Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
126 results
unwaf preview

unwaf

GitHubmmarting/unwaf

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
192
7 months ago
FUCK-CDN preview

FUCK-CDN

GitHub0xshe/fuck-cdn

Automated CDN origin-IP discovery skill for Claude Code that runs 40+ prioritized OSINT methods, cross-validates candidates via SSL and HTTP…

dns-analysisdns-subdomain-enumerationinformation-gathering+9
1512 months ago
HP-HPLIP-Mass-CVE-checker-2026-09- preview

HP-HPLIP-Mass-CVE-checker-2026-09-

GitHubmurrez/hp-hplip-mass-cve-checker-2026-09-

Mass check/research exploit for HP HPLIP CVE-2026-91097–91106 (<3.26.6), PAPPL :8000 IPP probes + hpssd templates

exploitationinformation-gatheringiot-security+5
10 days ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
5213 days ago
misfortune-cookie preview

misfortune-cookie

GitHubluel-4013/misfortune-cookie

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

binary-exploitationembedded-systems-securityexploitation+6
24 days ago
Project-CVE-2026-45833 preview

Project-CVE-2026-45833

GitHube4zyy/project-cve-2026-45833

Exploit tool for CVE-2026-45833 in ChromaDB, enabling malicious model generation, reconnaissance, and data exfiltration from target collections via…

data-exfiltrationexploitationreconnaissance+2
1 month ago
Project-CVE-2026-33017 preview

Project-CVE-2026-33017

GitHube4zyy/project-cve-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

command-and-controlexploitationpayload-development+6
11 month ago
CVE-2026-22812 preview

CVE-2026-22812

GitHubmad12wader/cve-2026-22812

Nuclei template for detecting and exploiting unauthenticated remote code execution in OpenCode via crafted HTTP requests.

exploitationpenetration-testingreconnaissance+2
8 months ago
CVE-2025-61882 preview

CVE-2025-61882

GitHubsachinart/cve-2025-61882

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

exploitationpenetration-testingreconnaissance+3
110 years ago
CVE-2021-40438 preview

CVE-2021-40438

GitHubkashkovsky/cve-2021-40438

Proof-of-concept exploit for CVE-2021-40438, an Apache HTTP Server mod_proxy vulnerability allowing request forwarding to arbitrary origins, with a…

exploitationpenetration-testingreconnaissance+2
194 years ago
subdomain-tko preview

subdomain-tko

GitHubrandomrobbiebf/subdomain-tko

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

dns-analysisreconnaissancesubdomain-enumeration+2
6 years ago
vegadns preview

vegadns

GitLabwattocyber/vegadns

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

dns-analysisdns-subdomain-enumerationinformation-gathering+3
1 month ago
cantina preview
Archived

cantina

GitLabwattocyber/cantina

OSCP-legal network recon orchestrator for port discovery, service classification, and enum-only plugin dispatch across HTTP, SMB, FTP, SNMP, SSH, and…

information-gatheringnetwork-mappingpenetration-testing+2
1 month ago
httprobe preview

httprobe

GitHubtomnomnom/httprobe

Take a list of domains and probe for working HTTP and HTTPS servers

dns-subdomain-enumerationgeneral-purpose-utilitiesinformation-gathering+7
3.1k4 years ago
CypherDog preview

CypherDog

GitHubsadprocessor/cypherdog

PoSh BloodHound Dog Whisperer

information-gatheringpenetration-testingreconnaissance+2
1943 years ago
CVE-2026-17543-PHP-Exposure-Validator preview

CVE-2026-17543-PHP-Exposure-Validator

GitHubpratham220/cve-2026-17543-php-exposure-validator

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

defensive-toolsinformation-gatheringpenetration-testing+5
1 month ago
BFScan preview

BFScan

GitHubblackfan/bfscan

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

android-securityapi-securityinformation-gathering+5
2579 months ago
emby_ssrf preview

emby_ssrf

GitHubbtnz-k/emby_ssrf

Metasploit auxiliary module that identifies Emby Media Server version and exploits CVE-2020-26948 SSRF vulnerability to scan internal network…

exploitationnetwork-mappingreconnaissance+3
5 years ago
Previous1234567Next