Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
Paste2Web preview

Paste2Web

GitHubd4vinci/paste2web

A python3 script that uses cl1p website to send and receive secret messages

data-exfiltrationeducationencryption-decryption-tools+2
319 years ago
CVE-2025-8570 preview

CVE-2025-8570

GitHubnxploited/cve-2025-8570

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

authentication-authorizationeducationexploitation+6
1 year ago
Metasploit-Module-TFM preview

Metasploit-Module-TFM

GitHubcgv-dev/metasploit-module-tfm

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

cloud-securitycontainer-securityeducation+7
2 years ago
roundcube-cve-2025-49113-lab preview

roundcube-cve-2025-49113-lab

GitHubankitpandey383/roundcube-cve-2025-49113-lab

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

code-analysisctfeducation+7
10 months ago
nhi-zero-trust-bypass preview

nhi-zero-trust-bypass

GitHubalexsvobo/nhi-zero-trust-bypass

Demonstrates a real-world zero-trust bypass by exploiting BIND CVE-2025-40775 to disrupt DNS, break secret rotation, and expose static credentials in…

cloud-securitydns-analysiseducation+5
51 year ago
CVE-2021-22911-RocketChat preview

CVE-2021-22911-RocketChat

GitHubfaridi-m/cve-2021-22911-rocketchat

Exploit for Rocket.Chat 3.12.1 RCE via pre-auth NoSQL injection, leaking admin TOTP secret and password reset token to achieve remote code execution…

educationexploitationpayload-development+3
26 months ago
CVE-2026-53519-PoC preview

CVE-2026-53519-PoC

GitHubtar-xz/cve-2026-53519-poc

PoC exploit for CVE-2026-53519.

educationexploitationpenetration-testing+3
33 months ago
CVE-2024-22369 preview

CVE-2024-22369

GitHuboscerd/cve-2024-22369

CVE-2024-22369 Reproducer

database-securityeducationexploitation+3
42 years ago
Fern Pattern Scanner preview

Fern Pattern Scanner

GitLabgitlab-da/tutorials/security-and-governance/custom-scanner-integration/fern-pattern-scanner

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

code-analysisdevsecopseducation+3
52 years ago
rp2350_hacking_challenge preview

rp2350_hacking_challenge

GitHubraspberrypi/rp2350_hacking_challenge

Raspberry Pi RP2350 hacking challenge: extract a 128-bit OTP secret protected by secure boot and OTP lock, with setup scripts and firmware for Pico 2…

cryptographyctfeducation+5
2051 year ago
CVE-2017-1000486 preview

CVE-2017-1000486

GitHubpastea/cve-2017-1000486

Multi-step proof-of-concept exploit for CVE-2017-1000486 (PrimeFaces EL injection) with padding oracle secret retrieval and blacklist-bypassing…

educationexploitationpayload-development+3
44 years ago
details-for-CVE-2022-46505 preview

details-for-CVE-2022-46505

GitHubsmalltown123/details-for-cve-2022-46505

MatrixSSL session resume bug

binary-analysiscryptographyeducation+2
3 years ago
Stegano preview

Stegano

GitHubcedricbonhomme/stegano

A pure Python steganography module.

cryptographyeducationencryption-decryption-tools+2
5942 months ago
LLMReaper preview

LLMReaper

GitHubthewhiteh4t/llmreaper

Passive LLM Conversation Capture & Sensitive Data Exposure Research

educationinformation-gatheringosint+3
174 months ago
ST3GG preview

ST3GG

GitHubelder-plinius/st3gg

All-in-one steganography suite

ai-securityctfdata-exfiltration+8
1.8k3 months ago
ed25519-unsafe-libs preview

ed25519-unsafe-libs

GitHubmystenlabs/ed25519-unsafe-libs

List of unsafe ed25519 signature libs

cryptographycurated-resourceseducation+3
2502 years ago
recipe-blog-encoding preview

recipe-blog-encoding

GitHubtbrockman/recipe-blog-encoding

Hide valuable information where it's least expected

cryptographyeducationencryption-decryption-tools+3
56 months ago
mojo-v preview

mojo-v

GitHubtoddmaustin/mojo-v

RISC-V ISA extension for hardware-enforced secret computation using ML-KEM-512 key encapsulation and SIMON-128 encryption, enabling data-oblivious…

cryptographyeducationembedded-systems-security+4
1511 month ago
Previous12Next