Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
haptyc preview

haptyc

GitHubdefparam/haptyc

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

fuzzingpayload-generationpenetration-testing+1
93
4 years ago
ZIPFileRaider preview

ZIPFileRaider

GitHubdestine21/zipfileraider

ZIP File Raider - Burp Extension for ZIP File Payload Testing

fuzzingpayload-generationpenetration-testing+2
715 years ago
MalQR.github.io preview

MalQR.github.io

GitHubmalqr/malqr.github.io

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

fuzzingpayload-generationpenetration-testing+1
1274 years ago
recollapse preview

recollapse

GitHub0xacb/recollapse

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

fuzzingpayload-generationwaf-bypass+1
1.4k1 year ago
xxexploiter preview

xxexploiter

GitHubluisfontes19/xxexploiter

Tool to help exploit XXE vulnerabilities

exploitationfuzzingpayload-generation+2
6164 years ago
XanXSS preview

XanXSS

GitHubekultek/xanxss

A simple XSS finding tool

fuzzingpayload-generationpenetration-testing+2
1107 years ago
XSSFuzzer preview

XSSFuzzer

GitHubnytrorst/xssfuzzer

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

fuzzingpayload-generationwaf-bypass+1
1387 years ago
py3webfuzz preview

py3webfuzz

GitHubjangelesg/py3webfuzz

A Python3 module to assist in fuzzing web applications

fuzzingpayload-generationpenetration-testing+2
572 years ago
CVE-2013-2729 preview

CVE-2013-2729

GitHubfeliam/cve-2013-2729

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

binary-exploitationexploitationfuzzing+3
246 years ago
CVE-2026-14266 preview

CVE-2026-14266

GitHub4minx/cve-2026-14266

CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip

binary-exploitationexploitationfuzzing+2
310 days ago
Log4Shell preview

Log4Shell

GitHubr00thunter/log4shell

Generic Scanner for Apache log4j RCE CVE-2021-44228

exploitationfuzzingpayload-generation+3
74 years ago
CVE-2026-41096 preview

CVE-2026-41096

GitHubm0n1x90/cve-2026-41096

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

binary-exploitationdns-analysisexploitation+3
33 months ago
cve-2026-69243-poc-aiohttp-smuggling preview

cve-2026-69243-poc-aiohttp-smuggling

GitHubjvbotelho/cve-2026-69243-poc-aiohttp-smuggling

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…

exploitationfuzzingpayload-generation+3
121 days ago
react2shell preview

react2shell

GitHubgrp-ops/react2shell

Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).

exploitationfuzzingpayload-generation+3
48 months ago
CVE-2025-20260-POC preview

CVE-2025-20260-POC

GitHubalex-acero-security/cve-2025-20260-poc

Proof-of-concept exploit for CVE-2025-20260, a buffer overflow in ClamAV's PDF scanning. Includes a Python script to generate a malicious PDF and…

binary-exploitationexploitationfuzzing+3
3 months ago
Payload-and-Polyglot-Lists preview

Payload-and-Polyglot-Lists

GitHubgromhacks/payload-and-polyglot-lists

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

educationfuzzingosint+4
364 months ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubpopclom/cve-2025-5548

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

binary-exploitationdebuggerseducation+8
5 months ago
XSStrike preview

XSStrike

GitHubs0md3v/xsstrike

Most advanced XSS scanner.

crawlerdynamic-code-analysisfuzzing+8
15.1k1 year ago