Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
111 results
SirepRAT preview

SirepRAT

GitHubsafebreach-labs/sireprat

Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)

command-and-controlexploitationiot-security+4
389
5 years ago
DahuaLoginBypass preview

DahuaLoginBypass

GitHubbp2008/dahualoginbypass

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

authentication-authorizationexploitationiot-security+3
1982 months ago
hackEmbedded preview

hackEmbedded

GitHubdoudoudedi/hackembedded

This tool is used for encrypt backdoor,shellcode,socks5 proxy generation,Information retrieval and POC arrangement for various architecture devices

command-and-controlembedded-systems-securityencryption-decryption-tools+8
2062 months ago
KITT-Lite preview

KITT-Lite

GitHubcisc0-gif/kitt-lite

Python-Based Pentesting CLI Tool

command-and-controlexploit-frameworkshardware-hacking+9
905 years ago
CVE-2021-4045 preview

CVE-2021-4045

GitHubhacefresko/cve-2021-4045

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

binary-analysiscommand-and-controlembedded-systems-security+6
1191 year ago
duckLogger preview

duckLogger

GitHubitsmmdoha/ducklogger

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

command-and-controldata-exfiltrationembedded-systems-security+8
915 months ago
signy preview

signy

GitHubgolioth/signy

Asymmetric cryptography library for generating signed URLs on embedded devices, enabling time-limited resource access using PSA Crypto API with…

authentication-authorizationcryptographyembedded-systems-security+3
706 months ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubverylazytech/cve-2024-10914

POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS

command-and-controlexploitationiot-security+3
481 year ago
CVE-2024-53375 preview

CVE-2024-53375

GitHubthottysploity/cve-2024-53375

TP-Link Archer AXE75 Authenticated Command Injection

command-and-controlexploitationhardware-security+4
211 year ago
cve-2022-31898 preview

cve-2022-31898

GitHubgigaryte/cve-2022-31898

Proof-of-concept exploit for CVE-2022-31898, a command injection vulnerability in GL-iNet routers (firmware < 3.215). Provides reverse shell via…

command-and-controlexploitationiot-security+3
183 years ago
TP-Link-ArcherC5-RCE preview

TP-Link-ArcherC5-RCE

GitHubjackdoan/tp-link-archerc5-rce

CVE-2018-19537

command-and-controlembedded-systems-securityexploitation+8
207 years ago
my-little-honeypot preview

my-little-honeypot

GitHubpandipanda69/my-little-honeypot

Lightweight telnet honeypot for capturing IoT malware samples and identifying active command-and-control infrastructure, designed for educational…

command-and-controliot-securitymalware-analysis+2
179 years ago
CVE-2022-39073 preview

CVE-2022-39073

GitHubv0lp3/cve-2022-39073

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

command-and-controlexploitationiot-security+3
113 years ago
CVE-2024-7120 preview

CVE-2024-7120

GitHubgh-ost00/cve-2024-7120

Proof-of-concept exploit for CVE-2024-7120 command injection vulnerability in RAISECOM gateway devices. Provides exploitation details, affected…

command-and-controlexploitationiot-security+3
82 years ago
CVE-2021-4045 preview

CVE-2021-4045

GitHub0xbinder/cve-2021-4045

🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓

command-and-controlexploitationhardware-iot-security+3
92 years ago
CVE-2022-36267-PoC preview

CVE-2022-36267-PoC

GitHub0xnslabs/cve-2022-36267-poc

PoC Script for CVE-2022-36267: Exploits an unauthenticated remote command injection vulnerability in Airspan AirSpot 5410 antenna.

command-and-controleducationexploitation+3
122 years ago
CVE-2022-30023 preview

CVE-2022-30023

GitHubhaniwa0x01/cve-2022-30023

Authenticated command injection exploit for Tenda HG9 routers. Provides interactive remote shell access via Python script for penetration testing and…

command-and-controlexploitationiot-security+3
84 years ago
CVE-2021-33044 preview

CVE-2021-33044

GitHubspy0x7/cve-2021-33044

Dahua IPC/VTH/VTO devices auth bypass exploit

authentication-authorizationexploitationiot-security+2
44 years ago
Previous1234567Next