Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
959 results
CVE-2024-38828 preview

CVE-2024-38828

GitHubfuncid/cve-2024-38828

PoC and fix for CVE-2024-38828: Spring Framework DoS via Content-Length manipulation in ByteArrayHttpMessageConverter. Includes load testing,…

code-analysiseducationexploitation+2
1 year ago
VUL4J-23 preview

VUL4J-23

GitHubepicosy/vul4j-23

Curated Java web framework vulnerability (CVE-2016-5394) for Apache Sling, designed for security testing, exploitation practice, and vulnerability…

code-analysiseducationexploitation+3
2 years ago
frameworks_base_AOSP10_r33_CVE-2023-21097 preview

frameworks_base_AOSP10_r33_CVE-2023-21097

GitHubuthrasri/frameworks_base_aosp10_r33_cve-2023-21097

Android AOSP 10 framework base repository containing the fix for CVE-2023-21097, a vulnerability in the Android framework that could lead to local…

android-securitybinary-exploitationexploitation+2
2 years ago
frameworks_base_AOSP10_r33_CVE-2021-20138 preview

frameworks_base_AOSP10_r33_CVE-2021-20138

GitHubshaikusaf/frameworks_base_aosp10_r33_cve-2021-20138

Analyzes and patches Android framework vulnerability CVE-2021-20138 in AOSP 10, providing security fixes for mobile platforms.

android-securitybinary-exploitationexploitation+2
4 years ago
SpringPathTraversal preview

SpringPathTraversal

GitHubgforresu/springpathtraversal

String MVC Framework Path-Traversal proof of concept. CVE-2014-3625

exploitationmisconfigurationpenetration-testing+2
9 years ago
Silverseal preview

Silverseal

GitHubidov31/silverseal

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

binary-exploitationexploitationmalware-analysis+4
1187 days ago
certfuzz preview
Archived

certfuzz

GitHubcertcc/certfuzz

This project contains the source code for the CERT Basic Fuzzing Framework (BFF) and the CERT Failure Observation Engine (FOE).

binary-analysisdynamic-analysis-sandboxingexploitation+3
2741 year ago
btlejuice preview
Archived

btlejuice

GitHubdigitalsecurity/btlejuice

BtleJuice Bluetooth Smart (LE) Man-in-the-Middle framework

bluetooth-securityexploitationpacket-sniffing-analysis+3
8507 years ago
Ivy preview
Archived

Ivy

GitHuboptiv/ivy

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

exploitationpayload-developmentpayload-generation+4
7433 years ago
0xsp-Mongoose preview
Archived

0xsp-Mongoose

GitHubzux0x3a/0xsp-mongoose

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

command-and-controldns-analysisexploitation+8
5344 years ago
Dr0p1t-Framework preview
Archived

Dr0p1t-Framework

GitHubd4vinci/dr0p1t-framework

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

anti-botcommand-and-controlexploitation+9
1.5k7 years ago
pentestly preview
Archived

pentestly

GitHubpraetorian-inc/pentestly

Python and Powershell internal penetration testing framework

command-and-controlexploitationinformation-gathering+8
72010 years ago
maalik preview
Archived

maalik

GitHubquantumcore/maalik

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

command-and-controlexploitationlateral-movement+6
935 years ago
CVE-2022-36537 preview

CVE-2022-36537

GitHubmalwareman007/cve-2022-36537

POC of CVE-2022-36537

authentication-authorizationexploitationinformation-gathering+3
361 year ago
CVE-2022-26265 preview

CVE-2022-26265

GitHubsh4den/cve-2022-26265

The first proof of concept of the Contao CMS RCE

command-and-controlexploitationpayload-generation+3
102 months ago
CVE-2022-47966 preview

CVE-2022-47966

GitHubsh4den/cve-2022-47966

The manage engine mass loader for CVE-2022-47966

command-and-controlexploitationpenetration-testing+3
72 months ago
CVE-2026-32941 preview

CVE-2026-32941

GitHubskoveit/cve-2026-32941

CVE-2026-32941 PoC - Sliver Remote OOM

command-and-controlexploitationred-teaming+1
61 month ago
CVE-2020-35729 preview

CVE-2020-35729

GitHubal1ex/cve-2020-35729

CVE-2020-35729

command-and-controlexploitationpayload-development+3
55 years ago
Previous1…474849…54Next