Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
Memcrashed-DDoS-Exploit preview

Memcrashed-DDoS-Exploit

GitHub649/memcrashed-ddos-exploit

DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API

exploitationinformation-gatheringosint
1.4k6 years ago
DorkNet preview

DorkNet

GitHubnullarray/dorknet

Selenium powered Python script to automate searching for vulnerable web apps.

information-gatheringosintvulnerability-scanners+1
3486 years ago
dorkScanner preview

dorkScanner

GitHubmadhavmehndiratta/dorkscanner

A typical search engine dork scanner scrapes search engines with dorks that you provide in order to find vulnerable URLs.

information-gatheringosintvulnerability-scanners+1
2863 years ago
FireShodanMap preview

FireShodanMap

GitHubwarflop/fireshodanmap

FireShodanMap is a Realtime map that integrates Firebase, Google Maps and Shodan. A search is carried out using Shodan searching vulnerable devices…

information-gatheringosintreconnaissance+1
1258 years ago
dorkscout preview

dorkscout

GitHubr4ygm/dorkscout

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

crawlerinformation-gatheringosint+2
2435 years ago
CVE-2018-20555 preview

CVE-2018-20555

GitHubfs0c131y/cve-2018-20555

Exploit for CVE-2018-20555: automated discovery and takeover of Twitter accounts via leaked API keys in vulnerable Social Network Tabs WordPress…

crawlerexploitationinformation-gathering+3
717 years ago
cve-2024-6387_hassh preview

cve-2024-6387_hassh

GitHub0x4d31/cve-2024-6387_hassh

HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).

information-gatheringnetwork-securityosint+3
102 years ago
pwn-vbulletin preview

pwn-vbulletin

GitHubandripwn/pwn-vbulletin

Identify vulnerable (RCE) vBulletin 5.0.0 - 5.5.4 instances using Shodan (CVE-2019-16759)

exploitationinformation-gatheringosint+3
45 years ago
ShodanFortiOS preview

ShodanFortiOS

GitHubtechinsightspro/shodanfortios

Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)

exploitationinformation-gatheringnetwork-security+3
23 years ago
confusploit preview

confusploit

GitHubp4b3l1t0/confusploit

This is a python script that can be used with Shodan CLI to mass hunting Confluence Servers vulnerable to CVE-2022-26134

exploitationinformation-gatheringosint+3
27 months ago
SOC-L1-OSINT-Investigation-MikroTik-CVE-2018-1156 preview

SOC-L1-OSINT-Investigation-MikroTik-CVE-2018-1156

GitHubjonathaninfinity01/soc-l1-osint-investigation-mikrotik-cve-2018-1156

L1 SOC Analysis: OSINT detection and risk validation of publicly exposed MikroTik RouterOS vulnerable to RCE | Tools: Shodan, NIST NVD

educationincident-responseinformation-gathering+6
2 months ago
Shodan-CVE-2024-4577 preview

Shodan-CVE-2024-4577

GitHubd3ck4/shodan-cve-2024-4577

Proof-of-concept exploit for CVE-2024-4577 with Shodan integration for automated discovery of vulnerable targets on the internet.

exploitationinformation-gatheringosint+2
22 years ago
webcvescanner preview

webcvescanner

GitHubnmanzi/webcvescanner

Gather a list of Citrix appliances in a country / state pair, and check if they're vulnerable to CVE-2019-19781

information-gatheringosintreconnaissance+2
16 years ago
CVE-2017-5487 preview

CVE-2017-5487

GitHubdream434/cve-2017-5487

Exploit for CVE-2017-5487 to enumerate WordPress user accounts via the REST API, extracting sensitive information from vulnerable 4.7 installations.

information-gatheringosintreconnaissance+2
1 year ago
cve-2021-41773 preview

cve-2021-41773

GitHubmohwahyudi/cve-2021-41773

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

exploitationinformation-gatheringosint+3
4 years ago
InfoLeak-Scanner preview
Archived

InfoLeak-Scanner

GitHubsiwecos/infoleak-scanner

Web scanner that detects CMS versions, plugins, vulnerable JavaScript libraries, email addresses, and phone numbers on target websites, scoring…

email-harvestinginformation-gatheringosint+2
173 years ago
pagodo preview

pagodo

GitHubopsdisk/pagodo

pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching

information-gatheringosintreconnaissance+2
3.4k1 year ago
msmailprobe preview

msmailprobe

GitHubbusterb/msmailprobe

Enumerate valid users on Office 365 and Exchange via time-based and error-based techniques across multiple exposed services, including OWA,…

email-securityinformation-gatheringosint+2
2048 years ago
Previous12Next