Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
113 results
CVE-2024-48887-Exploit preview

CVE-2024-48887-Exploit

GitHubgroshi215/cve-2024-48887-exploit

Unverified Password Change (CWE-620)

authenticationexploitationpenetration-testing+3
2
1 year ago
CVE-2021-24750 preview

CVE-2021-24750

GitHubfimtow/cve-2021-24750

Demonstration of the WP Visitor Statistics plugin exploit

exploitationpenetration-testingvulnerability-analysis+2
14 years ago
FOSKiller preview

FOSKiller

GitHub7megaumka7/foskiller

FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse

api-security-testingexploitationpassword-attacks+3
13 months ago
winboxPOC preview

winboxPOC

GitHubtr33-he11/winboxpoc

Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)

exploitationinformation-gatheringnetwork-security+3
17 years ago
postgres-bruteforcer preview

postgres-bruteforcer

GitHubrandomrobbiebf/postgres-bruteforcer

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

authenticationdatabase-securityexploitation+2
3 years ago
WinboxPoC preview
Archived

WinboxPoC

GitHubbasucert/winboxpoc

Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)

exploitationinformation-gatheringnetwork-security+3
5195 years ago
reaver-wps-fork-t6x preview

reaver-wps-fork-t6x

GitHubt6x/reaver-wps-fork-t6x

Brute-force attack tool against WPS registrar PINs to recover WPA/WPA2 passphrases, supporting online brute force and offline Pixie Dust attacks on…

exploitationpassword-attackswi-fi-auditing+1
2.0k11 months ago
Brutal preview

Brutal

GitHubscreetsec/brutal

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is…

exploitationhardware-hackingpassword-cracking+5
1.3k7 years ago
win-brute-logon preview

win-brute-logon

GitHubdarkcodersc/win-brute-logon

Crack any Microsoft Windows users password without any privilege (Guest account included)

exploitationpassword-attackspassword-cracking+2
1.2k2 years ago
KeePwn preview

KeePwn

GitHuborange-cyberdefense/keepwn

A python tool to automate KeePass discovery and secret extraction.

exploitationpassword-crackingpost-exploitation+1
5301 year ago
WPAxFuzz preview

WPAxFuzz

GitHubefchatz/wpaxfuzz

A full-featured open-source Wi-Fi fuzzer

exploitationfuzzingvulnerability-analysis+2
2143 months ago
ADCSync preview

ADCSync

GitHubjpg0mez/adcsync

Use ESC1 to perform a makeshift DCSync and dump hashes

authenticationexploitationpassword-cracking+1
2132 years ago
Venom-JWT preview

Venom-JWT

GitHubz-bool/venom-jwt

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

exploitationfuzzingpassword-cracking+3
2871 year ago
vss-fr2system preview

vss-fr2system

GitHubsailay1996/vss-fr2system

test

exploitationpassword-crackingpenetration-testing+4
1075 months ago
cve-2020-1472 preview

cve-2020-1472

GitHubmstxq17/cve-2020-1472

cve-2020-1472 复现利用及其exp

exploitationpassword-crackingpenetration-testing+3
1126 years ago
crack preview

crack

GitHubaveragesecurityguy/crack

XMLRPC server for password cracking

exploitationpassword-attackspassword-cracking+3
3311 years ago
killosx preview

killosx

GitHubd4rkcat/killosx

use the Apple CoreText exploit (CVE-2012-3716) and launch an AP to affect all devices within wifi range

exploitationred-teamingvulnerability-analysis+2
2211 years ago
hook preview

hook

GitHubjbaines-r7/hook

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

exploitationpassword-crackingpenetration-testing+3
104 years ago
Previous1234567Next