Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
Argus preview

Argus

GitHubdozermx/argus

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

api-securityfuzzinginformation-gathering+9
5
5 months ago
prismsec preview

prismsec

GitHubazmisyahrul/prismsec

Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

dns-subdomain-enumerationpenetration-testingpenetration-testing-frameworks+7
2 days ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
17 days ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
11 month ago
peeko preview

peeko

GitHubb3rito/peeko

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

command-and-controldata-exfiltrationinformation-gathering+7
2331 year ago
phantomrecon preview

phantomrecon

GitHubl33tdawg/phantomrecon

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

dns-analysisexploitationinformation-gathering+6
36 months ago
JavaDeserialization preview

JavaDeserialization

GitHubetocheney/javadeserialization

针对类似CVE-2017-10271漏洞的一个java反序列化漏洞扫描器

exploitationnetwork-mappingpayload-generation+3
97 years ago
topera preview

topera

GitHubtoperaproject/topera

IPv6 analysis tool: the other side

ids-ips-evasionnetwork-securitypenetration-testing+3
3612 years ago
CVE-2023-27163-InternalProber preview

CVE-2023-27163-InternalProber

GitHubsamh4cks/cve-2023-27163-internalprober

A tool to perform port scanning using vulnerable Request-Baskets

exploitationpenetration-testingport-scanning+3
52 years ago
CVE-2014-4210-SSRF-PORTSCANNER-POC preview

CVE-2014-4210-SSRF-PORTSCANNER-POC

GitHubunmanarc/cve-2014-4210-ssrf-portscanner-poc

CVE-2014-4210 SSRF PORTSCANNER PoC

educationexploitationport-scanning+3
36 years ago
SSRFX preview

SSRFX

GitHubnonenotnull/ssrfx

CVE-2014-4210+Redis未授权访问

exploitationpenetration-testingport-scanning+3
989 years ago
Exploit_CVE-2023-27163 preview

Exploit_CVE-2023-27163

GitHubj0ey17/exploit_cve-2023-27163

Proof of Concept exploit for Server Side Request Forgery vulnerability in Requests Basket v1.2.1 and before.

exploitationpenetration-testingport-scanning+3
11 year ago
CVE-2025-64459-hunter preview

CVE-2025-64459-hunter

GitHubpurehate/cve-2025-64459-hunter

CVE-2025-64459-hunter

exploitationnetwork-mappingport-scanning+3
6 months ago
WebLogic-SSRF_CVE-2014-4210 preview

WebLogic-SSRF_CVE-2014-4210

GitHubnhpt/weblogic-ssrf_cve-2014-4210

Weblogic SearchPublicRegistries SSRF(CVE-2014-4210) Exploit Script based on Python3

exploitationnetwork-mappingport-scanning+3
115 years ago
CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer preview

CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer

GitHubtheopaid/cve-2023-27163-request-baskets-local-ports-bruteforcer

PoC and internal port brute-forcer for CVE-2023-27163

exploitationport-scanningreconnaissance+2
11 year ago
CVE-2023-27163-exploit preview

CVE-2023-27163-exploit

GitHubjeanback1/cve-2023-27163-exploit
cloud-securityexploitationport-scanning+3
3 months ago
xerosploit preview

xerosploit

GitHublionsec/xerosploit

Efficient and advanced man in the middle framework

exploitationinformation-gatheringnetwork-security+4
2.2k3 years ago
pentest-mcp preview

pentest-mcp

GitHubdmontgomery40/pentest-mcp

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

exploitationfuzzingnetwork-mapping+8
1425 months ago
Previous12Next