Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
waf-fu preview

waf-fu

GitHubconfused-binary/waf-fu

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

cloud-securitydefensive-toolsincident-response+6
2
1 month ago
PAGASUS-PRO preview

PAGASUS-PRO

GitHubthakur2309/pagasus-pro

Python ADB-based Android device management and security audit toolkit with an interactive menu for root detection, permission dumps, debuggable app…

android-securitydata-exfiltrationeducation+8
5341 month ago
Llama-Stack-0.4.0rc3-local-CVE-2026-25211 preview

Llama-Stack-0.4.0rc3-local-CVE-2026-25211

GitHubmbanyamer/llama-stack-0.4.0rc3-local-cve-2026-25211

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

database-securityexploitationinformation-gathering+3
8 months ago
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

data-exfiltrationexploitationinformation-gathering+3
1 month ago
CVE-2024-12849 preview

CVE-2024-12849

GitHubrandomrobbiebf/cve-2024-12849

Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read

exploitationinformation-gatheringvulnerability-analysis+1
1 year ago
ImpossibleTravelLogAnalysis preview

ImpossibleTravelLogAnalysis

GitHubnccgroup/impossibletravelloganalysis

Basic log analysis tool to detect impossible travel via IP address geographic information

anomaly-detectionforensicsincident-response+3
207 years ago
Zeek-Endpoint-Enrichment preview

Zeek-Endpoint-Enrichment

GitHubcorelight/zeek-endpoint-enrichment

Zeek log enrichment tool that adds host information and known entity references to enhance network security monitoring and incident response.

information-gatheringlog-analysisnetwork-security+1
43 months ago
buttinsky preview

buttinsky

GitHubmushorg/buttinsky

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

information-gatheringintrusion-detectionmalware-analysis+2
8213 years ago
fortios-auth-bypass-poc-CVE-2024-55591 preview

fortios-auth-bypass-poc-CVE-2024-55591

GitHubsysirq/fortios-auth-bypass-poc-cve-2024-55591

Proof-of-concept exploit for FortiOS authentication bypass (CVE-2024-55591) that allows unauthenticated access to system logs via WebSocket on…

authentication-authorizationexploitationinformation-gathering+3
261 year ago
AnySniff preview

AnySniff

GitHubmkultra6969/anysniff

AnySniff is a tool for monitoring TCP connections of processes like AnyDesk on Windows. It uses the CVE-2024-52940 vulnerability to track open…

exploitationinformation-gatheringnetwork-security+3
41 year ago
CVE-2025-44823 preview

CVE-2025-44823

GitHubskraft9/cve-2025-44823

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

api-securityauthenticationexploitation+3
10 months ago
CVE-2023-47668 preview

CVE-2023-47668

GitHubnxploited/cve-2023-47668

Python exploit for CVE-2023-47668 that extracts sensitive log information from vulnerable Restrict Content WordPress plugin versions <= 3.2.7.

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2023-47529 preview

CVE-2023-47529

GitHubrandomrobbiebf/cve-2023-47529

Cloud Templates & Patterns collection <= 1.2.2 - Sensitive Information Exposure via Log File

exploitationinformation-gatheringlog-analysis+3
12 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubshamo0/cve-2021-44228

log4shell (CVE-2021-44228) scanning tool

exploitationinformation-gatheringreconnaissance+3
44 years ago
CVE-2021-33558. preview

CVE-2021-33558.

GitHubmdanzaruddin/cve-2021-33558.

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

exploitationinformation-gatheringmisconfiguration+2
35 years ago
CVE-2020-17519 preview

CVE-2020-17519

GitHubgazettel/cve-2020-17519

Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2019-19653 preview

CVE-2019-19653

GitHubjra89/cve-2019-19653

Chevereto information disclosure <= 3.13.5 Core

exploitationinformation-gatheringmisconfiguration+2
6 years ago
CVE-2020-29666 preview

CVE-2020-29666

GitHubjet-pentest/cve-2020-29666

Proof-of-concept for CVE-2020-29666: directory listing vulnerability in Lan ATMService M3 ATM Monitoring System 6.1.0 that exposes log files…

information-gatheringmisconfigurationreconnaissance+2
5 years ago
Previous123Next