Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
157 results
AWSBucketDump preview

AWSBucketDump

GitHubjordanpotti/awsbucketdump

Security Tool to Look For Interesting Files in S3 Buckets

cloud-securityinformation-gatheringpenetration-testing+1
1.5k
4 years ago
uDork preview

uDork

GitHubm3n0sd0n4ld/udork

uDork is a script written in Bash Scripting that uses advanced Google search techniques to obtain sensitive information in files or directories, find…

information-gatheringosintreconnaissance+2
8674 years ago
eviltree preview

eviltree

GitHubt3l3machus/eviltree

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

information-gatheringpost-exploitationprivilege-escalation+3
4131 year ago
JSpector preview

JSpector

GitHubhisxo/jspector

A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues

crawlerinformation-gatheringweb-security
3773 years ago
CVE-2026-37070 preview

CVE-2026-37070

GitHubjfs-jfs/cve-2026-37070

Proof-of-concept exploit for CVE-2026-37070: an authenticated attacker can read arbitrary uploaded files in Veno File Manager 4.4.9 via a crafted GET…

exploitationinformation-gatheringpenetration-testing+2
3 months ago
Windows-Explorer-CVE-2025-24071 preview

Windows-Explorer-CVE-2025-24071

GitHubcesarbtakeda/windows-explorer-cve-2025-24071

PoC exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability that leaks NTLM hashes via malicious .library-ms files in RAR/ZIP…

educationexploitationinformation-gathering+2
11 year ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4804 years ago
GooFuzz preview

GooFuzz

GitHubm3n0sd0n4ld/goofuzz

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

dns-subdomain-enumerationfuzzinginformation-gathering+3
1.6k9 months ago
golddigger preview

golddigger

GitHubustayready/golddigger

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

data-exfiltrationinformation-gatheringpenetration-testing+1
1983 years ago
iCULeak.py preview

iCULeak.py

GitHubllt4l/iculeak.py

Tool to find and extract credentials from phone configuration files hosted on CUCM

information-gatheringosintpenetration-testing
1037 years ago
grafana-unauth-file-read preview

grafana-unauth-file-read

GitHubvulnmachines/grafana-unauth-file-read

Exploit for Grafana LFI vulnerability CVE-2021-43798 enabling unauthorized file reading via path traversal in plugin endpoints.

exploitationinformation-gatheringpenetration-testing+3
44 years ago
CVE-2024-36991 preview

CVE-2024-36991

GitHubgunzf0x/cve-2024-36991

Proof-of-concept exploit for CVE-2024-36991 enabling arbitrary file read via path traversal in Splunk for Windows versions below 9.2.2, 9.1.5, and…

exploitationinformation-gatheringpenetration-testing+2
41 year ago
CVE-2021-33558. preview

CVE-2021-33558.

GitHubmdanzaruddin/cve-2021-33558.

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

exploitationinformation-gatheringmisconfiguration+2
35 years ago
pillager preview

pillager

GitHubbrittonhayes/pillager

Pillage filesystems for sensitive information with Go 🔍

data-exfiltrationinformation-gatheringpenetration-testing+4
31610 months ago
lifer preview

lifer

GitHubpaul-tew/lifer

Windows link file (shortcuts) examiner

binary-analysisdigital-forensicsforensics+1
682 years ago
Awesome-Pentest preview

Awesome-Pentest

GitHubkc57/awesome-pentest

A list of awesome penetration testing tools and resources.

cloud-securitycurated-resourceseducation+9
842 years ago
vt-py-scanner preview

vt-py-scanner

GitHubneorai/vt-py-scanner

Recursively scan folders with VirusTotal API to detect malware. Features hash lookup, CSV export, real-time progress, and rate-limit handling for…

forensicshash-analysisinformation-gathering+3
69 months ago
MyLog4Shell preview

MyLog4Shell

GitHubkal1gh0st/mylog4shell

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

dns-analysisexploitationinformation-gathering+3
14 years ago
Previous12…9Next