Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
469 results
react preview

react

GitHubjanhalendk/react

A OSINT project that explores how to dump data from React

educationinformation-gatheringosint+2
811 year ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubkento-sec/cve-2024-34102

Go-based exploit for CVE-2024-34102, an XXE vulnerability in Adobe Commerce leading to remote code execution. Supports single and batch URL scanning…

educationexploitationpenetration-testing+2
1 year ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubbughuntar/cve-2024-34102

Exploitation CVE-2024-34102

educationexploitationpenetration-testing+2
52 years ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubcythonic1/cve-2024-9264

A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.

educationexploitationpenetration-testing+2
31 year ago
avoidz preview

avoidz

GitHubm4sc3r4n0/avoidz

Avoidz tool to bypass most A.V softwares

educationexploit-frameworksids-ips-evasion+3
1399 years ago
FlowAnalyzer preview

FlowAnalyzer

GitHubmanuelberrueta/flowanalyzer

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

api-securityapi-security-testingauthentication-authorization+5
1842 years ago
echteeteepee preview

echteeteepee

GitHubperplext/echteeteepee

Go tool and Nuclei template for testing James Kettle's (CVE-2025-32094) HTTP/1.1 must die: the desync endgame

dynamic-analysis-sandboxingeducationfuzzing+3
61 year ago
exploit_cve-2021-29447 preview

exploit_cve-2021-29447

GitHubmega8bit/exploit_cve-2021-29447

Go-based exploit for CVE-2021-29447 targeting WordPress 5.6.2 with PHP 8. Generates a malicious .wav payload to retrieve arbitrary files from the…

educationexploitationpenetration-testing+2
73 years ago
OreNPMGuard preview

OreNPMGuard

GitHubrapticore/orenpmguard

Defense Against the Shai-Hulud Supply Chain Attack

code-analysisdevsecopseducation+6
139 months ago
Persistnux preview

Persistnux

GitHubgo-lanz/persistnux

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

container-escapedigital-forensicseducation+7
32 months ago
CVE-2025-5777-Exploit preview

CVE-2025-5777-Exploit

GitHubsoltanali0/cve-2025-5777-exploit

Async-based exploit tool for CVE-2025-5777 that detects and extracts leaked authentication tokens, internal IPs, and hidden endpoint paths from…

educationexploitationinformation-gathering+3
51 year ago
AdvPhishing preview

AdvPhishing

GitHubignitetch/advphishing

This is Advance Phishing Tool ! OTP PHISHING

educationimpersonation-toolsinformation-gathering+3
3.3k9 months ago
cnappgoat preview

cnappgoat

GitHubtenable/cnappgoat

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

cloud-infrastructure-securitycloud-securityctf+5
2982 years ago
CVE-2025-4123-Exploit preview

CVE-2025-4123-Exploit

GitHubmorphykutay/cve-2025-4123-exploit

Proof-of-concept tool that sends a crafted payload to a target and detects open redirect vulnerabilities by inspecting 301/302 responses and Location…

educationexploitationvulnerability-analysis+1
11 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubchocapikk/cve-2026-24061

Proof-of-concept exploit for GNU Inetutils telnetd authentication bypass (CVE-2026-24061) with Docker lab setup and Go PoC. Exploits NEW-ENVIRON…

authentication-authorizationeducationexploitation+4
128 months ago
EXOCET-AV-Evasion preview

EXOCET-AV-Evasion

GitHubtanc7/exocet-av-evasion

EXOCET - AV-evading, undetectable, payload delivery tool

command-and-controlcryptographyeducation+9
8414 years ago
obsidian-osint-templates preview

obsidian-osint-templates

GitHubwebbreacher/obsidian-osint-templates

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

curated-resourceseducationinformation-gathering+2
8143 months ago
esp32-wifi-penetration-tool preview

esp32-wifi-penetration-tool

GitHubrisinek/esp32-wifi-penetration-tool

Exploring possibilities of ESP32 platform to attack on nearby Wi-Fi networks.

educationexploitationhardware-hacking+6
3.1k3 years ago
Previous12…27Next