Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
118 results
dorkX preview

dorkX

GitHubethicalhackingplayground/dorkx

Pipe different tools with google dork Scanner

information-gatheringpenetration-testingreconnaissance+2
57
6 years ago
Xenotix-xBOT preview

Xenotix-xBOT

GitHubajinabraham/xenotix-xbot

Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C

command-and-controlexploitationinformation-gathering+4
288 years ago
flask_appengine_redirector preview

flask_appengine_redirector

GitHubkillswitch-gui/flask_appengine_redirector

Google App Engine Flask C2 redirector

cloud-securitycommand-and-controlpenetration-testing+2
89 years ago
joomla-cve-2018-6396 preview

joomla-cve-2018-6396

GitHubjavierolmedo/joomla-cve-2018-6396

Joomla - Component Google Map Landkarten <= 4.2.3 - SQL Injection

exploitationinformation-gatheringpenetration-testing+2
88 years ago
CVE-2023-32117 preview

CVE-2023-32117

GitHubrandomrobbiebf/cve-2023-32117

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

api-security-testingexploitationinformation-gathering+3
63 years ago
CVE-2022-3904 preview

CVE-2022-3904

GitHubrandomrobbiebf/cve-2022-3904

CVE-2022-3904 MonsterInsights < 8.9.1 - Stored Cross-Site Scripting via Google Analytics

exploitationpenetration-testingvulnerability-analysis+2
33 years ago
CVE-2026-7275-moodle preview

CVE-2026-7275-moodle

GitHubexdev994/cve-2026-7275-moodle

PoC & dokumentasi untuk CVE-2026-7275: Moodle Google Drive Repository (repository_googledocs) — Path Traversal / Arbitrary File Write yang dapat…

code-analysiseducationexploitation+3
1 month ago
CVE-2025-55182-Exploiter preview

CVE-2025-55182-Exploiter

GitHubalfazhossain/cve-2025-55182-exploiter

CVE-2025-55182-Exploiter Google Chrome Extension. nextjs vulnerability #nextjscve

exploitationinformation-gatheringpenetration-testing+3
48 months ago
CMS-Made-Simple-2.2.10---SQL-Injection preview

CMS-Made-Simple-2.2.10---SQL-Injection

GitHubjyothsna-git007/cms-made-simple-2.2.10---sql-injection

Google Dorks for detecting CMS Made Simple < 2.2.10 SQL Injection (CVE-2019-9053). Built for security auditing and patch verification.

exploitationinformation-gatheringpenetration-testing+3
3 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubyucaerin/cve-2026-8181

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

authenticationctfeducation+4
3 months ago
react2shell-rce-autobot preview

react2shell-rce-autobot

GitHubhndko/react2shell-rce-autobot

🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)

exploitationinformation-gatheringpenetration-testing+3
7 months ago
CVE-2024-2387 preview

CVE-2024-2387

GitHubrandomrobbiebf/cve-2024-2387

Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected…

exploitationpenetration-testingvulnerability-analysis+2
11 year ago
google_socks preview
Archived

google_socks

GitHublukebaggett/google_socks

A proof of concept demonstrating the use of Google Drive for command and control.

cloud-securitycommand-and-controldata-exfiltration+3
888 years ago
CVE-2025-10046 preview
Archived

CVE-2025-10046

GitHubbytereaper77/cve-2025-10046

exploit SQL injection ELEX WooCommerce Google Shopping

database-securityexploitationpenetration-testing+3
611 months ago
SocialPwned preview
Archived

SocialPwned

GitHubmrtuxx/socialpwned

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

email-harvestinginformation-gatheringosint+5
1.3k1 year ago
aura-inspector preview

aura-inspector

GitHubgoogle/aura-inspector
api-security-testingcloud-securityinformation-gathering+3
1045 months ago
CloudBrute preview

CloudBrute

GitHub0xsha/cloudbrute

Uncover a target's cloud infrastructure, files, and apps across major providers (AWS, Azure, GCP) using unauthenticated enumeration with concurrent…

cloud-securityinformation-gatheringosint+2
1.1k1 year ago
EyeWitness preview

EyeWitness

GitHubredsiege/eyewitness

Automated web screenshot tool for reconnaissance, capturing site visuals, server headers, and identifying default credentials. Supports multiple…

information-gatheringosintpenetration-testing+2
5.8k7 months ago
Previous1234567Next