Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
70 results
WPSniper preview

WPSniper

GitHubynsmroztas/wpsniper

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

information-gatheringpenetration-testingreconnaissance+4
1 day ago
JQueryingU preview

JQueryingU

GitHubsamsayen/jqueryingu

Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request

information-gatheringosint-social-engineeringphishing-tools+2
7 years ago
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
253 days ago
CVE-2026-21440 preview

CVE-2026-21440

GitHubyou-ssef9/cve-2026-21440

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

information-gatheringreconnaissancevulnerability-analysis+1
18 months ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
GetFGPP preview

GetFGPP

GitHubn00py/getfgpp

Get Fine Grained Password Policy

configuration-auditinginformation-gatheringpenetration-testing+1
796 months ago
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k2 years ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
kong-pwn preview

kong-pwn

GitHubrandomrobbiebf/kong-pwn

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

api-securitycloud-securityexploitation+6
66 years ago
eos preview

eos

GitHubsynacktiv/eos

Enemies Of Symfony - Debug mode Symfony looter

information-gatheringmisconfigurationpenetration-testing+3
3631 year ago
crtsh preview

crtsh

GitHubknqyf263/crtsh

API client for crt.sh

osintreconnaissancesubdomain-enumeration
415 years ago
VMware-CVE-2022-22954 preview

VMware-CVE-2022-22954

GitHublucksec/vmware-cve-2022-22954

Proof-of-concept exploit for CVE-2022-22954, a server-side template injection in VMware Workspace ONE Access Freemarker, enabling remote code…

exploitationpenetration-testingreconnaissance+2
4 years ago
cngo preview

cngo

GitHub0xsnowmn/cngo

Fast Golang Tool To Get Cname For Domains and Subdomain

dns-analysisinformation-gatheringnetwork-mapping+2
161 year ago
Mindmaps preview

Mindmaps

GitHubsynacktiv/mindmaps

Azure mindmap for penetration tests

cloud-securitycurated-resourceseducation+3
2332 years ago
MassZeroLogon preview

MassZeroLogon

GitHublikeww/masszerologon

Tool for mass testing ZeroLogon vulnerability CVE-2020-1472

exploitationinformation-gatheringnetwork-security+3
3 years ago
VMware-CVE-2022-22954 preview

VMware-CVE-2022-22954

GitHubnieldk/vmware-cve-2022-22954

Proof-of-concept exploit for CVE-2022-22954, a Freemarker server-side template injection in VMware Workspace ONE Access, with a one-line GET request…

exploitationinformation-gatheringreconnaissance+2
4 years ago
CVE-2025-10035_GoAnywhere preview

CVE-2025-10035_GoAnywhere

GitHuborange0mint/cve-2025-10035_goanywhere

CVE-2025-10035_GoAnywhere Get RCE

exploitationinformation-gatheringpenetration-testing+3
0 years ago
VMware-CVE-2022-22954 preview

VMware-CVE-2022-22954

GitHubsherlocksecurity/vmware-cve-2022-22954

POC for VMWARE CVE-2022-22954

exploitationpenetration-testingreconnaissance+3
2794 years ago
Previous1234Next