Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
68 results
udpx preview

udpx

GitHubnullt3r/udpx

Single-packet UDP scanner in Go for fast discovery of 45+ services across networks, supporting custom probes, CIDR scanning, and JSONL output.

information-gatheringnetwork-securityport-scanning+2
238
2 months ago
SCANNER-INURLBR preview

SCANNER-INURLBR

GitHubmrcl0wnlab/scanner-inurlbr

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

crawlerdns-subdomain-enumerationemail-harvesting+6
2351 year ago
mass3 preview

mass3

GitHubsmiegles/mass3

Multi-threaded DNS-based enumeration tool for discovering AWS S3 buckets using pre-compiled wordlists and custom DNS resolvers, with optional Docker…

cloud-securitydns-analysisinformation-gathering+2
1257 years ago
ParaForge preview

ParaForge

GitHubanof-cyber/paraforge

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

fuzzinginformation-gatheringpenetration-testing+1
1423 years ago
dns-rebinding-tool preview

dns-rebinding-tool

GitHubh43z/dns-rebinding-tool

dns rebind tool with custom scripts

dns-analysisinformation-gatheringpenetration-testing+1
853 years ago
webstor preview

webstor

GitHubrossgeerlings/webstor

Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

dns-analysisinformation-gatheringreconnaissance+2
1582 years ago
IIS-Backdoor preview

IIS-Backdoor

GitHubnu11secur1ty/iis-backdoor

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

command-and-controlexploitationids-ips-evasion+4
346 years ago
BadExclusionsNWBO preview

BadExclusionsNWBO

GitHubiamagarre/badexclusionsnwbo

BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR

defensive-toolsinformation-gatheringpenetration-testing+2
752 years ago
cowcloud preview

cowcloud

GitHubnccgroup/cowcloud

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

cloud-infrastructure-securitycloud-securitydevsecops+5
603 years ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
92 months ago
CVE-2019-0708Poc-BatchScanning preview

CVE-2019-0708Poc-BatchScanning

GitHubht0ruial/cve-2019-0708poc-batchscanning

Batch scanning tool for CVE-2019-0708 (BlueKeep) vulnerability detection on Windows systems, supporting single and multi-IP scanning with custom IP…

exploitationinformation-gatheringnetwork-security+3
57 years ago
CVE-2026-49772 preview

CVE-2026-49772

GitHubjoshuavanderpoll/cve-2026-49772

Blind SQL injection exploit for CVE-2026-49772 targeting The Events Calendar WordPress plugin. Extracts database contents via boolean/time-based…

exploitationinformation-gatheringpenetration-testing+2
43 months ago
CVE-2026-29000-PoC-Exploit preview

CVE-2026-29000-PoC-Exploit

GitHubtc4dy/cve-2026-29000-poc-exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

authentication-authorizationeducationexploitation+6
33 months ago
ESXi-Ransomware-Scanner-mi preview

ESXi-Ransomware-Scanner-mi

GitHubcyberthreatanalysis/esxi-ransomware-scanner-mi

ESXi EZ - A custom scanner that takes list of IPs either in JSON, CSV or individually and checks for infection CVE-2021-21974

information-gatheringreconnaissancescripting-automation+2
23 years ago
FOFA-API-Threaded-Searcher preview

FOFA-API-Threaded-Searcher

GitHubjenderal92/fofa-api-threaded-searcher

Multi‑threaded Python tool to query FOFA API, extract custom fields (IP, port, cert, TLS, etc.), deduplicate results, and resume interrupted searches.

information-gatheringiot-securityosint+1
4 months ago
Vite-CVE-2025-30208-EXP preview

Vite-CVE-2025-30208-EXP

GitHublilil3333/vite-cve-2025-30208-exp

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2016-6210-exploit preview

CVE-2016-6210-exploit

GitHubgoomdan/cve-2016-6210-exploit

Custom exploit written for enumerating usernames as per CVE-2016-6210

exploitationinformation-gatheringpassword-attacks+3
12 years ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubfernandobortotti/cve-2024-24919

Automated exploit for CVE-2024-24919 with API-based vulnerable IP discovery and LFI brute-force using custom wordlists. Designed for educational…

educationexploitationinformation-gathering+3
12 years ago
Previous1234Next