Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
numa preview

numa

GitHubrazvandimescu/numa

Portable DNS resolver in Rust — .numa local domains, ad blocking, developer overrides

dns-analysisdns-fuzzingdns-subdomain-enumeration+3
1.4k
1 day ago
sshuttle preview

sshuttle

GitHubsshuttle/sshuttle

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

command-and-controldata-exfiltrationdns-analysis+6
13.5k2 days ago
CVE-2020-5148 preview

CVE-2020-5148

GitHubl0lsec/cve-2020-5148

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

authenticationexploitationinformation-gathering+6
1 month ago
WantasticCore preview

WantasticCore

GitHubwantasticapp/wantasticcore

AIO Cloud Managment Server

ai-securityauthenticationcloud-security+6
141 month ago
web preview

web

GitHubpi-hole/web

Pi-hole Dashboard for stats and more

dns-analysislog-analysisnetwork-security+1
2.6k1 month ago
zttp preview

zttp

GitLabnihal799/zttp

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

authentication-authorizationcloud-infrastructure-securitydefensive-tools+3
2 months ago
cve-2026-8697 preview

cve-2026-8697

GitHubitzmetanjim/cve-2026-8697

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

educationexploitationhardware-iot-security+7
13 months ago
cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure preview

cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

GitHubminanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

exploitationinformation-gatheringiot-security+3
13 months ago
CVE-2026-30081 preview

CVE-2026-30081

GitHubrakeshelamaran98/cve-2026-30081

Documentation of CVE-2026-30081, a high-severity cleartext transmission vulnerability in Quantum Networks QN-I-470 router firmware 6.1.1.B1, allowing…

exploitationinformation-gatheringnetwork-security+2
5 months ago
SharpSCCM preview

SharpSCCM

GitHubmayyhem/sharpsccm

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

authenticationlateral-movementnetwork-security+3
7025 months ago
CVE-2026-20131-POC preview

CVE-2026-20131-POC

GitHubp3nt3st3r-star/cve-2026-20131-poc

Proof-of-concept exploit for CVE-2026-20131, a pre-authentication RCE in Cisco Catalyst SD-WAN Controller and Manager, enabling admin access and…

exploitationnetwork-securitypenetration-testing+3
5 months ago
CYBERDUDEBIVASH-5G-Core-Key-Rotation-Ghost-Admin-Auditor preview

CYBERDUDEBIVASH-5G-Core-Key-Rotation-Ghost-Admin-Auditor

GitHubcyberdudebivash/cyberdudebivash-5g-core-key-rotation-ghost-admin-auditor

Production-grade tool for detecting & remediating CVE-2026-0622 (Ghost Admin privilege escalation & master key exposure in 5G core software).

anomaly-detectioncloud-securityconfiguration-auditing+3
7 months ago
Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198- preview

Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198-

GitHubahmedmansour93/event-id-193-rule-name-soc231-cisco-ios-xe-web-ui-zeroday-cve-2023-20198-

🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker…

educationexploitationincident-response+3
1 year ago
serviceDetector preview

serviceDetector

GitHubtothi/servicedetector

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

information-gatheringnetwork-securitypenetration-testing+2
2412 years ago
Fortinet-CVE-2022-40684 preview

Fortinet-CVE-2022-40684

GitHubjsongmax/fortinet-cve-2022-40684

Go-based exploit tool for CVE-2022-40684 (Fortinet authentication bypass). Automates SSH key injection for authorized penetration testing and…

exploitationnetwork-securitypenetration-testing+3
23 years ago
toxy preview
Archived

toxy

GitHubh2non/toxy

Hackable HTTP proxy for resiliency testing and simulated network conditions

api-security-testingchaos-engineeringnetwork-security+3
2.7k4 years ago
cve-2019-1040-scanner preview

cve-2019-1040-scanner

GitHubfox-it/cve-2019-1040-scanner

SMB vulnerability scanner that detects CVE-2019-1040 by sending invalid NTLM authentication packets, enabling MIC Remove relay attacks for domain…

authenticationexploitationnetwork-security+2
3006 years ago