Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
687 results
Praeda preview

Praeda

GitHubpercx/praeda

Automated data harvesting tool for extracting sensitive information (backups, clones, address books) from web servers via targeted scanning and…

crawlerinformation-gatheringnetwork-mapping+3
192
2 years ago
Burp_Collector preview

Burp_Collector

GitHubsajibuu/burp_collector

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

api-security-testinginformation-gatheringpenetration-testing+4
102 years ago
gitlab-12.9.0-file-read preview

gitlab-12.9.0-file-read

GitHuberk3/gitlab-12.9.0-file-read

A (wanted to be) better script than what can be found on exploit-db about the authenticated arbitrary read file on GitLab v12.9.0 (CVE-2020-10977)

exploitationinformation-gatheringpenetration-testing+2
5 years ago
magic-extractor preview

magic-extractor

GitHubxchwarze/magic-extractor

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

binary-analysisdata-recoverydigital-forensics+8
365 days ago
cve-2022-44268-detector preview

cve-2022-44268-detector

GitHubjnschaeffer/cve-2022-44268-detector

Detect images that likely exploit CVE-2022-44268

binary-analysisdata-exfiltrationforensics+3
52 years ago
Inspector preview

Inspector

GitHubgraniet/inspector

The Inspector tool is a privilege escalation helper (PoC), easy to deployed on web server, this tool can list process running with root, check kernel…

information-gatheringpenetration-testingprivilege-escalation+1
1207 years ago
ActiveReign preview

ActiveReign

GitHubm8sec/activereign

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

command-and-controlexploitationinformation-gathering+2
2462 years ago
Gxss preview
Archived

Gxss

GitHubkathanp19/gxss

A tool to check a bunch of URLs that contain reflecting params.

information-gatheringpenetration-testingreconnaissance+2
6022 years ago
CVE-2019-13063-POC preview

CVE-2019-13063-POC

GitHub0x6b7966/cve-2019-13063-poc

Proof of concept tool to exploit the directory traversal and local file inclusion vulnerability that resides in the Sahi-pro web application…

exploitationinformation-gatheringpenetration-testing+2
7 years ago
cve-2016-1764 preview

cve-2016-1764

GitHubmoloch--/cve-2016-1764

Extraction of iMessage Data via XSS

data-exfiltrationexploitationinformation-gathering+4
5110 years ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
2 days ago
CVE-2024-27630 preview

CVE-2024-27630

GitHubally-petitt/cve-2024-27630

CVE-2024–27630 Reference

educationinformation-gatheringpapers-research+3
2 years ago
CVE-2021-43798 preview

CVE-2021-43798

GitHubokymi-x/cve-2021-43798

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

encryption-decryption-toolsexploitationinformation-gathering+3
2 months ago
Chrome-and-Edge-Version-Dumper preview

Chrome-and-Edge-Version-Dumper

GitHubmav3r1ck0x1/chrome-and-edge-version-dumper

Powershell script that dumps Chrome and Edge version to a text file in order to determine if you need to update due to CVE-2022-1096

general-purpose-utilitiesinformation-gatheringscripting-automation+1
24 years ago
CVE-2021-3019 preview

CVE-2021-3019

GitHubgivemefivw/cve-2021-3019

Automated exploitation tool for CVE-2021-3019 that reads target IPs from a text file and executes the exploit against HTTP endpoints.

exploitationinformation-gatheringreconnaissance+2
5 years ago
hikvision_CVE-2017-7921_auth_bypass_config_decryptor preview

hikvision_CVE-2017-7921_auth_bypass_config_decryptor

GitHubp4tq/hikvision_cve-2017-7921_auth_bypass_config_decryptor

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, revealing user credentials and device settings.

encryption-decryption-toolsexploitationinformation-gathering+3
4 years ago
PutScanner preview

PutScanner

GitHubx00byte/putscanner

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]

exploitationinformation-gatheringpenetration-testing+3
81 year ago
Extracter preview

Extracter

GitHubk3ystr0k3r/extracter

A nice web-crawler written in Bash that will look for login pages/admin-panels for you on any given website.

crawlerinformation-gatheringosint+2
63 years ago
Previous123…39Next