Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
687 results
VTScanner preview

VTScanner

GitHubsamhaxr/vtscanner

A comprehensive Python-based security tool for file scanning, malware detection, and analysis in an ever-evolving cyber landscape.

hash-analysisinformation-gatheringmalware-analysis+1
112
2 years ago
CVE-2024-4040-SSTI-LFI-PoC preview

CVE-2024-4040-SSTI-LFI-PoC

GitHubstuub/cve-2024-4040-ssti-lfi-poc

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

authenticationexploitationinformation-gathering+3
662 years ago
CVE-2019-6447 preview

CVE-2019-6447

GitHubosuni-99/cve-2019-6447

The above investigation of the ES file browser security weakness allows us to see the issue in its entirety

android-securityexploitationinformation-gathering+2
4 years ago
Burp_Collector preview

Burp_Collector

GitHubsajibuu/burp_collector

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

api-security-testinginformation-gatheringpenetration-testing+4
102 years ago
GTFOBLookup preview

GTFOBLookup

GitHubnccgroup/gtfoblookup

Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io), LOLBAS (https://github.com/LOLBAS-Project/LOLBAS),…

information-gatheringlateral-movementpenetration-testing+3
2903 years ago
westone-CVE-2021-21980-scanner preview

westone-CVE-2021-21980-scanner

GitHubosyanina/westone-cve-2021-21980-scanner

A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.

exploitationinformation-gatheringpenetration-testing+2
64 years ago
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

data-exfiltrationexploitationinformation-gathering+3
18 days ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubxmohamed0/cve-2021-41773

Shell-based exploit for CVE-2021-41773 targeting Apache HTTP Server path traversal vulnerability, enabling unauthenticated remote file disclosure and…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubkaanatmacaa/cve-2024-23897

Nuclei template to detect CVE-2024-23897 Jenkins local file inclusion vulnerability, enabling rapid identification of exploitable instances for…

exploitationinformation-gatheringpenetration-testing+3
222 years ago
kamene preview

kamene

GitHubphaethon/kamene

Network packet and pcap file crafting/sniffing/manipulation/visualization security tool. Originally forked from scapy in 2015 and providing python3…

information-gatheringnetwork-mappingnetwork-security+3
8725 years ago
CVE-2020-5377 preview

CVE-2020-5377

GitHubh3x0v3rl0rd/cve-2020-5377

Python exploit script for CVE-2020-5377 targeting Dell OpenManage Server Administrator file read vulnerability. Enables remote file disclosure via…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4793 years ago
s3reverse preview

s3reverse

GitHubhahwul/s3reverse

The format of various s3 buckets is convert in one format. for bugbounty and security testing.

cloud-securityinformation-gatheringmisconfiguration+1
903 years ago
pyWhat preview

pyWhat

GitHubbee-san/pywhat

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

data-exfiltrationeducationforensics+7
7.3k3 years ago
Mikrotik-router-hack preview

Mikrotik-router-hack

GitHubhacker30468/mikrotik-router-hack

Proof-of-concept exploit for CVE-2018-14847 (MikroTik WinBox vulnerability) enabling arbitrary file read and plaintext password extraction via TCP/IP…

exploitationinformation-gatheringnetwork-security+3
555 years ago
goshs preview

goshs

GitHubgoshs-labs/goshs

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

command-and-controlctfdns-analysis+5
9626 days ago
smbmap preview

smbmap

GitHubshawndevans/smbmap

SMB share enumeration tool for listing drives, permissions, and contents across domains. Supports file upload/download/delete, remote command…

information-gatheringnetwork-securitypenetration-testing+2
2.1k7 months ago
WordPress-File-Upload-4.24.11---Unauthenticated-Path-Traversal preview

WordPress-File-Upload-4.24.11---Unauthenticated-Path-Traversal

GitHubamirqusairy99/wordpress-file-upload-4.24.11---unauthenticated-path-traversal

Python-based tool to detect and exploit arbitrary file read vulnerability in WordPress WP File Upload plugin (<=4.24.11), enabling unauthenticated…

exploitationinformation-gatheringpenetration-testing+2
10 months ago
Previous12…39Next