Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
OTRS-4.0.1-6.0.1-Remote-Command-Execution preview

OTRS-4.0.1-6.0.1-Remote-Command-Execution

GitHubsmarttfoxx/otrs-4.0.1-6.0.1-remote-command-execution

CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an…

exploitationpenetration-testingremote-access-tool+2
1 year ago
CVE-2024-10605 preview

CVE-2024-10605

GitHubbevennyamande/cve-2024-10605
exploitationpenetration-testingvulnerability-analysis+2
1 year ago
agent_tesla_panel_rce preview

agent_tesla_panel_rce

GitHubmekhalleh/agent_tesla_panel_rce

This is Metasploit module who exploit the command injection vulnerability in control center of the agent Tesla.

exploitationpenetration-testingweb-application-exploitation
16 years ago
Vulnerable-Web-Application preview

Vulnerable-Web-Application

GitHubowasp/vulnerable-web-application

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

educationpenetration-testingweb-application-exploitation
4227 years ago
CredNinja preview

CredNinja

GitHubraikia/credninja

A multithreaded tool designed to identify if credentials are valid, invalid, or local admin valid credentials within a network at-scale via SMB, plus…

information-gatheringlateral-movementpenetration-testing
4484 years ago
SnaffPoint preview

SnaffPoint

GitHubnheiniger/snaffpoint

A tool for pointesters to find candies in SharePoint

cloud-securityinformation-gatheringpenetration-testing+3
2893 years ago
witchcraft preview

witchcraft

GitHubcosmic-zip/witchcraft

WITCHCRAFT is a cyberdeck toolkit built for runners who dive deep into the mesh. It’s your all-in-one rig for data-ghosting, ICE-breaking, and…

bluetooth-securityforensicsnetwork-mapping+8
521 year ago
So You Want To Build A Nethunter Kernel preview

So You Want To Build A Nethunter Kernel

GitLabakabulous/so_you_want_to_build_a_nethunter_kernel

Step-by-step guide to building custom Kali NetHunter kernels for Android: source retrieval, toolchain selection, cross-compilation, and flashing.

android-securityeducationembedded-systems-security+3
31 month ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubshadowbrokers-exploitleak/cve-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker…

exploitationpenetration-testingremote-access-tool+2
27 years ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubbarry-mccockiner/cve-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker…

exploitationinformation-gatheringpenetration-testing+3
17 years ago
ntlm_theft preview

ntlm_theft

GitHubgreenwolf/ntlm_theft

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

information-gatheringpassword-attackspenetration-testing+2
1.5k11 months ago
React2Shell preview

React2Shell

GitHubmuhammaduwais/react2shell

A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications.

educationinformation-gatheringpenetration-testing+2
26 months ago
ghosthound preview

ghosthound

GitHubjvbotelho/ghosthound

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

exploitationinformation-gatheringlateral-movement+5
4313 days ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubmmakingdom/cve-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

educationexploitationpenetration-testing+2
19 months ago
CVE-2020-8559 preview

CVE-2020-8559

GitHubtdwyer/cve-2020-8559

This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

cloud-securitycontainer-securityexploitation+5
546 years ago
CVE-2023-38545 preview

CVE-2023-38545

GitHubd0rb/cve-2023-38545

This script is designed to exploit a heap buffer overflow vulnerability in a socks5 proxy server.

exploitationpayload-developmentpenetration-testing+3
212 years ago
CVE-2025-63353 preview

CVE-2025-63353

GitHub0xa1m/cve-2025-63353

This is a Proof-Of-Concept of CVE-2025-63353

educationexploitationpassword-attacks+4
48 months ago
CVE-2024-27130 preview

CVE-2024-27130

GitHubd0rb/cve-2024-27130

This Python script is designed as a proof-of-concept (PoC) for the CVE-2024-27130 vulnerability in QNAP QTS

exploitationpayload-generationpenetration-testing+3
22 years ago
Previous12Next