Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
63 results
netmap.js preview

netmap.js

GitHubserain/netmap.js

Fast browser-based network discovery module

information-gatheringnetwork-mappingpenetration-testing+2
1155 years ago
Azur3Alph4 preview

Azur3Alph4

GitHubhyd3sec/azur3alph4

PowerShell module for post-breach Azure red teaming, automating token extraction, resource enumeration, and lateral movement within managed identity…

cloud-securityinformation-gatheringpenetration-testing+3
635 years ago
tiktok-scraper preview

tiktok-scraper

GitHubsoxoj/tiktok-scraper

Scrape and download TikTok video posts, user profiles, hashtag trends, and music feed metadata via CLI or Node.js module. Supports batch downloads,…

crawlerdata-exfiltrationinformation-gathering+1
494 years ago
CVE-2017-7529 preview

CVE-2017-7529

GitHubshehzadcyber/cve-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into…

exploitationinformation-gatheringpenetration-testing+2
114 years ago
MalConfig preview

MalConfig

GitHubjacobsoo/malconfig

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

android-securitycommand-and-controlinformation-gathering+3
77 years ago
citrix_adc_netscaler_lfi preview

citrix_adc_netscaler_lfi

GitHubzeop-cybersec/citrix_adc_netscaler_lfi

This Metasploit-Framework module can be use to help companies to check the last Citrix vulnerability CVE-2020-8193, CVE-2020-8195 and CVE-2020-8196…

exploit-frameworksinformation-gatheringpenetration-testing+3
66 years ago
PasswordsSniffer preview

PasswordsSniffer

GitHubmauricelambert/passwordssniffer

This module sniff username and password of unprotected protocols.

information-gatheringnetwork-securitypacket-sniffing-analysis+2
95 years ago
CVE-2019-1003000_RCE-DETECTION preview

CVE-2019-1003000_RCE-DETECTION

GitHub1nthekut/cve-2019-1003000_rce-detection

A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for…

exploitationinformation-gatheringpenetration-testing+3
47 years ago
CVE-2026-24849 preview

CVE-2026-24849

GitHubdoany1/cve-2026-24849

Proof-of-concept exploit for CVE-2026-24849, an authenticated path-traversal arbitrary file read in OpenEMR's EtherFax module. Reads server files…

data-exfiltrationexploitationinformation-gathering+3
3 months ago
ExploitVelotiSmart preview

ExploitVelotiSmart

GitHubs1kr10s/exploitvelotismart

Exploit module for VelotiSmart local file inclusion (CVE-2018-14064) that retrieves sensitive files from vulnerable web servers.

exploitationinformation-gatheringpenetration-testing+2
47 years ago
nmap-CVE-2022-21907 preview

nmap-CVE-2022-21907

GitHubgpiechnik2/nmap-cve-2022-21907

Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution.…

exploitationinformation-gatheringpenetration-testing+2
24 years ago
CVE-2025-48703 preview

CVE-2025-48703

GitHubitstarsec/cve-2025-48703

Proof-of-concept exploit for CVE-2025-48703, an unauthenticated remote code execution vulnerability in CentOS Web Panel (CWP) versions prior to…

exploitationinformation-gatheringreconnaissance+2
3 months ago
Bluetooth-Crash-CVE-2017-0785 preview

Bluetooth-Crash-CVE-2017-0785

GitHubravss/bluetooth-crash-cve-2017-0785

Exploit script for CVE-2017-0785 that crashes the Bluetooth module on Android 4.0+ devices by sending crafted SDP search requests, causing…

android-securitybluetooth-securityexploitation+3
18 years ago
-Exploit-CVE-2017-7529 preview

-Exploit-CVE-2017-7529

GitHubcoolman6942o/-exploit-cve-2017-7529

CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module…

exploitationinformation-gatheringpenetration-testing+2
12 years ago
CVE-2018-13379 preview

CVE-2018-13379

GitHubyukar1z0e/cve-2018-13379

Exploit module for CVE-2018-13379 targeting Fortinet VPN path traversal vulnerability. Scans IP lists and extracts credentials from vulnerable…

exploitationinformation-gatheringpenetration-testing+2
6 years ago
CVE-2020-17519 preview

CVE-2020-17519

GitHubdev-team-12x/cve-2020-17519

Metasploit auxiliary module exploiting CVE-2020-17519 for unauthenticated directory traversal in Apache Flink, enabling arbitrary file read via HTTP…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
cve-2013-3319 preview

cve-2013-3319

GitHubdevoteam-cybertrust/cve-2013-3319

metasploit module for CVE-2013-3319 / SAP Security Note 1816536

exploit-frameworksinformation-gatheringpenetration-testing+3
12 years ago
CVE-2022-34961 preview

CVE-2022-34961

GitHubbypazs/cve-2022-34961

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users…

educationexploitationinformation-gathering+3
4 years ago
Previous1234Next