Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
22 days ago
git-dump preview

git-dump

GitHubjenderal92/git-dump

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and…

information-gatheringmisconfigurationpenetration-testing+3
13 months ago
dns-zone-audit preview

dns-zone-audit

GitHubsleepthegod/dns-zone-audit

This Bash script checks domains for DNS zone transfer misconfigurations (CVE-1999-0532). It queries name servers and attempts AXFR requests; if…

dns-analysisinformation-gatheringmisconfiguration+3
15 months ago
CVE-2025-2304 preview

CVE-2025-2304

GitHubcsuribird/cve-2025-2304

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

authentication-authorizationeducationexploitation+5
56 months ago
PoC-Apache-CVE-2021-41773-Infrastructure-LAB preview

PoC-Apache-CVE-2021-41773-Infrastructure-LAB

GitHubisabbii/poc-apache-cve-2021-41773-infrastructure-lab

Docker-based lab for Apache CVE-2021-41773 path traversal and RCE exploitation with Python exploit script, demonstrating vulnerability analysis and…

container-securityeducationexploitation+4
6 months ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
7 months ago
CVE-2025-55182-scanner preview

CVE-2025-55182-scanner

GitHubyaupunal/cve-2025-55182-scanner

CVE-2025-55182-scanner with 2 different method

defensive-toolsids-ips-evasionmisconfiguration+3
8 months ago
CVE-2025-61882-CVE-2025-61884 preview

CVE-2025-61882-CVE-2025-61884

GitHubrxerium/cve-2025-61882-cve-2025-61884

Detection for CVE-2025-61882 & CVE-2025-61884

misconfigurationpenetration-testingvulnerability-scanners+2
3510 months ago
ingress-nightmare preview

ingress-nightmare

GitHubtuladhar/ingress-nightmare

IngressNightmare (CVE-2025-1974)

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
1 year ago
CVE-2025-1974 preview

CVE-2025-1974

GitHub0xbingo/cve-2025-1974

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

cloud-securitycontainer-securityeducation+4
1 year ago
Disable-IPv6-CVE-2024-38063-Fix preview

Disable-IPv6-CVE-2024-38063-Fix

GitHubalmogopp/disable-ipv6-cve-2024-38063-fix

A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the…

defensive-toolsgeneral-purpose-utilitiesmisconfiguration+2
2 years ago
CVE-2024-3094-Vulnerability-Checker-Fixer preview

CVE-2024-3094-Vulnerability-Checker-Fixer

GitHubgensecaihq/cve-2024-3094-vulnerability-checker-fixer

Shell script and Ansible playbook to detect and remediate CVE-2024-3094 in xz-utils by checking package versions, upgrading or downgrading to a…

cloud-securitydevsecopsmisconfiguration+3
262 years ago
cve-2024-3094-detect preview

cve-2024-3094-detect

GitHubgalacticquest/cve-2024-3094-detect

Bash script to detect vulnerable XZ Utils versions (CVE-2024-3094) and downgrade to a safe release, supporting multiple Linux distributions and…

general-purpose-utilitiesmisconfigurationscripting-automation+2
12 years ago
CVE-2024-3094-checker preview

CVE-2024-3094-checker

GitHubhazemkya/cve-2024-3094-checker

Bash script to detect and remediate CVE-2024-3094, a critical supply-chain vulnerability in the XZ Utils library, with automatic safe version…

misconfigurationscripting-automationsupply-chain-security+2
2 years ago
Log4j-CVE-2021-44228-Remediation preview

Log4j-CVE-2021-44228-Remediation

GitHubdigital-dev/log4j-cve-2021-44228-remediation

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple…

cloud-securitydefensive-toolsincident-response+3
2 years ago
jdwp-shellifier preview

jdwp-shellifier

GitHubioactive/jdwp-shellifier

Exploitation script for exposed Java Debug Wire Protocol (JDWP) services, enabling pentesters to inject Java code and execute arbitrary OS commands…

debuggersexploitationmisconfiguration+1
9172 years ago
mitigate-folina preview

mitigate-folina

GitHubderco0n/mitigate-folina

Mitigates the "Folina"-ZeroDay (CVE-2022-30190)

defensive-toolsincident-responsemisconfiguration+1
14 years ago
vCenter-Server-Workaround-Script-CVE-2021-44228 preview

vCenter-Server-Workaround-Script-CVE-2021-44228

GitHubfazmin/vcenter-server-workaround-script-cve-2021-44228

Script - Workaround instructions to address CVE-2021-44228 in vCenter Server

cloud-infrastructure-securityincident-responsemisconfiguration+3
24 years ago
Previous12Next