Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
64 results
WPCracker preview

WPCracker

GitHubjonirinta-kahila/wpcracker

WordPress pentest tool

information-gatheringpassword-attackspenetration-testing+1
42
5 years ago
device-activity-tracker preview

device-activity-tracker

GitHubgommzystudio/device-activity-tracker

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

educationexploitationinformation-gathering+7
5.1k8 months ago
obsidian-osint-templates preview

obsidian-osint-templates

GitHubwebbreacher/obsidian-osint-templates

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

curated-resourceseducationinformation-gathering+2
8093 months ago
Leaked-Credentials preview

Leaked-Credentials

GitHubh4x0r-dz/leaked-credentials

how to look for Leaked Credentials !

educationinformation-gatheringpenetration-testing+2
1.1k2 years ago
netlas-cookbook preview

netlas-cookbook

GitHubnetlas-io/netlas-cookbook

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

curated-resourcesdigital-forensicseducation+9
8891 year ago
OpenClaw_Termux preview

OpenClaw_Termux

GitHubandroidmalware/openclaw_termux

How to Install OpenClaw on an Android Phone and Control It via WhatsApp

android-securityeducationinformation-gathering+4
3237 months ago
TJ-OSINT-Notebook preview

TJ-OSINT-Notebook

GitHubtjnull/tj-osint-notebook

This OSINT Notebook provides an overview of the tools, techniques, and resources that I use for a variety of situations when it comes to performing…

curated-resourceseducationinformation-gathering+2
3722 years ago
buttinsky preview

buttinsky

GitHubmushorg/buttinsky

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

information-gatheringintrusion-detectionmalware-analysis+2
8213 years ago
react preview

react

GitHubjanhalendk/react

A OSINT project that explores how to dump data from React

educationinformation-gatheringosint+2
820 years ago
Social-media-c2 preview

Social-media-c2

GitHubwoj-ciech/social-media-c2

Script is a proof of concept how to control your machine by using social media sites.

command-and-controlinformation-gatheringosint-social-engineering+3
238 years ago
CVE-2022-46364-Proof-of-the-concept preview

CVE-2022-46364-Proof-of-the-concept

GitHubcybermaksx/cve-2022-46364-proof-of-the-concept

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

educationexploitationinformation-gathering+3
35 months ago
CVE-2026-31024 preview

CVE-2026-31024

GitHuberikdervishi03/cve-2026-31024

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

binary-exploitationeducationexploitation+5
23 months ago
LInux-Kernel-InfoLeak-6.12.-Leveraged-to-do-cross-container-info-leak.- preview

LInux-Kernel-InfoLeak-6.12.-Leveraged-to-do-cross-container-info-leak.-

GitHubspiralbl0ck/linux-kernel-infoleak-6.12.-leveraged-to-do-cross-container-info-leak.-

POC shows how to leak postgresql stuff cause hugefile sub-system. Based on https://x.com/spendergrsec/status/1993794163880718700?s=20

binary-exploitationcontainer-escapedata-exfiltration+3
29 months ago
Log4j-CVE-2021-44228 preview

Log4j-CVE-2021-44228

GitHubdark-ninja10/log4j-cve-2021-44228

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
Ios-Safari-Mallicous-Extension-Example preview

Ios-Safari-Mallicous-Extension-Example

GitHubspiralbl0ck/ios-safari-mallicous-extension-example

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

exploitationinformation-gatheringios-security+3
2 years ago
CVE-2024-50848 preview

CVE-2024-50848

GitHub1mhr4b/cve-2024-50848

Proof-of-concept for an XXE vulnerability in WorldServer v11.8.2; demonstrates how a crafted .tmx file can leak system files and potentially execute…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2023-27997 preview

CVE-2023-27997

GitHubcyb3renthusiast/cve-2023-27997

How to get access via CVE-2022-27997

exploitationinformation-gatheringpenetration-testing+2
3 years ago
HotelDruid-CVE-2021-42948 preview

HotelDruid-CVE-2021-42948

GitHubdhammon/hoteldruid-cve-2021-42948

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
Previous1234Next