Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
267 results
parameth preview
Archived

parameth

GitHubmak-/parameth

This tool can be used to brute discover GET and POST parameters

information-gatheringpenetration-testingreconnaissance+3
1.4k
7 years ago
Optiva-Framework preview

Optiva-Framework

GitHubjoker25000/optiva-framework

Optiva-Framework 🔎 Web Application Scanner🕵️

encryption-decryption-toolshash-analysisinformation-gathering+6
3148 years ago
exploit_cve-2021-29447 preview

exploit_cve-2021-29447

GitHubmega8bit/exploit_cve-2021-29447

Go-based exploit for CVE-2021-29447 targeting WordPress 5.6.2 with PHP 8. Generates a malicious .wav payload to retrieve arbitrary files from the…

educationexploitationpenetration-testing+2
73 years ago
SocialPwned preview
Archived

SocialPwned

GitHubmrtuxx/socialpwned

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

email-harvestinginformation-gatheringosint+5
1.3k1 year ago
ZeroLogon-to-Shell preview

ZeroLogon-to-Shell

GitHubc3rrberu5/zerologon-to-shell

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

exploitationpassword-crackingpenetration-testing+3
3 years ago
wordlistgen preview

wordlistgen

GitHubameenmaali/wordlistgen

Quickly generate context-specific wordlists for content discovery from lists of URLs or paths

information-gatheringpenetration-testingreconnaissance+1
2416 years ago
ccat preview

ccat

GitHubrhinosecuritylabs/ccat

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

cloud-securitycontainer-securityexploitation+1
6536 years ago
DirDar preview

DirDar

GitHubm4dm0e/dirdar

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

information-gatheringpenetration-testingvulnerability-scanners+1
4532 years ago
poc-cve-2026-32255 preview

poc-cve-2026-32255

GitHubkoadt/poc-cve-2026-32255

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

educationexploitationpenetration-testing+3
26 months ago
dark-fantasy-hack-tool preview

dark-fantasy-hack-tool

GitHubritvikb99/dark-fantasy-hack-tool

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

educationemail-harvestinginformation-gathering+5
4824 years ago
watchTowr-vs-Progress-ShareFile-CVE-2026-2699 preview

watchTowr-vs-Progress-ShareFile-CVE-2026-2699

GitHubwatchtowrlabs/watchtowr-vs-progress-sharefile-cve-2026-2699

Detection artifact for CVE-2026-2699 Progress ShareFile authentication bypass. Sends GET to /ConfigService/Admin.aspx to check vulnerability.

authenticationpenetration-testingvulnerability-analysis+1
36 months ago
ipv4Bypass preview

ipv4Bypass

GitHubmilo2012/ipv4bypass

Using IPv6 to Bypass Security

ids-ips-evasionnetwork-securitypenetration-testing+2
931 year ago
CVE-2026-87902 preview

CVE-2026-87902

GitHublutfifakee-project/cve-2026-87902

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

exploitationpenetration-testingremote-access-tool+3
13 days ago
Inspector preview

Inspector

GitHubgraniet/inspector

The Inspector tool is a privilege escalation helper (PoC), easy to deployed on web server, this tool can list process running with root, check kernel…

information-gatheringpenetration-testingprivilege-escalation+1
1208 years ago
Max preview

Max

GitHubknavesec/max

Suite of tools for BloodHound that enables domain password auditing, privilege path analysis, edge manipulation, and custom Cypher queries to…

information-gatheringpenetration-testing
5331 year ago
CVE-2021-31761 preview

CVE-2021-31761

GitHubmesh3l911/cve-2021-31761

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

exploitationpenetration-testingremote-access-tool+2
55 years ago
CVE-2024-12856 preview

CVE-2024-12856

GitHubnu113d/cve-2024-12856

An exploit for Four-Faith routers to get a reverse shell

exploitationpenetration-testingremote-access-tool+2
31 year ago
ntdsdotsqlite preview

ntdsdotsqlite

GitHubalmandin/ntdsdotsqlite

A small utility to translate NTDS.dit files to SQLite format.

digital-forensicsencryption-decryption-toolspassword-attacks+2
852 years ago
Previous12…15Next