Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
687 results
CVE-2025-24071 preview

CVE-2025-24071

GitHubabdelrahman0sayed/cve-2025-24071

This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive…

exploitationinformation-gatheringpassword-cracking+4
1
8 months ago
WordPress-File-Upload-4.24.11---Unauthenticated-Path-Traversal preview

WordPress-File-Upload-4.24.11---Unauthenticated-Path-Traversal

GitHubamirqusairy99/wordpress-file-upload-4.24.11---unauthenticated-path-traversal

Python-based tool to detect and exploit arbitrary file read vulnerability in WordPress WP File Upload plugin (<=4.24.11), enabling unauthenticated…

exploitationinformation-gatheringpenetration-testing+2
10 months ago
bfac preview

bfac

GitHubmazen160/bfac

BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.

information-gatheringreconnaissancevulnerability-scanners+1
5624 years ago
CVE-2025-505050 preview

CVE-2025-505050

GitHubaljoharasubaie/cve-2025-505050

An issue was discovered in machpanel 8 allowing attackers to execute arbitrary commands via the ticket text box.

exploitationinformation-gatheringpenetration-testing+2
8 months ago
CVE-2019-12102-Scanner preview

CVE-2019-12102-Scanner

GitHubegi08/cve-2019-12102-scanner

Automated scanner for CVE-2019-12102 unauthenticated file upload vulnerability in Kentico CMS. Checks domains, verifies with hash parameter, and…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2018-2628-MultiThreading preview

CVE-2018-2628-MultiThreading

GitHubaedoo/cve-2018-2628-multithreading

WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreading

exploitationinformation-gatheringpenetration-testing+3
158 years ago
cowcloud preview

cowcloud

GitHubnccgroup/cowcloud

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

cloud-infrastructure-securitycloud-securitydevsecops+5
603 years ago
CVE-2022-47952 preview

CVE-2022-47952

GitHubmaherazzouzi/cve-2022-47952

LXC Information Disclosure vulnerability.

container-securityexploitationinformation-gathering+2
3 years ago
CVE-2021-43008-AdminerRead preview

CVE-2021-43008-AdminerRead

GitHubp0dalirius/cve-2021-43008-adminerread

Exploit tool for CVE-2021-43008 Adminer 1.0 up to 4.6.2 Arbitrary File Read vulnerability

exploitationinformation-gatheringpenetration-testing+3
852 years ago
CVE-2017-7921 preview

CVE-2017-7921

GitHubmverschu/cve-2017-7921

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

authenticationexploitationinformation-gathering+5
6 months ago
SharpStat preview

SharpStat

GitHubraikia/sharpstat

C# utility that uses WMI to run "cmd.exe /c netstat -n", save the output to a file, then use SMB to read and delete the file remotely

information-gatheringlateral-movementnetwork-security+2
396 years ago
CVE-2025-24071-PoC preview

CVE-2025-24071-PoC

GitHublooky243/cve-2025-24071-poc

CVE-2025-24071 Proof Of Concept

data-exfiltrationexploitationinformation-gathering+3
31 year ago
Daily-dose-of-malware preview

Daily-dose-of-malware

GitHubwoj-ciech/daily-dose-of-malware

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

command-and-controlinformation-gatheringmalware-analysis+2
408 years ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubviszsec/cve-2024-23897

Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE

code-analysisexploitationinformation-gathering+3
52 years ago
SMBCrunch preview

SMBCrunch

GitHubraikia/smbcrunch

3 tools that work together to simplify reconaissance of Windows File Shares

information-gatheringnetwork-securitypenetration-testing+2
1708 years ago
lnkbomb preview
Archived

lnkbomb

GitHubdievus/lnkbomb

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

exploitationinformation-gatheringlateral-movement+3
3631 year ago
IpGeo preview

IpGeo

GitHubz4l4mi/ipgeo

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

information-gatheringnetwork-forensicsosint+1
1323 years ago
Instagram-Notes-Audio-Leakage-via-URL-Extraction-Fixed preview

Instagram-Notes-Audio-Leakage-via-URL-Extraction-Fixed

GitHubi12gocaj/instagram-notes-audio-leakage-via-url-extraction-fixed

Informe técnico de una vulnerabilidad ya corregida en Instagram Notes que exponía el audio original de vídeos mediante URLs directas.

educationinformation-gatheringpapers-research+2
81 year ago
Previous1…345…39Next