE-2014-2383-LFI-to-RCE-Escalation

GitHubrelativ3pa1n/cve-2014-2383-lfi-to-rce-escalation
educationexploitationpayload-development+3
13 years ago
traveller-htb preview

traveller-htb

GitHubsharma01672/traveller-htb

Traveller is an Easy Linux machine featuring a Joomla 4.2.7 travel booking website vulnerable to CVE-2023-23752, an unauthenticated REST API…

educationexploitationinformation-gathering+6
1 month ago
CVE-2022-0944_RCE_Automation preview

CVE-2022-0944_RCE_Automation

GitHubphilip-otter/cve-2022-0944_rce_automation

PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: …

educationexploitationpenetration-testing+2
1 year ago
CVE-2024-44541 preview

CVE-2024-44541

GitHubpointedsec/cve-2024-44541

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

educationexploitationpassword-cracking+3
1 year ago
CVE-2024-10542 preview

CVE-2024-10542

GitHububaydev/cve-2024-10542

WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation

authenticationeducationexploitation+3
31 year ago
velociraptor preview

velociraptor

GitHubvelocidex/velociraptor

Digging Deeper....

digital-forensicseducationforensics+2
4.2k2 days ago
Nmap-Cheat-Sheet preview

Nmap-Cheat-Sheet

GitHubnu11secur1ty/nmap-cheat-sheet
curated-resourceseducationinformation-gathering+6
64 years ago
CVE-2023-36159 preview

CVE-2023-36159

GitHubunknown00759/cve-2023-36159
educationpenetration-testingvulnerability-analysis+2
3 years ago
MobileApp-Pentest-Cheatsheet preview

MobileApp-Pentest-Cheatsheet

GitHubtanprathan/mobileapp-pentest-cheatsheet

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

android-securitycurated-resourcesdynamic-code-analysis+9
5.3k2 years ago
CVE-2023-25292 preview

CVE-2023-25292

GitHubbrainkok/cve-2023-25292

Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive…

educationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2022-44268-automated-poc preview

CVE-2022-44268-automated-poc

GitHubashifcoder/cve-2022-44268-automated-poc

An information disclosure vulnerability that could be exploited to read arbitrary files from a server when parsing an image in Image Magic.

educationexploitationinformation-gathering+3
3 years ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
32.9k3 days ago
log4j preview

log4j

GitHubwortell/log4j

Repo containing all info, scripts, etc. related to CVE-2021-44228

curated-resourceseducationexploitation+6
104 years ago
ProxyLogon preview

ProxyLogon

GitHubimmersive-labs-sec/proxylogon

Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange

educationexploitationlabs-practice+2
35 years ago
Previous1234…11Next