Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
kcmd preview

kcmd

Bitbucketaseemjakhar/kcmd

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

cryptographyexploitationhardware-iot-security+4
11 years ago
CVE-2023-22960 preview

CVE-2023-22960

GitHubt3l3machus/cve-2023-22960

This vulnerability allows an attacker to bypass the credentials brute-force prevention mechanism of the Embedded Web Server (interface) of more than…

exploitationpassword-attackspenetration-testing+1
913 years ago
CVE-2026-55579 preview

CVE-2026-55579

GitHubch4120n/cve-2026-55579

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

educationexploitationlabs-practice+6
11 month ago
CVE-2018-9995_dvr_credentials preview

CVE-2018-9995_dvr_credentials

GitHubezelf/cve-2018-9995_dvr_credentials

(CVE-2018-9995) Get DVR Credentials

exploitationiot-securitypassword-attacks+3
5577 years ago
Genzai preview

Genzai

GitHubumair9747/genzai

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

iot-securitypassword-attackspenetration-testing+3
2091 year ago
CVE-2023-43261 preview

CVE-2023-43261

GitHubwin3zz/cve-2023-43261

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

exploitationiot-securitymisconfiguration+3
572 years ago
CVE-2018-18852 preview

CVE-2018-18852

GitHubhook-s3c/cve-2018-18852

Authenticated remote code execution exploit for CERIO routers (DT300N, DT100G, AMR-3204, WMR-200N) using vendor default credentials. Python PoC…

embedded-systems-securityexploitationiot-security+4
457 years ago
zyxel-vmg8825-keygen preview

zyxel-vmg8825-keygen

GitHubboginw/zyxel-vmg8825-keygen

A key generator for Zyxel VMG8825-T50

embedded-systems-securityexploitationhardware-security+3
273 years ago
bugstropics preview

bugstropics

GitHubdozernz/bugstropics

Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk

cryptographyembedded-systems-securityexploitation+4
124 years ago
awind-research preview

awind-research

GitHubqkaiser/awind-research

This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…

embedded-systems-securityexploitationhardware-iot-security+5
135 years ago
CheckPWD preview

CheckPWD

GitHubal1ex/checkpwd

Check the default pwd of product via checklist.

curated-resourceshardware-iot-securityinformation-gathering+3
184 years ago
mySCADA-myPRO-7-Hardcoded-FTP-Username-and-Password preview

mySCADA-myPRO-7-Hardcoded-FTP-Username-and-Password

GitHubemreovunc/myscada-mypro-7-hardcoded-ftp-username-and-password

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

embedded-systems-securityexploitationhardware-iot-security+4
128 years ago
CVE-2017-14262 preview

CVE-2017-14262

GitHubzzz66686/cve-2017-14262

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

embedded-systems-securityexploitationiot-security+3
68 years ago
cve-2017-7921-golang preview

cve-2017-7921-golang

GitHubmisakamikato/cve-2017-7921-golang

Hikvision IP camera access bypass exploit, developed by golang.

exploitationiot-securitypassword-attacks+3
125 months ago
CVE-2025-63353 preview

CVE-2025-63353

GitHubhanianis/cve-2025-63353

A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted…

exploitationhardware-securityiot-security+3
99 months ago
CVE-2026-23005-Matter-Commissioning-Code-Brute-Force-Without-Rate-Limit preview

CVE-2026-23005-Matter-Commissioning-Code-Brute-Force-Without-Rate-Limit

GitHubgeorge0papasotiriou/cve-2026-23005-matter-commissioning-code-brute-force-without-rate-limit

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…

embedded-systems-securityexploitationiot-security+2
24 days ago
CVE-2018-9995_Batch_scanning_exp preview

CVE-2018-9995_Batch_scanning_exp

GitHubzzh217/cve-2018-9995_batch_scanning_exp

CVE-2018-9995_Batch_scanning_exp

exploitationiot-securitypassword-attacks+3
48 years ago
routeros-CVE-2018-14847-bytheway preview

routeros-CVE-2018-14847-bytheway

GitHubbabyshen/routeros-cve-2018-14847-bytheway

By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:

embedded-systems-securityexploitationiot-security+3
43 years ago
Previous123Next