Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
466 results
nemesis preview

nemesis

GitHublibnet/nemesis

A command-line network packet crafting and injection utility

exploitationfuzzingnetwork-security+2
5283 years ago
GATOR preview

GATOR

GitHubanrbn/gator

Modular GCP attack toolkit for offensive research, enabling reconnaissance, authentication manipulation, and exploitation of cloud functions,…

cloud-securityexploitationpenetration-testing+2
903 years ago
caplets preview

caplets

GitHubbettercap/caplets

caplets and proxy modules.

exploitationinformation-gatheringnetwork-security+4
5282 months ago
mousejack preview

mousejack

GitHubbastilleresearch/mousejack

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

exploitationfirmware-analysishardware-iot-security+3
1.4k8 years ago
CVE-2021-21985_PoC preview

CVE-2021-21985_PoC

GitHubalt3kx/cve-2021-21985_poc

PoC exploit and NSE scanner for CVE-2021-21985, a vCenter Server RCE vulnerability in the vSAN Health Check plugin, with manual exploitation steps…

exploitationpenetration-testingreconnaissance+3
2134 years ago
rupture preview

rupture

GitHubdecrypto-org/rupture

A framework for BREACH and other compression-based crypto attacks

cryptographyexploitationpacket-sniffing-analysis+3
2387 years ago
CVE-2025-5419 preview

CVE-2025-5419

GitHubmistymntncop/cve-2025-5419

Proof-of-concept exploit for CVE-2025-5419, demonstrating a critical vulnerability with a JavaScript-based implementation for security testing and…

exploitationpenetration-testingreconnaissance+2
941 year ago
CVE-2022-22963 preview

CVE-2022-22963

GitHubdinosn/cve-2022-22963

Proof-of-concept exploit for CVE-2022-22963 (Spring Cloud Function SpEL RCE). Scans URLs, executes commands, and identifies vulnerable targets.

exploitationpenetration-testingreconnaissance+2
1164 years ago
CVE-2023-36845 preview

CVE-2023-36845

GitHubkljunowsky/cve-2023-36845

Proof-of-concept exploit for CVE-2023-36845 enabling unauthenticated remote code execution on Juniper SRX firewalls and EX switches via PHP…

exploitationpenetration-testingreconnaissance+3
552 years ago
Microsoft_Exchange_Server_SSRF_CVE-2021-26855 preview

Microsoft_Exchange_Server_SSRF_CVE-2021-26855

GitHubconjojo/microsoft_exchange_server_ssrf_cve-2021-26855

Python exploit script for CVE-2021-26855 (Microsoft Exchange Server SSRF) with integrated ZoomEye dork for mass scanning and detection of vulnerable…

exploitationpenetration-testingreconnaissance+2
355 years ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubhazcod/cve-2025-53770

Go-based scanner that detects SharePoint CVE-2025-53770 RCE vulnerability by injecting a harmless marker into the ToolBox widget and verifying its…

exploitationpayload-developmentpenetration-testing+3
467 months ago
VMware_vCenter_UNAuthorized_RCE_CVE-2021-21972 preview

VMware_vCenter_UNAuthorized_RCE_CVE-2021-21972

GitHubconjojo/vmware_vcenter_unauthorized_rce_cve-2021-21972

Python-based exploit and detection script for CVE-2021-21972 (VMware vCenter unauthorized RCE), using Zoomeye dork for host discovery and pocsuite3…

exploitationpenetration-testingreconnaissance+2
275 years ago
FortiSandbox-RCE-Exploit-CVE-2026-39808 preview

FortiSandbox-RCE-Exploit-CVE-2026-39808

GitHubynsmroztas/fortisandbox-rce-exploit-cve-2026-39808

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

command-and-controlexploitationpenetration-testing+3
265 months ago
detect_bluekeep.py preview

detect_bluekeep.py

GitHubhynekpetrak/detect_bluekeep.py

Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support

exploitationnetwork-securitypenetration-testing+3
277 years ago
cve-2020-0796 preview

cve-2020-0796

GitHubbutrintkomoni/cve-2020-0796

Identifying and Mitigating the CVE-2020–0796 flaw in the fly

exploitationnetwork-securitypenetration-testing+2
176 years ago
Struts-Apache-ExploitPack preview

Struts-Apache-ExploitPack

GitHubret2jazzy/struts-apache-exploitpack

These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)

command-and-controlexploitationpenetration-testing+3
169 years ago
CVE-2022-22954-PoC preview

CVE-2022-22954-PoC

GitHubtunelko/cve-2022-22954-poc

VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.

exploitationpenetration-testingreconnaissance+2
162 years ago
CVE-2023-27350-POC preview

CVE-2023-27350-POC

GitHubimancybersecurity/cve-2023-27350-poc

Proof-of-concept exploit for CVE-2023-27350 targeting authentication bypass in PaperCut MF/NG print management software. Includes Shodan dorks for…

authenticationexploitationreconnaissance+2
121 year ago
Previous12…26Next