Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
CVE-2019-10779 preview

CVE-2019-10779

GitHubrepublicr0k/cve-2019-10779

GCHQ Stroom is vulnerable to Cross-Site Scripting due to the ability to load the Stroom dashboard on another site and insufficient protection against…

information-gatheringpenetration-testingvulnerability-analysis+1
2
5 years ago
Identificador-CVE-2018-11759 preview

Identificador-CVE-2018-11759

GitHubjulioliraup/identificador-cve-2018-11759

Bash script to detect and exploit CVE-2018-11759 in Apache Tomcat instances, with audit logging of target load balancer details, internal addresses,…

exploitationinformation-gatheringvulnerability-scanners+1
2 years ago
metasploit-framework preview
Archived

metasploit-framework

GitHubmarkoarmitage/metasploit-framework

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

command-and-controlexploitationexploit-frameworks+8
55 years ago
PowerHuntShares preview

PowerHuntShares

GitHubnetspi/powerhuntshares

Audits Active Directory SMB shares to inventory, analyze, and report excessive privileges. Discovers accessible systems, enumerates share ACLs,…

configuration-auditinginformation-gatheringnetwork-security+2
1.1k0 years ago
PANO preview

PANO

GitHubalw1ez/pano

Graph-based OSINT investigation platform with timeline analysis, entity management, and AI-powered transforms for uncovering hidden connections…

ai-securityinformation-gatheringosint+1
6177 months ago
M365Pwned preview

M365Pwned

GitHubotterhacker/m365pwned

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

data-exfiltrationexploitationimpersonation-tools+5
2517 months ago
linkedin-extension-fingerprinting preview

linkedin-extension-fingerprinting

GitHubmdp/linkedin-extension-fingerprinting

Documents and identifies 2,953 Chrome extensions silently probed by LinkedIn, providing tools to fetch extension names and analyze browser…

data-exfiltrationfingerprint-spoofinginformation-gathering+4
2168 months ago
MysqlHoneypot preview

MysqlHoneypot

GitHubal1ex/mysqlhoneypot

MysqlHoneypot

defensive-toolsinformation-gatheringintrusion-detection+2
244 years ago
CVE-2018-6389 preview

CVE-2018-6389

GitHubomidsec/cve-2018-6389

PoC Exploit CVE-2018-6389

exploitationinformation-gatheringpenetration-testing+2
710 months ago
CNVD-2020-10487-Bulk-verification preview

CNVD-2020-10487-Bulk-verification

GitHubdelsadan/cnvd-2020-10487-bulk-verification

CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本,批量验证,并自动截图,方便提交及复核

exploitationinformation-gatheringpenetration-testing+2
36 years ago
CVE-2025-2294 preview

CVE-2025-2294

GitHubnxploited/cve-2025-2294

Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion

educationexploitationinformation-gathering+3
31 year ago
AVX-Side-Channel preview

AVX-Side-Channel

GitHubbytereaper77/avx-side-channel

AVX-Based Timing Side Channel — ASLR Detection

educationhardware-securityinformation-gathering+1
11 year ago