Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
95 results
CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction preview

CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction

GitHubdhananjayasj/cve-2024-1698-notificationx-wordpress-plugin-sql-injection-to-admin-credential-extraction

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

exploitationinformation-gatheringpassword-cracking+3
2 months ago
AirScout preview

AirScout

GitHubstiffies/airscout

A nice tool that automates network hash capturing and has a nice GUI. Read README.md for more information and NEVER use this without explicit…

information-gatheringnetwork-mappingpassword-cracking+5
411 months ago
CVE-2024-33901-ProofOfConcept preview

CVE-2024-33901-ProofOfConcept

GitHubgmikisilva/cve-2024-33901-proofofconcept

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

data-exfiltrationdigital-forensicsexploitation+3
21 year ago
HTB-Mailing-A-Complete-Walkthrough preview

HTB-Mailing-A-Complete-Walkthrough

GitHubthemursalin/htb-mailing-a-complete-walkthrough

If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on…

ctfeducationexploitation+8
4 months ago
Exploit_CVE-2021-24762 preview

Exploit_CVE-2021-24762

GitHubc4cnm/exploit_cve-2021-24762

This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.

exploitationpassword-crackingpenetration-testing+2
110 months ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubabdelrahman0sayed/cve-2025-24071

This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive…

exploitationinformation-gatheringpassword-cracking+4
18 months ago
ilk-toolkit preview

ilk-toolkit

GitLabilk-toolkit/ilk-toolkit

A ToolKit that automatically installs & configures all the Tools needed to turn your Daily Driver Linux Distro into a Pentesting Machine

information-gatheringnetwork-securitypassword-cracking+5
4 years ago
Password-Analysis preview

Password-Analysis

GitHubam0nt31r0/password-analysis

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…

password-attackspassword-crackingpenetration-testing+1
4 years ago
CVE-2025-44203 preview

CVE-2025-44203

GitHubivant7d3/cve-2025-44203

Exploit for CVE-2025-44203 targeting a race condition in HotelDruid 3.0.0/3.0.7 that leaks admin credentials and causes denial of service. Includes a…

exploitationinformation-gatheringpassword-cracking+2
1 month ago
kraker preview
Archived

kraker

GitHubzzzteph/kraker

Kraker is a distributed password brute-force system that focused on easy use.

hash-analysispassword-crackingpenetration-testing+2
821 year ago
Talon preview
Archived

Talon

GitHuboptiv/talon

A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.

authenticationpassword-attackspassword-cracking+2
4413 years ago
BruteSploit preview
Archived

BruteSploit

GitHubscreetsec/brutesploit

BruteSploit is a collection of method for automated Generate, Bruteforce and Manipulation wordlist with interactive shell. That can be used during a…

ctfpassword-attackspassword-cracking+3
7746 years ago
SocialPwned preview
Archived

SocialPwned

GitHubmrtuxx/socialpwned

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

email-harvestinginformation-gatheringosint+5
1.3k1 year ago
Mutator preview

Mutator

Bitbucketalone/mutator

Generate mutations over a wordlist

fuzzinggeneral-purpose-utilitiespassword-cracking
12 years ago
payloads preview

payloads

GitHubfoospidy/payloads

Git All the Payloads! A collection of web attack payloads.

ctfcurated-resourceseducation+6
4.0k3 years ago
linWinPwn preview

linWinPwn

GitHublefayjey/linwinpwn

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

exploitationinformation-gatheringpassword-cracking+3
2.2k12 days ago
BruteShark preview

BruteShark

GitHubodedshimon/bruteshark

Network Analysis Tool

dns-analysisforensicshash-analysis+4
3.4k3 years ago
airgorah preview

airgorah

GitHubmartin-olivier/airgorah

A WiFi security auditing software mainly based on aircrack-ng tools suite

information-gatheringpassword-crackingpenetration-testing+2
1.1k4 days ago
Previous123456Next