Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
Krawl preview

Krawl

GitHubblessedrebus/krawl

Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging…

ai-securityanti-botcloud-security+6
733
3 days ago
SnitchDNS preview

SnitchDNS

GitHubctxis/snitchdns

Database Driven DNS Server with a Web UI

command-and-controldata-exfiltrationdns-analysis+7
2442 years ago
NginxHunter preview

NginxHunter

GitHubemrekybs/nginxhunter

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…

defensive-toolsincident-responselog-analysis+2
52 years ago
apache_audit_cve-2026-23918 preview

apache_audit_cve-2026-23918

GitHubsibersan/apache_audit_cve-2026-23918

Python toolkit to audit Apache HTTP Server against CVE-2026-23918 (HTTP/2 double-free RCE) and 4 related CVEs. Passive scanner with ALPN verification…

configuration-auditingdefensive-toolsincident-response+3
4 months ago
cve-2025-55182-scanner preview

cve-2025-55182-scanner

GitHubtechgaun/cve-2025-55182-scanner

Python-based scanner for CVE-2025-55182 indicators of compromise. Checks filesystem paths, processes, systemd services, cron persistence, and…

forensicsincident-responsemalware-analysis+3
39 months ago
How-To-Secure-A-Linux-Server preview

How-To-Secure-A-Linux-Server

GitHubimthenachoman/how-to-secure-a-linux-server

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

authenticationconfiguration-auditingcurated-resources+7
31.4k7 days ago
log4j_checker_beta preview

log4j_checker_beta

GitHubrubo77/log4j_checker_beta

a fast check, if your server could be vulnerable to CVE-2021-44228

code-analysisdynamic-analysis-sandboxingincident-response+3
2474 years ago
vcsa-hardening-tool preview

vcsa-hardening-tool

GitHubmandiant/vcsa-hardening-tool

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

authenticationcloud-infrastructure-securityconfiguration-auditing+9
145 months ago
CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector preview

CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector

GitHubadityabhatt3010/cve-2025-59287-when-your-patch-server-becomes-the-attack-vector

CVE-2025-59287 — Critical unauthenticated RCE in Windows Server Update Services (WSUS) via unsafe deserialization of an AuthorizationCookie, enabling…

curated-resourceseducationexploitation+5
1010 months ago
React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web preview

React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web

GitHubadityabhatt3010/react2shell-cve-2025-55182-the-deserialization-bug-that-broke-the-web

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

ctfeducationexploitation+8
89 months ago
CVE-2022-47966_checker preview

CVE-2022-47966_checker

GitHubace-responder/cve-2022-47966_checker

Run on your ManageEngine server

forensicsincident-responseioc-management+3
23 years ago
CVE-2025-66478 preview

CVE-2025-66478

GitHubexptechtw/cve-2025-66478

Real-world attack log analysis of CVE-2025-66478 (Next.js Server Actions RCE) with malware samples, attacker IP tracking, and container security…

container-securityeducationexploitation+6
29 months ago
flight-risk preview

flight-risk

GitHubjoaoreis13/flight-risk

Security toolkit for CVE-2025-55182 (React2Shell) — scan, detect, correlate, and test React Server Components RCE vulnerability

cloud-securitycontainer-securitydevsecops+6
4 months ago
CVE-2025-55182-Researching-process preview

CVE-2025-55182-Researching-process

GitHubcybersecurity-enthusiasts-ce/cve-2025-55182-researching-process

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

curated-resourceseducationexploitation+6
4 months ago
CVE-2025-55182-Researching-process preview

CVE-2025-55182-Researching-process

GitHuborgito1015/cve-2025-55182-researching-process

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes vulnerability analysis, detection rules…

educationexploitationincident-response+6
14 months ago
CVE-2025-55182-Researching-process preview

CVE-2025-55182-Researching-process

GitHubtechwithorgito/cve-2025-55182-researching-process

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

curated-resourceseducationexploitation+6
3 months ago
cloudpanel-2.4.2-CVE-2024-44765-recovery preview

cloudpanel-2.4.2-CVE-2024-44765-recovery

GitHubjosephgodwinkimani/cloudpanel-2.4.2-cve-2024-44765-recovery

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

cloud-securityincident-responsemisconfiguration+3
11 year ago
React2Shell_Hunter preview

React2Shell_Hunter

GitHubrocklambros/react2shell_hunter

AWS Organization-wide detection toolkit for CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE vulnerabilities)

cloud-securitydefensive-toolsexploitation+6
19 months ago
Previous12Next