Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
22 days ago
CVE-2017-9798 preview
Archived

CVE-2017-9798

GitHubnitrado/cve-2017-9798

Checks a shared hosting environment for CVE-2017-9798

misconfigurationscripting-automationvulnerability-analysis+1
38 years ago
jdwp-shellifier preview

jdwp-shellifier

GitHubioactive/jdwp-shellifier

Exploitation script for exposed Java Debug Wire Protocol (JDWP) services, enabling pentesters to inject Java code and execute arbitrary OS commands…

debuggersexploitationmisconfiguration+1
9172 years ago
PoC-Apache-CVE-2021-41773-Infrastructure-LAB preview

PoC-Apache-CVE-2021-41773-Infrastructure-LAB

GitHubisabbii/poc-apache-cve-2021-41773-infrastructure-lab

Docker-based lab for Apache CVE-2021-41773 path traversal and RCE exploitation with Python exploit script, demonstrating vulnerability analysis and…

container-securityeducationexploitation+4
6 months ago
CVE-2025-1974 preview

CVE-2025-1974

GitHub0xbingo/cve-2025-1974

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

cloud-securitycontainer-securityeducation+4
1 year ago
linuxprivchecker preview

linuxprivchecker

GitHubsleventyeleven/linuxprivchecker

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

ctfeducationinformation-gathering+3
1.8k5 years ago
CVE-2025-61882-CVE-2025-61884 preview

CVE-2025-61882-CVE-2025-61884

GitHubrxerium/cve-2025-61882-cve-2025-61884

Detection for CVE-2025-61882 & CVE-2025-61884

misconfigurationpenetration-testingvulnerability-scanners+2
3510 months ago
CVE-2024-3094-Vulnerability-Checker-Fixer preview

CVE-2024-3094-Vulnerability-Checker-Fixer

GitHubgensecaihq/cve-2024-3094-vulnerability-checker-fixer

Shell script and Ansible playbook to detect and remediate CVE-2024-3094 in xz-utils by checking package versions, upgrading or downgrading to a…

cloud-securitydevsecopsmisconfiguration+3
262 years ago
CVE-2025-2304 preview

CVE-2025-2304

GitHubcsuribird/cve-2025-2304

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

authentication-authorizationeducationexploitation+5
56 months ago
dns-zone-audit preview

dns-zone-audit

GitHubsleepthegod/dns-zone-audit

This Bash script checks domains for DNS zone transfer misconfigurations (CVE-1999-0532). It queries name servers and attempts AXFR requests; if…

dns-analysisinformation-gatheringmisconfiguration+3
15 months ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubaxisops/cve-2021-44228

log4j mitigation work

configuration-auditingdevsecopsmisconfiguration+3
4 years ago
CVE-2024-3094-checker preview

CVE-2024-3094-checker

GitHubhazemkya/cve-2024-3094-checker

Bash script to detect and remediate CVE-2024-3094, a critical supply-chain vulnerability in the XZ Utils library, with automatic safe version…

misconfigurationscripting-automationsupply-chain-security+2
2 years ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
7 months ago
fix-CVE-2020-15228 preview

fix-CVE-2020-15228

GitHubguettli/fix-cve-2020-15228

Python script that automatically patches GitHub Actions workflow files to replace deprecated and insecure ::set-env and ::add-path commands with the…

devsecopsgeneral-purpose-utilitiesmisconfiguration+1
75 years ago
git-dump preview

git-dump

GitHubjenderal92/git-dump

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and…

information-gatheringmisconfigurationpenetration-testing+3
13 months ago
cve-2024-3094-detect preview

cve-2024-3094-detect

GitHubgalacticquest/cve-2024-3094-detect

Bash script to detect vulnerable XZ Utils versions (CVE-2024-3094) and downgrade to a safe release, supporting multiple Linux distributions and…

general-purpose-utilitiesmisconfigurationscripting-automation+2
12 years ago
CVE-2021-36934 preview

CVE-2021-36934

GitHubtda90/cve-2021-36934

CVE-2021-36934 PowerShell Fix

configuration-auditingmisconfigurationprivilege-escalation+2
15 years ago
mitigate-folina preview

mitigate-folina

GitHubderco0n/mitigate-folina

Mitigates the "Folina"-ZeroDay (CVE-2022-30190)

defensive-toolsincident-responsemisconfiguration+1
14 years ago
Previous12Next