Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
EvilAbigail preview

EvilAbigail

GitHubstrozfriedberg/evilabigail

Automated Linux evil maid attack

exploitationpassword-attackspayload-development+3
436
10 years ago
VBA-macro-experiments preview

VBA-macro-experiments

GitHubadepts-of-0xcc/vba-macro-experiments

Collection of VBA macro published in our twitter / blog

adversarial-attackpassword-attackspayload-development+2
1574 years ago
chalumeau preview

chalumeau

GitHubcyberstruggle/chalumeau

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.

command-and-controlpassword-attackspayload-development+3
1026 years ago
VeeamDumper-BOF preview

VeeamDumper-BOF

GitHubmwr-cybersec/veeamdumper-bof

A credential extraction BOF for Veeam Backup and Replication and Veeam One

password-attackspayload-developmentpenetration-testing+2
802 months ago
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below preview

CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37756-cwe-521-lead-to-malicious-plugin-upload-in-the-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

exploitationmisconfigurationpassword-attacks+3
12 years ago
CVE-2020-7378 preview

CVE-2020-7378

GitHubloganpkinfosec/cve-2020-7378

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

exploitationpassword-attackspayload-development+3
1 year ago
CVE-2025-60787 preview

CVE-2025-60787

GitHubagent-skywalker/cve-2025-60787

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

command-and-controlexploitationpassword-attacks+5
5 months ago
RomBuster preview

RomBuster

GitHubentysec/rombuster

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

exploitationinformation-gatheringiot-security+1
5602 years ago
lscript preview
Archived

lscript

GitHubarismelachroinos/lscript

The LAZY script will make your life easier, and of course faster.

exploit-frameworksinformation-gatheringpassword-attacks+7
4.3k5 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtrackflaw/cve-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

email-securityexploitationpassword-attacks+3
1323 years ago
cve-2023-23397 preview

cve-2023-23397

GitHubbronzebee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

email-securityexploitationpassword-attacks+3
143 years ago
SMB_CVE-2025-24071 preview

SMB_CVE-2025-24071

GitHubex-cal1bur/smb_cve-2025-24071

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

exploitationpassword-attackspayload-generation+3
41 year ago
Ghost-CMS-Exploit preview

Ghost-CMS-Exploit

GitHubgl1tch0x1/ghost-cms-exploit

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

exploitationpassword-attackspayload-generation+4
1 year ago
smbexec preview

smbexec

GitHubbrav0hax/smbexec

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

command-and-controlexploitationlateral-movement+6
26211 years ago
siemframework preview

siemframework

GitHubelevenpaths/siemframework

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

exploit-frameworksinformation-gatheringnetwork-mapping+7
426 years ago
shiguresh preview

shiguresh

GitHubredsplit/shiguresh

CVE-2004-1769 // Mass cPanel Reset password

exploitationpassword-attacksvulnerability-analysis+1
16 years ago
WPForce preview

WPForce

GitHubn00py/wpforce

Wordpress Attack Suite

password-attackspayload-generationpenetration-testing+2
9775 years ago
TomcatScanPro preview

TomcatScanPro

GitHublizhianyuguangming/tomcatscanpro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

exploitationpassword-attackspayload-generation+3
2962 months ago
Previous12Next