Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
Portspoof preview

Portspoof

GitHubdrk1wi/portspoof

Emulates open ports and service signatures across all 65535 TCP ports to slow reconnaissance, confuse scanners, and waste attacker resources with…

defensive-toolsids-ips-evasionnetwork-security+3
2.4k
6 days ago
CVE-2026-6060-QUIC-Handshake-Amplification-via-Address-Validation-Bypass preview

CVE-2026-6060-QUIC-Handshake-Amplification-via-Address-Validation-Bypass

GitHubgeorge0papasotiriou/cve-2026-6060-quic-handshake-amplification-via-address-validation-bypass
adversarial-attackeducationexploitation+2
18 days ago
CVE-2026-54121 preview

CVE-2026-54121

GitHubchpratik/cve-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

educationincident-responselog-analysis+4
124 days ago
TLS-Attacker preview

TLS-Attacker

GitHubtls-attacker/tls-attacker

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

cryptographyfuzzingnetwork-security+2
87927 days ago
CVE-2026-32202 preview

CVE-2026-32202

GitHubasdrf5gh67j8ki/cve-2026-32202
authenticationexploitationlateral-movement+2
1 month ago
cve-2026-8697 preview

cve-2026-8697

GitHubitzmetanjim/cve-2026-8697

writeup

educationexploitationhardware-iot-security+7
12 months ago
BIND-9-Cache-Poisoning-PoC---CVE-2025-40778 preview

BIND-9-Cache-Poisoning-PoC---CVE-2025-40778

GitHubsirbuvladste/bind-9-cache-poisoning-poc---cve-2025-40778

Proof of Concept for CVE-2025-40778: BIND 9 DNS Cache Poisoning via unsolicited Additional Section records.

dns-analysiseducationexploitation+3
7 months ago
Open5GS-CVE-2025-41067-CVE-2025-41068-PoC preview

Open5GS-CVE-2025-41067-CVE-2025-41068-PoC

GitHubxvk1t1/open5gs-cve-2025-41067-cve-2025-41068-poc

This repository contains the Proof-of-Concept (PoC) exploit scripts for two vulnerabilities, CVE-2025-41067 and CVE-2025-41068. These vulnerabilities…

educationexploitationnetwork-security+2
7 months ago
CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC preview

CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC

GitHubomer-efe-curkus/cve-2025-32433-erlang-otp-ssh-rce-poc

The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

command-and-controlexploitationnetwork-security+3
161 year ago
CVE-2024-27686 preview

CVE-2024-27686

GitHubthemehackers/cve-2024-27686

This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to…

exploitationinformation-gatheringnetwork-security+1
31 year ago
APOLOGEE preview
Archived

APOLOGEE

GitHubrosesecurity/apologee

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

authenticationexploitationexploit-frameworks+8
501 year ago
CVE-2024-51179 preview

CVE-2024-51179

GitHublakshmirnr/cve-2024-51179
exploitationnetwork-securitypacket-sniffing-analysis+2
41 year ago
CVE-2023-25136 preview

CVE-2023-25136

GitHubmrmtwoj/cve-2023-25136

This vulnerability is of the "double-free" type, which occurs during the processing of key exchange (KEX) algorithms in OpenSSH. A "double-free"…

exploitationinformation-gatheringnetwork-security+3
11 year ago
AIP preview

AIP

GitHubstratosphereips/aip

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

information-gatheringintrusion-detectioniot-security+3
321 year ago
cve-2022-22954 preview

cve-2022-22954

GitHubcorelight/cve-2022-22954
exploitationincident-responseintrusion-detection+3
11 year ago
Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198- preview

Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198-

GitHubahmedmansour93/event-id-193-rule-name-soc231-cisco-ios-xe-web-ui-zeroday-cve-2023-20198-

🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker…

educationexploitationincident-response+3
1 year ago
CVE-2024-42657 preview

CVE-2024-42657

GitHubbaroi-ai/cve-2024-42657

CVE-2024-42657 An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of…

exploitationinformation-gatheringnetwork-security+3
2 years ago
CVE-2024-6387_Check preview

CVE-2024-6387_Check

GitHubsardine-web/cve-2024-6387_check

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some…

exploitationnetwork-securitypenetration-testing+2
12 years ago
Previous12Next