Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
27 results
CVE-2025-27480-The-Silent-Gateway-Risk preview

CVE-2025-27480-The-Silent-Gateway-Risk

GitHubmrk336/cve-2025-27480-the-silent-gateway-risk

Letting attackers run malicious code without needing a cracked password, user interaction, or even a foothold in your network. That’s CVE-2025-27480

binary-exploitationcloud-securityeducation+3
1 year ago
WiFi-password-stealer preview

WiFi-password-stealer

GitHubaleksamcode/wifi-password-stealer

Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password).

data-exfiltrationeducationhardware-hacking+6
6061 year ago
DefaultCreds-cheat-sheet preview

DefaultCreds-cheat-sheet

GitHubihebski/defaultcreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

curated-resourcesdefensive-toolseducation+6
6.8k13 days ago
JustTryHarder preview

JustTryHarder

GitHubsinfulz/justtryharder

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

educationexploitationpassword-cracking+7
8383 months ago
CVE-2023-33730 preview

CVE-2023-33730

GitHubsahiloj/cve-2023-33730

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

authentication-authorizationeducationexploitation+8
17 months ago
KeePass-CVE-2023-32784-Exploitation-and-Defense preview

KeePass-CVE-2023-32784-Exploitation-and-Defense

GitHubareebashoaib42/keepass-cve-2023-32784-exploitation-and-defense

Exploitation and defense-in-depth mitigation strategies for the KeePass memory leakage vulnerability (CVE-2023-32784).

configuration-auditingdefensive-toolseducation+5
4 months ago
cve-2026-8697 preview

cve-2026-8697

GitHubitzmetanjim/cve-2026-8697

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

educationexploitationhardware-iot-security+7
14 months ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
13 months ago
SecRep preview

SecRep

GitHubr3dxpl0it/secrep

SecRep Is a Repository That Contain Useful Intrusion, Penetration and Hacking Archive Including Tools List, Cheetsheet and Payloads

curated-resourceseducationexploitation+5
197 years ago
openwifipass preview

openwifipass

GitHubseemoo-lab/openwifipass

An open source implementation of Apple's Wi-Fi Password Sharing protocol in Python.

educationpapers-researchreverse-engineering+2
8421 month ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4834 years ago
D4TA-HUNTER preview

D4TA-HUNTER

GitHubmicro-joan/d4ta-hunter

Automated OSINT framework for ethical hacking audits. Collects employee emails, password hashes, subdomains, and IPs via BreachDirectory and…

educationemail-harvestinginformation-gathering+3
1783 years ago
CVE-2024-21413-POC preview

CVE-2024-21413-POC

GitHubr00tb1t/cve-2024-21413-poc

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC

educationemail-securityexploitation+3
172 years ago
CiscoSpill preview

CiscoSpill

GitHubshaheemirza/ciscospill

Just a PoC tool to extract password using CVE-2019-1653.

educationexploitationinformation-gathering+3
47 years ago
CVE-2024-25832-PoC preview

CVE-2024-25832-PoC

GitHub0xnslabs/cve-2024-25832-poc

PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

educationexploitationinformation-gathering+3
42 years ago
Hack-The-Box-Enigma-Findings-Report preview

Hack-The-Box-Enigma-Findings-Report

GitHubmmoobbeeiidat-design/hack-the-box-enigma-findings-report

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager…

ctfeducationexploitation+8
3 months ago
Zero-Day-Legacy preview

Zero-Day-Legacy

GitHubayham-megdadi/zero-day-legacy

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

ctfeducationlabs-practice+6
23 months ago
Exploiting-a-vulnerability-using-reverse-shell preview

Exploiting-a-vulnerability-using-reverse-shell

GitHubdampedcoast/exploiting-a-vulnerability-using-reverse-shell

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…

ctfeducationexploitation+5
4 months ago
Previous12Next