Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
Aether preview

Aether

GitHubfknmega/aether

AI-driven OSINT and security research agent that builds a live knowledge graph from public data, with bundled recon tools and offensive-security…

ai-securityctfcurated-resources+5
174
6 days ago
insightsnexus preview

insightsnexus

GitHubcyberintel-labs/insightsnexus

OSINT Graph Investigation Application

curated-resourcesdns-subdomain-enumerationeducation+7
349 months ago
osint-menace preview

osint-menace

GitHubawesom3alex/osint-menace

Passive OSINT triage console for email, username, domain, IP, and crypto wallet reconnaissance. Features case management, curated resource links, and…

cryptographycurated-resourcesdns-analysis+5
92 months ago
CVE-2007-2447 preview

CVE-2007-2447

GitHubfoudadev/cve-2007-2447

Educational exploit implementation for CVE-2007-2447 Samba 3.0.20-3.0.25rc username map script command execution vulnerability with Python SMB client…

binary-exploitationcommand-and-controleducation+6
2 years ago
CVE-2011-2523-exploit preview

CVE-2011-2523-exploit

GitHubdahalsamir/cve-2011-2523-exploit

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

binary-exploitationcommand-and-controleducation+5
5 months ago
Hundred OSINT preview

Hundred OSINT

GitLabt-beckett/h-osint

Local-first, keyboard-driven OSINT workbench for the terminal with 28 modules covering username, domain, IP, email, breach, and geolocation lookups…

dns-analysiseducationemail-harvesting+7
6 days ago
Linux-Kodachi preview

Linux-Kodachi

GitHubwmal/linux-kodachi

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

cryptographydigital-forensicseducation+9
4999 days ago
open-sammy preview

open-sammy

GitHubowasp/open-sammy

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

cloud-securityconfiguration-auditingcontainer-security+3
289 days ago
vicidial-cve-2024-8503-blind-sqli-poc preview

vicidial-cve-2024-8503-blind-sqli-poc

GitHubmachine-farmer/vicidial-cve-2024-8503-blind-sqli-poc

Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.

database-securityeducationexploitation+3
4 months ago
PoC-CVE-2024-44349 preview

PoC-CVE-2024-44349

GitHubandreaf17/poc-cve-2024-44349

Proof-of-concept exploit for CVE-2024-44349, an SQL injection in Anteeo WMS v4.7.x, enabling database dumping and arbitrary SQL query execution.

ctfdatabase-securityeducation+4
110 months ago
CVE-2026-36227 preview

CVE-2026-36227

GitHubnullbyte8080/cve-2026-36227

Benign proof-of-concept for CVE-2026-36227, a path traversal vulnerability in Easy Chat Server 3.1 user registration. Demonstrates unauthorized file…

educationexploitationlabs-practice+3
3 months ago
CVE-2025-46047 preview

CVE-2025-46047

GitHubj0ey17/cve-2025-46047

PoC for Silverpeas <= 6.4.2 Username Enumeration

educationexploitationinformation-gathering+3
21 year ago
blackbird preview

blackbird

GitLabgcabc123/blackbird

An OSINT tool to search for accounts by username in social networks.

curated-resourceseducationinformation-gathering+3
14 years ago
Samba-CVE-2007-2447-Exploit preview

Samba-CVE-2007-2447-Exploit

GitHubshivamdey/samba-cve-2007-2447-exploit

Python exploit for CVE-2007-2447 in Samba, enabling remote command execution via crafted username. Delivers reverse shell to attacker. For authorized…

educationexploitationpayload-generation+3
2 years ago
CVE-2025-11833-PoC preview

CVE-2025-11833-PoC

GitHubbocgoinfosec/cve-2025-11833-poc

Proof-of-concept checker for CVE-2025-11833, allowing security researchers to test vulnerable web applications with configurable credentials and loot…

educationexploitationpenetration-testing+2
10 months ago
Exploit-for-CVE-2025-2304 preview

Exploit-for-CVE-2025-2304

GitHubsparrowhawk1113/exploit-for-cve-2025-2304

Exploit for CVE-2025-2304

educationexploitationprivilege-escalation+2
7 months ago
Exploit-for-CVE-2024-46987 preview

Exploit-for-CVE-2024-46987

GitHubsparrowhawk1113/exploit-for-cve-2024-46987

Exploit for CVE-2024-46987

educationexploitationpenetration-testing+2
7 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubtiborscholtz/cve-2026-24061

Educational Docker lab demonstrating Telnet NEW-ENVIRON username injection (CVE-2026-24061) with a Python client and vulnerable server for isolated…

educationexploitationlabs-practice+2
7 months ago
Previous12Next