Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
internal-security-detect preview

internal-security-detect

GitHubrxerium/internal-security-detect

The detection of internal security controls at a company

configuration-auditingdefensive-toolsinformation-gathering+5
2
7 months ago
CVE-2022-23779 preview

CVE-2022-23779

GitHubfbusr/cve-2022-23779

CVE-2022-23779: Internal Hostname Disclosure Vulnerability

exploitationinformation-gatheringreconnaissance+2
14 years ago
CVE-2025-67160 preview

CVE-2025-67160

GitHubremenis/cve-2025-67160

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

exploitationinformation-gatheringiot-security+3
7 months ago
CVE-2024-12404 preview

CVE-2024-12404

GitHubrandomrobbiebf/cve-2024-12404

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

database-securityexploitationinformation-gathering+3
1 year ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

api-security-testingcloud-securityexploitation+3
1 day ago
CVE-2023-48795 preview

CVE-2023-48795

GitHubhav0cx0/cve-2023-48795

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

information-gatheringnetwork-securitypenetration-testing+2
1 year ago
appledb_rs preview

appledb_rs

GitHubsynacktiv/appledb_rs

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

curated-resourcesinformation-gatheringios-security+3
2710 months ago
ridrelay preview

ridrelay

GitHubskorov/ridrelay

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

authenticationinformation-gatheringpenetration-testing+1
3996 years ago
duckLogger preview

duckLogger

GitHubitsmmdoha/ducklogger

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

command-and-controldata-exfiltrationembedded-systems-security+8
864 months ago
strot preview

strot

GitHubvertexcover-io/strot

API Scraper Agent for Web API's

api-security-testingcrawlerinformation-gathering+3
189 months ago
cve-2021-22146 preview

cve-2021-22146

GitHubmagichk/cve-2021-22146
database-securityexploitationinformation-gathering+2
35 years ago
CVE-2018-12598 preview

CVE-2018-12598

GitHubalt3kx/cve-2018-12598

CVE-2018-12598

exploitationinformation-gatheringpenetration-testing+2
8 years ago
CVE-2018-12597 preview

CVE-2018-12597

GitHubalt3kx/cve-2018-12597

CVE-2018-12597

exploitationinformation-gatheringpenetration-testing+2
8 years ago
CVE-2018-10715 preview

CVE-2018-10715

GitHubalt3kx/cve-2018-10715

CVE-2018-10715

exploitationinformation-gatheringpenetration-testing+2
8 years ago
CVE-2018-10467 preview

CVE-2018-10467

GitHubalt3kx/cve-2018-10467

CVE-2018-10467

exploitationinformation-gatheringpenetration-testing+2
8 years ago
WhoDat preview
Archived

WhoDat

GitHubmitrecnd/whodat

Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)

api-securitydata-exfiltrationdns-analysis+5
1594 years ago
Previous123Next