Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
56
21 days ago
VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS preview

VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS

GitHubmourafuseti/vulneravel-cve-2018-14847---credenciais-extraidas

VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON

exploitationiot-securitynetwork-security+3
14 months ago
Pwdb-Public preview

Pwdb-Public

GitHubignis-sec/pwdb-public

A collection of all the data i could extract from 1 billion leaked credentials from internet.

curated-resourcespassword-attackspassword-cracking
3.3k6 years ago
kcmd preview

kcmd

Bitbucketaseemjakhar/kcmd

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

cryptographyexploitationhardware-iot-security+4
11 years ago
Genzai preview

Genzai

GitHubumair9747/genzai

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

iot-securitypassword-attackspenetration-testing+3
2131 year ago
cve-2018-9995 preview

cve-2018-9995

GitHubdearpan/cve-2018-9995

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

exploitationiot-securitypassword-attacks+2
4 years ago
Digisol-DG--GR1321-s-Password-Storage-in-Plaintext--CVE-2024-4232 preview

Digisol-DG--GR1321-s-Password-Storage-in-Plaintext--CVE-2024-4232

GitHubredfox-security/digisol-dg--gr1321-s-password-storage-in-plaintext--cve-2024-4232

Proof-of-concept exploit for CVE-2024-4232 targeting plaintext password storage in Digisol DG-GR1321 routers. Demonstrates extraction of credentials…

exploitationiot-securitymisconfiguration+3
2 years ago
HIK-CVE-2021-36260-Exploit preview

HIK-CVE-2021-36260-Exploit

GitHubhaingn/hik-cve-2021-36260-exploit

Go-based brute-force exploit tool targeting Hikvision cameras vulnerable to CVE-2021-36260, with multi-threaded scanning and configurable…

exploitationiot-securitypassword-attacks+2
12 years ago
Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232 preview

Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232

GitHubredfox-security/digisol-dg-gr1321-s-password-storage-in-plaintext-cve-2024-4232

Proof-of-concept demonstrating plaintext password storage vulnerability in Digisol DG-GR1321 routers, enabling credential exposure and unauthorized…

hardware-securityiot-securitymisconfiguration+3
2 years ago
cve-2017-7921-golang preview

cve-2017-7921-golang

GitHubmisakamikato/cve-2017-7921-golang

Hikvision IP camera access bypass exploit, developed by golang.

exploitationiot-securitypassword-attacks+3
136 months ago
CVE-2025-63353 preview

CVE-2025-63353

GitHubhanianis/cve-2025-63353

A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted…

exploitationhardware-securityiot-security+3
1111 months ago
hikvision_brute preview

hikvision_brute

GitHubnanotrash/hikvision_brute

Brute Hikvision CAMS with CVE-2021-36260 Exploit

exploitationiot-securitypassword-attacks+3
33 years ago
RTSPbrute preview

RTSPbrute

GitLabcamshift/rtspbrute

Simple rtsp-stream bruteforce

fuzzingiot-securitynetwork-security+2
28 years ago
CVE-2025-65427 preview

CVE-2025-65427

GitHubkirubel-cve/cve-2025-65427

Proof-of-concept exploit for CVE-2025-65427: missing rate limiting on Dbit N300 T1 Pro router login API enabling brute-force attacks and…

authenticationiot-securitypassword-attacks+3
9 months ago
CVE-2018-9995_dvr_credentials preview

CVE-2018-9995_dvr_credentials

GitHubezelf/cve-2018-9995_dvr_credentials

(CVE-2018-9995) Get DVR Credentials

exploitationiot-securitypassword-attacks+3
5598 years ago
CVE-2023-43261 preview

CVE-2023-43261

GitHubwin3zz/cve-2023-43261

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

exploitationiot-securitymisconfiguration+3
573 years ago
HTC preview

HTC

GitHubwmasday/htc

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

exploitationiot-securitypassword-attacks+3
33 years ago
Tool_Exploit_Password_Camera_CVE-2018-9995 preview

Tool_Exploit_Password_Camera_CVE-2018-9995

GitHublequockhanh2k/tool_exploit_password_camera_cve-2018-9995

Exploit tool for CVE-2018-9995 that extracts credentials from vulnerable DVR devices via Google dorking and direct IP access.

exploitationiot-securitypassword-attacks+3
4 years ago
Previous12Next