Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
DahuaConsole preview

DahuaConsole

GitHubmcw0/dahuaconsole

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

authentication-authorizationembedded-systems-securityexploitation+5
318
1 year ago
CVE-2019-17221 preview

CVE-2019-17221

GitHubh4ckologic/cve-2019-17221

PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read…

exploitationinformation-gatheringreconnaissance+2
86 years ago
CVE-2019-5513-scanner preview

CVE-2019-5513-scanner

GitHubsudosu01/cve-2019-5513-scanner

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

exploitationinformation-gatheringpenetration-testing+3
2 months ago
CVE-2022-23779 preview

CVE-2022-23779

GitHubrishi-kaul/cve-2022-23779

CVE-2022-23779 is a security vulnerability in Zoho ManageEngine Desktop Central ,Testing for CVE-2022-23779 using curl

exploitationinformation-gatheringpenetration-testing+3
7 months ago
CVE-2017-9506 preview

CVE-2017-9506

GitHublabsbots/cve-2017-9506

Atlassian Jira XSS attack via Server Side Request Forgery (SSRF).

exploitationinformation-gatheringpenetration-testing+3
4 years ago
ntlm_theft preview

ntlm_theft

GitHubgreenwolf/ntlm_theft

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

information-gatheringpassword-attackspenetration-testing+2
1.5k11 months ago
leakdb preview

leakdb

GitHubmoloch--/leakdb

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

cloud-securitydata-exfiltrationinformation-gathering+2
1916 years ago
CVE-2023-26083 preview

CVE-2023-26083

GitHubnoverisp3/cve-2023-26083

CVE-2023-26083-Mali-InfoLeak-PoC

binary-exploitationeducationexploitation+3
2 months ago
CVE-2025-68645 preview

CVE-2025-68645

GitHubcrow5-oss/cve-2025-68645
exploitationinformation-gatheringpenetration-testing+3
6 months ago
CVE-2023-7231 preview

CVE-2023-7231

GitHubbbo513/cve-2023-7231

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

cloud-securitycontainer-securitydata-exfiltration+6
11 year ago
Identificador-CVE-2018-11759 preview

Identificador-CVE-2018-11759

GitHubjulioliraup/identificador-cve-2018-11759
exploitationinformation-gatheringvulnerability-scanners+1
2 years ago
SCANNER-INURLBR preview

SCANNER-INURLBR

GitHubgoogleinurl/scanner-inurlbr

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

email-harvestinginformation-gatheringosint+2
8805 years ago
sonar.js preview

sonar.js

GitHubmandatoryprogrammer/sonar.js

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

exploitationinformation-gatheringpenetration-testing+3
55210 years ago
SCANNER-INURLBR preview

SCANNER-INURLBR

GitHubmrcl0wnlab/scanner-inurlbr

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

crawlerdns-subdomain-enumerationemail-harvesting+6
2291 year ago
vinifera preview

vinifera

GitHubzomato/vinifera

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

incident-responseinformation-gatheringosint+2
942 years ago
automato preview

automato

GitHubskahwah/automato

automato should help with automating some of the user-focused enumeration tasks during an internal penetration test.

information-gatheringpassword-attackspenetration-testing
716 years ago
kong-pwn preview

kong-pwn

GitHubrandomrobbiebf/kong-pwn

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

api-securitycloud-securityexploitation+6
66 years ago
Zoho_CVE-2022-23779 preview

Zoho_CVE-2022-23779

GitHubvulnmachines/zoho_cve-2022-23779

Internal Hostname Disclosure Vulnerability

exploitationinformation-gatheringreconnaissance+2
43 years ago
Previous123Next