Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read preview

CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read

GitHubgeorge0papasotiriou/cve-2026-21015-php-filter-chain-arbitrary-file-read

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

data-exfiltrationexploitationinformation-gathering+4
1 month ago
godehashed preview

godehashed

GitHuban00byss/godehashed

A golang tool that uses the dehashed.com API to search for compromised assets.

data-exfiltrationinformation-gatheringosint+1
105 years ago
slack-watchman preview

slack-watchman

GitHubpapermtn/slack-watchman

Slack enumeration and exposed secrets detection tool

defensive-toolsinformation-gatheringosint+3
40315 days ago
gitlab-watchman preview

gitlab-watchman

GitHubpapermtn/gitlab-watchman

Finding exposed secrets and personal data in GitLab

code-analysisdata-exfiltrationdevsecops+3
2061 year ago
CVE-2025-68613 preview

CVE-2025-68613

GitHubintelligent-ears/cve-2025-68613

Nuclei-based detection template for CVE-2025-68613, a critical RCE in n8n workflow automation. Uses multi-layered passive fingerprinting to identify…

exploitationinformation-gatheringpenetration-testing+3
8 months ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubalt3kx/cve-2022-22965

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

exploitationinformation-gatheringpenetration-testing+3
1004 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubabhishekmorla/cve-2022-26134

Exploit scanner for CVE-2022-26134 in Atlassian Confluence. Uses Shodan to find vulnerable hosts, then executes commands via the OGNL injection…

exploitationinformation-gatheringpenetration-testing+3
84 years ago
CVE-2014-0160-Scanner preview

CVE-2014-0160-Scanner

GitHubobayesshelton/cve-2014-0160-scanner

PHP CLI script to scan domains for the CVE-2014-0160 (Heartbleed) vulnerability using an external API service.

exploitationinformation-gatheringpenetration-testing+2
12 years ago
robin preview

robin

GitHubapurvsinghgautam/robin

AI-powered dark web OSINT tool that uses LLMs to refine queries, filter search results, and generate investigation summaries with a web UI and Docker…

ai-securitycrawlerinformation-gathering+3
7.0k19 days ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
cloudbunny preview

cloudbunny

GitHubwarflop/cloudbunny

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

information-gatheringosintreconnaissance+2
3762 years ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
11 month ago
CVE-2024-56331 preview

CVE-2024-56331

GitHubgriisemine/cve-2024-56331

Proof-of-concept exploit for CVE-2024-56331, demonstrating Local File Inclusion in Uptime Kuma via improper URL handling in the real-browser monitor.…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160 preview

CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

GitHubsimoesctt/ctt-heartbleed-temporal-resonance-memory-leak-exploit-heartbleed-cve-2014-0160

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,…

educationexploitationinformation-gathering+6
7 months ago
blind-sql-bitshifting preview
Archived

blind-sql-bitshifting

GitHubawnumar/blind-sql-bitshifting

A blind SQL injection module that uses bitshfting to calculate characters.

information-gatheringpenetration-testingvulnerability-analysis+1
1334 years ago
telegram-nearby-map preview

telegram-nearby-map

GitHubtejado/telegram-nearby-map

Maps nearby Telegram users using trilateration of distance data from the official Telegram library and OpenStreetMap, for OSINT and geolocation…

information-gatheringosintprivacy+1
1.2k2 years ago
CrossLinked preview

CrossLinked

GitHubm8sec/crosslinked

LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping

email-harvestinginformation-gatheringosint+2
1.6k1 year ago
subscraper preview

subscraper

GitHubm8sec/subscraper

Subdomain and target enumeration tool built for offensive security testing

dns-analysisinformation-gatheringosint+3
9742 years ago
Previous123Next