Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
68 results
CVE-2025-24799 preview

CVE-2025-24799

GitHubrosemary1337/cve-2025-24799

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

exploitationpenetration-testingvulnerability-analysis+2
11 months ago
rtf_exploit_extractor preview

rtf_exploit_extractor

GitHubcyberclues/rtf_exploit_extractor

Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents

binary-analysisexploitationforensics+2
239 years ago
CVE-2025-57819_FreePBX preview

CVE-2025-57819_FreePBX

GitHuborange0mint/cve-2025-57819_freepbx

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

educationexploitationinformation-gathering+4
211 months ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubaleewyy/cve-2025-49132

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

database-securityexploitationinformation-gathering+3
2 months ago
YellowKey-Bitlocker-CVE-2026-45585 preview

YellowKey-Bitlocker-CVE-2026-45585

GitHubboobalover7/yellowkey-bitlocker-cve-2026-45585

Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.

data-recoveryencryption-decryption-toolsexploitation+3
1 day ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubcarlosevieira/cve-2022-40684

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

authenticationexploitationpenetration-testing+2
873 years ago
FollinaExtractor preview

FollinaExtractor

GitHubmalwaretech/follinaextractor

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

exploitationinformation-gatheringmalware-analysis+2
314 years ago
sentryexploit preview

sentryexploit

GitHubleakix/sentryexploit

CVE-2023-38035 Recon oriented exploit, extract company name contact information

exploitationinformation-gatheringreconnaissance+2
72 years ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubccordeiro/cve-2022-40684

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

authenticationexploitationinformation-gathering+3
9 months ago
Project-Field-Analysis-and-Memory-Leak-Demonstration preview

Project-Field-Analysis-and-Memory-Leak-Demonstration

GitHubartemcyberlab/project-field-analysis-and-memory-leak-demonstration

The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to…

educationexploitationinformation-gathering+3
1 year ago
CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053- preview

CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-

GitHubhf3cyber/cms-made-simple-2.2.9-unauthenticated-sql-injection-exploit-cve-2019-9053-

This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL…

exploitationinformation-gatheringpassword-cracking+3
1 year ago
CVE-2021-29447-POC preview

CVE-2021-29447-POC

GitHubb-abderrahmane/cve-2021-29447-poc
exploitationpayload-generationpenetration-testing+2
12 years ago
CVE-2024-33676 preview

CVE-2024-33676

GitHubdersecure/cve-2024-33676
authentication-authorizationeducationembedded-systems-security+9
1 year ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
2 months ago
vcenter_saml_login preview

vcenter_saml_login

GitHubhorizon3ai/vcenter_saml_login

A tool to extract the IdP cert from vCenter backups and log in as Administrator

authentication-authorizationcloud-infrastructure-securityexploitation+4
5292 years ago
VMkatz preview

VMkatz

GitHubnikaiw/vmkatz

Extract Windows credentials directly from VM memory snapshots and virtual disks

digital-forensicsexploitationforensics+7
1.5k4 months ago
Tarmageddon-CVE-2025-62518- preview

Tarmageddon-CVE-2025-62518-

GitHubairineiandrei/tarmageddon-cve-2025-62518-
educationexploitationmalware-analysis+3
7 months ago
livewire-honeypot preview

livewire-honeypot

GitHubhelgesverre/livewire-honeypot

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

command-and-controldynamic-analysis-sandboxingexploitation+6
53 months ago
Previous1234Next