Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
pwn-hisilicon-dvr preview

pwn-hisilicon-dvr

GitHubtothi/pwn-hisilicon-dvr

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

binary-analysisembedded-systems-securityexploitation+8
385
3 years ago
cve-2024-43451-ntlm_hash_disclosure_reproduction preview

cve-2024-43451-ntlm_hash_disclosure_reproduction

GitHubrazureink/cve-2024-43451-ntlm_hash_disclosure_reproduction

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

educationexploitationinformation-gathering+5
2 months ago
CVE-2018-12633-TPLink-Auth-Bypass preview

CVE-2018-12633-TPLink-Auth-Bypass

GitHubwiliam227user/cve-2018-12633-tplink-auth-bypass

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).

data-exfiltrationeducationembedded-systems-security+8
9 months ago
wp2shell preview

wp2shell

GitHubekomssavior/wp2shell

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

exploitationinformation-gatheringpassword-cracking+5
92 months ago
https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubfathanahhidayati/https-github.com-xaitax-cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

email-securityexploitationpassword-cracking+4
2 years ago
Metasploitable2-VAPT-Report preview

Metasploitable2-VAPT-Report

GitHubklynezyro/metasploitable2-vapt-report

Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.

educationexploitationlabs-practice+8
9 months ago
CVE-2025-24071-PoC preview

CVE-2025-24071-PoC

GitHublooky243/cve-2025-24071-poc

CVE-2025-24071 Proof Of Concept

data-exfiltrationexploitationinformation-gathering+3
31 year ago
CVE-2026-33829-Writeup preview

CVE-2026-33829-Writeup

GitHubrahultb-sec/cve-2026-33829-writeup

Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)

educationexploitationinformation-gathering+3
4 months ago
CVE-2025-65900 preview

CVE-2025-65900

GitHubnoxurge/cve-2025-65900

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

authenticationexploitationmisconfiguration+3
10 months ago
CVE-2025-32044 preview

CVE-2025-32044

GitHubshinthink/cve-2025-32044

Moodle 4.5.0-4.5.2 Unauthenticated REST API User Data Exposure via Stack Trace Args Leak | CVSS 7.5

educationexploitationinformation-gathering+4
2 months ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubrubbxalc/cve-2025-24071

Generates a ZIP file exploiting CVE-2025-24071 to capture netNTLMv2 credentials from Windows Explorer via malicious .library-ms files, intended for…

educationexploitationinformation-gathering+3
11 year ago
CVE-2024-21413-POC preview

CVE-2024-21413-POC

GitHubr00tb1t/cve-2024-21413-poc

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC

educationemail-securityexploitation+3
172 years ago
htb-facts preview

htb-facts

GitHubmattiapertusati/htb-facts

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

cloud-securityctfeducation+7
5 months ago
CVE-2021-43798 preview

CVE-2021-43798

GitHubokymi-x/cve-2021-43798

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

encryption-decryption-toolsexploitationinformation-gathering+3
14 months ago
CVE-2025-24054-PoC preview

CVE-2025-24054-PoC

GitHubsimantchaudhari/cve-2025-24054-poc

Proof-of-concept exploit for CVE-2025-24054, a Windows Library (.library-ms) NTLM hash disclosure vulnerability. Generates a malicious .library-ms…

educationexploitationinformation-gathering+3
5 months ago
AutoPwn-Titanic.htb preview

AutoPwn-Titanic.htb

GitHubmaikneysm/autopwn-titanic.htb

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

ctfexploitationinformation-gathering+5
1 year ago
CVE-2025-24071_PoC preview

CVE-2025-24071_PoC

GitHubmarcejr117/cve-2025-24071_poc

A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes

exploitationinformation-gatheringpassword-cracking+2
241 year ago
hook preview

hook

GitHubjbaines-r7/hook

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

exploitationpassword-crackingpenetration-testing+3
104 years ago
Previous123Next