Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
173 results
ipChecker preview

ipChecker

GitHubmthbernardes/ipchecker

Check if a IP is from tor or is a malicious proxy

information-gatheringnetwork-securityosint+1
568 years ago
POC-2020-8558 preview

POC-2020-8558

GitHubtabbysable/poc-2020-8558

Information about Kubernetes CVE-2020-8558, including proof of concept exploit.

cloud-securitycontainer-securityexploitation+5
436 years ago
CVE-2025-62168 preview

CVE-2025-62168

GitHubmonzaviman/cve-2025-62168

Scanner and proof-of-concept for CVE-2025-62168, detecting Squid Proxy information disclosure that leaks HTTP authentication credentials.

exploitationinformation-gatheringpenetration-testing+2
1610 months ago
LeakSearch preview

LeakSearch

GitHubjoelgmsec/leaksearch

Searches and parses plaintext passwords from public breach databases (ProxyNova COMB) by keyword (user/domain/password), with proxy support and…

data-exfiltrationinformation-gatheringosint+1
4411 year ago
SuperMicro-Password-Scanner preview

SuperMicro-Password-Scanner

GitHub1n3/supermicro-password-scanner

Supermicro IPMI/BMC Cleartext Password Scanner

hardware-iot-securityinformation-gatheringmisconfiguration+3
4211 years ago
cloudbunny preview

cloudbunny

GitHubwarflop/cloudbunny

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

information-gatheringosintreconnaissance+2
3762 years ago
jsubfinder preview

jsubfinder

GitHubthreatunknown/jsubfinder

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

information-gatheringosintreconnaissance+3
2841 year ago
PhantomCrawler preview

PhantomCrawler

GitHubspyboy-productions/phantomcrawler

Multi-proxy web interaction simulator for analyzing traffic behavior, access controls, and response patterns under varied network conditions.…

information-gatheringpenetration-testingreconnaissance+1
808 months ago
ache preview

ache

GitHubvida-nyu/ache

Focused web crawler that uses page classifiers and link prioritization to efficiently collect domain-specific or pattern-matching web pages, with…

crawlerinformation-gatheringmachine-learning+1
4881 year ago
cPanel-WHM-CVE-2026-41940-auth-bypass-exploit preview

cPanel-WHM-CVE-2026-41940-auth-bypass-exploit

GitHubcerberusmrxi/cpanel-whm-cve-2026-41940-auth-bypass-exploit

Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without…

authentication-authorizationexploitationinformation-gathering+3
21 month ago
CVE-2023-6895 preview

CVE-2023-6895

GitHubnles-crt/cve-2023-6895

Python script to scan websites for CVE-2023-6895 vulnerability. Sends crafted requests, checks responses, and logs exploitable URLs with progress bar…

educationexploitationinformation-gathering+3
2 years ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
8901 month ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1247 months ago
CVE-2025-62168 preview

CVE-2025-62168

GitHubshahroodcert/cve-2025-62168

Proof-of-concept scanner for CVE-2025-62168, a Squid Proxy information disclosure vulnerability that exposes HTTP authentication credentials,…

exploitationinformation-gatheringpenetration-testing+2
110 months ago
CVE-2020-13158 preview

CVE-2020-13158

GitHubinfosec4fun/cve-2020-13158

CVE-2020-13158 - Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal

exploitationinformation-gatheringpenetration-testing+3
16 years ago
CVE-2025-2294 preview

CVE-2025-2294

GitHubr0otk3r/cve-2025-2294

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

code-analysisexploitationinformation-gathering+3
1 year ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubr0otk3r/cve-2025-31161

Python exploit for CVE-2025-31161, an authentication bypass in CrushFTP. Retrieves user lists via crafted CrushAuth and AWS4-HMAC-SHA256 headers.…

authenticationexploitationinformation-gathering+3
1 year ago
CVE-2020-17519 preview

CVE-2020-17519

GitHubgazettel/cve-2020-17519

Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

exploitationinformation-gatheringpenetration-testing+3
1 year ago
Previous123…10Next