Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
110 results
Freak-Scanner preview

Freak-Scanner

GitHubscottjpack/freak-scanner

Multithreaded FREAK scanner, used to detect SSL EXP Ciphers, vulnerable to CVE-2015-0204

information-gatheringnetwork-securitypenetration-testing+2
4
11 years ago
CVE-2019-5418-Scanner preview

CVE-2019-5418-Scanner

GitHubbrompwnie/cve-2019-5418-scanner

A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418

exploitationinformation-gatheringpenetration-testing+3
367 years ago
Multi-threaded-mass-exploiter-CVE-2018-13379-POC preview

Multi-threaded-mass-exploiter-CVE-2018-13379-POC

GitHubinstructor-admin/multi-threaded-mass-exploiter-cve-2018-13379-poc

CVE-2018-13379 mass exploiter for Fortinet FortiOS SSL VPN. Extracts credentials instantly, saves to CSV + PostgreSQL. Multi-threaded, no bullshit…

exploitationinformation-gatheringpassword-attacks+4
13 months ago
CVE-2011-3192 preview

CVE-2011-3192

GitHubfuturezayka/cve-2011-3192

Python exploit for CVE-2011-3192 (Apache Range Header Denial of Service). Executes multi-threaded HTTP requests to exhaust server resources. Requires…

exploitationpenetration-testingred-teaming+2
2 years ago
CredNinja preview

CredNinja

GitHubraikia/credninja

A multithreaded tool designed to identify if credentials are valid, invalid, or local admin valid credentials within a network at-scale via SMB, plus…

information-gatheringlateral-movementpenetration-testing
4497 years ago
SQLbit preview

SQLbit

GitHubsunlight-rim/sqlbit

A script for automatize boolean-based blind SQL injections (MVP).

penetration-testingvulnerability-analysisweb-application-exploitation
544 years ago
SharpShares preview

SharpShares

GitHubmitchmoser/sharpshares

Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain

information-gatheringnetwork-securitypenetration-testing+1
38511 months ago
CVE-2023-48084-Revised preview

CVE-2023-48084-Revised

GitHubmetthk/cve-2023-48084-revised

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

database-securityexploitationinformation-gathering+4
23 days ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubyassdev221608/cve-2024-6387

Python exploit for CVE-2024-6387 (OpenSSH signal handler race condition) targeting glibc-based 32-bit Linux systems, with multi-threaded concurrency…

binary-exploitationexploitationpayload-development+3
1 year ago
Magneto-PolyShell preview

Magneto-PolyShell

GitHubjenderal92/magneto-polyshell

Magento 2 Unauthenticated RCE Exploit – Uploads a PHP webshell via GraphQL product lookup + guest cart custom options. Multi‑threaded, auto‑detects…

exploitationpayload-generationpenetration-testing+3
3 months ago
Subhunter preview

Subhunter

GitHubumutcamliyurt/subhunter

Fast subdomain takeover scanner that checks DNS CNAME records against known fingerprints to detect vulnerable subdomains. Built in Go with…

penetration-testingsubdomain-enumerationvulnerability-scanners+1
883 months ago
cve-2018-15473 preview

cve-2018-15473

GitHubwtbacon/cve-2018-15473

Remote OpenSSH username enumeration exploit for CVE-2018-15473, featuring malformed packet and timing attack scripts with multi-threaded scanning.

exploitationinformation-gatheringnetwork-security+3
5 months ago
citrixmash_scanner preview

citrixmash_scanner

GitHubawesome-security/citrixmash_scanner

A fast multi threaded scanner for Citrix ADC (NetScaler) CVE-2019-19781 - Citrixmash

exploitationids-ips-evasionpenetration-testing+3
6 years ago
CVE-2026-6433 preview

CVE-2026-6433

GitHubmurrez/cve-2026-6433

PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk…

educationexploitationpayload-development+4
22 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubdennisec/cve-2026-41940

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

authentication-authorizationexploitationpenetration-testing+3
4 months ago
CVE-2026-6271 preview

CVE-2026-6271

GitHubxxconi/cve-2026-6271

Automated scanner for CVE-2026-6271, a critical unauthenticated arbitrary file upload leading to RCE in the WordPress Career Section plugin. Supports…

educationexploitationpayload-generation+4
3 months ago
buffalo preview

buffalo

GitHubd0n601/buffalo

A python3 multithreaded SSH dictionary attack tool

authenticationpassword-attackspenetration-testing+1
15 years ago
Reconnoitre preview

Reconnoitre

GitHubcodingo/reconnoitre

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+4
2.2k6 years ago
Previous1234567Next