Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
169 results
CVE-2024-40725 preview

CVE-2024-40725

GitHubsoltanali0/cve-2024-40725

exploit CVE-2024-40725 (Apache httpd) with

exploitationfuzzingpenetration-testing+3
121 year ago
danish_phone_wordlist_generator preview

danish_phone_wordlist_generator

GitHubn0kovo/danish_phone_wordlist_generator

Generate wordlists of Danish phone numbers by area and/or usage (Mobile, landline etc.) Useful for password cracking or fuzzing Danish targets.

fuzzingosintpassword-cracking
84 years ago
netgear_r6700v3_circled preview

netgear_r6700v3_circled

GitHubcyber-defence-campus/netgear_r6700v3_circled

Demonstrate some functionalities of Morion by generating an exploit for CVE-2022-27646 (stack buffer overflow on Netgear R6700v3 routers).

binary-exploitationeducationembedded-systems-security+4
81 year ago
CVE-2018-7449 preview

CVE-2018-7449

GitHubantogit-sys/cve-2018-7449

simple Python exploit using CVE-2018-7449 on embOS/IP FTP Server v3.22

exploitationfuzzingpenetration-testing+1
23 years ago
react2shell preview

react2shell

GitHubgrp-ops/react2shell

Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).

exploitationfuzzingpayload-generation+3
410 months ago
sparkplugFuzzer preview

sparkplugFuzzer

GitHubbishopfox/sparkplugfuzzer

Fuzzer for the Sparkplug B IIoT protocol

authenticationdynamic-analysis-sandboxingfuzzing+5
23 months ago
NetAudit-IoT preview

NetAudit-IoT

GitHubhmrumman777-beep/netaudit-iot

Research-driven UPnP vulnerability scanner focusing on libupnp 1.6.19 and CVE-2012-5958.

exploitationfuzzingiot-security+3
6 months ago
CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC preview

CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC

GitHubabrewer251/cve-2024-38475_sonicboom_apache_url_traversal_poc

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

exploitationfuzzingpenetration-testing+3
1 year ago
dtls-fuzzer preview

dtls-fuzzer

GitLabpfg666/dtls-fuzzer

dtls-fuzzer is a protocol-state-fuzzer for DTLS server implementations.

fuzzingnetwork-security
5 years ago
endsfuzzer preview

endsfuzzer

GitHubameenalkerdy/endsfuzzer

Fuzz a list of domains for specific endpoints

fuzzinginformation-gatheringweb-security
3 years ago
Injectus preview
Archived

Injectus

GitHubdubs3c/injectus

CRLF and open redirect fuzzer

fuzzinginformation-gatheringpenetration-testing+3
1125 years ago
path-auditor preview
Archived

path-auditor

GitHubgoogle/path-auditor

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

binary-analysisdynamic-code-analysisexploitation+3
2505 years ago
boringssl preview

boringssl

GitHubgoogle/boringssl

Fork of OpenSSL implementing TLS, cryptographic primitives, and X.509 certificate handling for use in Chrome and Android, with no API/ABI…

cryptographyencryption-decryption-toolsfuzzing+1
2.3k28 days ago
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k7 months ago
BurpCrypto preview

BurpCrypto

GitHubwhwlsfb/burpcrypto

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

encryption-decryption-toolsfuzzingpayload-generation+1
1.7k3 years ago
regexploit preview

regexploit

GitHubdoyensec/regexploit

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

fuzzingstatic-code-analysisvulnerability-analysis
8505 years ago
libssh-mirror preview

libssh-mirror

GitLablibssh/libssh-mirror

C library implementing the SSH protocol for secure remote access, authentication, and encrypted communication. Includes fuzzing support via OSS-Fuzz…

authenticationcryptographyencryption-decryption-tools+2
545 days ago
sign-saboteur preview

sign-saboteur

GitHubd0ge/sign-saboteur

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

authentication-authorizationcryptographyfuzzing+7
1731 year ago
Previous1…8910Next