Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
162 results
CVE-2024-24809-Proof-of-concept preview

CVE-2024-24809-Proof-of-concept

GitHubgh-ost00/cve-2024-24809-proof-of-concept

Critical Flaws in Traccar GPS System Expose Users to Remote Attacks

exploitationinformation-gatheringpenetration-testing+3
5
1 year ago
SocialFishMobile preview
Archived

SocialFishMobile

GitHubundeadsec/socialfishmobile

📱 🐟 An app to remote control SocialFish.

educationmobile-securityphishing+2
5853 years ago
evilqr preview

evilqr

GitHubkgretzky/evilqr

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

authenticationpenetration-testingphishing+4
4093 years ago
7-Zip-CVE-2025-0411-POC preview

7-Zip-CVE-2025-0411-POC

GitHubdhmosfunk/7-zip-cve-2025-0411-poc

This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.

exploitationmalware-analysisphishing+2
1551 year ago
CVE-2023-41425 preview

CVE-2023-41425

GitHubprodigiousmind/cve-2023-41425

WonderCMS Authenticated RCE - CVE-2023-41425

exploitationpayload-generationphishing+3
271 year ago
CVE-2026-2441 preview

CVE-2026-2441

GitHubmartinastarone/cve-2026-2441
binary-exploitationcommand-and-controleducation+8
3 months ago
LetsDefend-SOC173-Follina-0-Day-Detected preview

LetsDefend-SOC173-Follina-0-Day-Detected

GitHubarkha-corvus/letsdefend-soc173-follina-0-day-detected

We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered…

digital-forensicseducationincident-response+5
10 months ago
SuiteCRM-RCE preview

SuiteCRM-RCE

GitHubmcorybillington/suitecrm-rce

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

educationexploitationpapers-research+4
25 years ago
CVE-2024-34328 preview

CVE-2024-34328

GitHub0xsu3ks/cve-2024-34328
educationpapers-researchphishing+2
1 year ago
CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubdhananjayasj/cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability
exploitationlateral-movementpassword-cracking+3
2 months ago
ChromeAlone preview

ChromeAlone

GitHubpraetorian-inc/chromealone

A tool to transform Chromium browsers into a C2 Implant

command-and-controlpayload-developmentpersistence-mechanisms+6
5999 months ago
evil-ssdp preview

evil-ssdp

GitHubinitstring/evil-ssdp

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

exploitationids-ips-evasionimpersonation-tools+6
4422 years ago
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
151 year ago
CVE-2017-5415 preview

CVE-2017-5415

GitHub649/cve-2017-5415

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…

phishingsocial-engineeringweb-application-exploitation+1
79 years ago
EmailXpose preview

EmailXpose

GitLabroxanne_ardary/emailxpose

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

ai-securitydynamic-analysis-sandboxingemail-security+8
8 days ago
CVE-2021-24545 preview

CVE-2021-24545

GitHubv35hr4j/cve-2021-24545

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

exploitationpenetration-testingphishing+3
24 years ago
CVE-2024-34568 preview

CVE-2024-34568

GitHubsanupl/cve-2024-34568

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

exploitationphishingvulnerability-analysis+2
13 months ago
CVE-2021-43617 preview

CVE-2021-43617

GitHubsybelle03/cve-2021-43617

This is a reproduction of PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF) vulnerability

exploitationpenetration-testingphishing+3
13 years ago
Previous12…9Next