Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
awsScrape preview

awsScrape

GitHubjhaddix/awsscrape

A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.

information-gatheringnetwork-mappingnetwork-security+2
2362 years ago
sslScrape preview

sslScrape

GitHubcheetz/sslscrape

SSLScrape | A scanning tool for scaping hostnames from SSL certificates.

information-gatheringnetwork-mappingreconnaissance+1
3378 years ago
knockbleed preview

knockbleed

GitHubsiddolo/knockbleed

CVE-2014-0160 mass test against subdomains

exploitationinformation-gatheringreconnaissance+3
12 years ago
Freak-Scanner preview

Freak-Scanner

GitHubscottjpack/freak-scanner

Multithreaded FREAK scanner, used to detect SSL EXP Ciphers, vulnerable to CVE-2015-0204

information-gatheringnetwork-securitypenetration-testing+2
411 years ago
CVE-2024-3400-Check preview

CVE-2024-3400-Check

GitHubsxyrxyy/cve-2024-3400-check

Python script to check for CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS SSL VPN by probing /ssl-vpn/hipreport.esp and verifying file…

exploitationpenetration-testingreconnaissance+2
2 years ago
cve-2024-21762-checker preview

cve-2024-21762-checker

GitHubrdoix/cve-2024-21762-checker

Shodan-based scanner that discovers FortiGate SSL VPN devices and tests them for CVE-2024-21762 vulnerability, displaying organization and country…

exploitationnetwork-securityosint+3
12 years ago
Barcha preview

Barcha

GitHubs1n6h/barcha

Barcha is your Swiss‑Army knife for SQL Injection reconnaissance 🔍. Written in Go, it automates: Shodan enumeration of SSL hosts 🕵️‍♂️ Liveness &…

information-gatheringreconnaissancevulnerability-scanners+1
341 year ago
FinalRecon preview

FinalRecon

GitHubthewhiteh4t/finalrecon

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

crawlerdns-analysisinformation-gathering+7
3.0k3 months ago
CVE-2018-13379 preview

CVE-2018-13379

GitHubkh4sh3i/cve-2018-13379

CVE-2018-13379 - Fortinet SSL VPN Vulnerability

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2023-27997-Check preview

CVE-2023-27997-Check

GitHubimbas007/cve-2023-27997-check

Lightweight Python script to check Fortinet SSL VPN instances for CVE-2023-27997 vulnerability, supporting single URL and batch file scanning.

exploitationpenetration-testingreconnaissance+2
13 years ago
PoC-CVE-2021-41773 preview

PoC-CVE-2021-41773

GitHubiilegacyyii/poc-cve-2021-41773

Proof-of-concept scanner for Apache HTTP Server path traversal (CVE-2021-41773) with multi-host support, SSL verification toggle, and concurrent…

exploitationinformation-gatheringpenetration-testing+3
524 years ago
CVE-2024-21762-Checker preview

CVE-2024-21762-Checker

GitHubdefr0ggy/cve-2024-21762-checker

This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given…

exploitationnetwork-securitypenetration-testing+3
2 years ago
pulsexploit preview

pulsexploit

GitHubaqhmal/pulsexploit

Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this…

exploitationinformation-gatheringpenetration-testing+3
96 years ago
pulse-exploit preview

pulse-exploit

GitHubandripwn/pulse-exploit

Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

exploitationosintpenetration-testing+3
16 years ago
wordpress-cve-2024-10924-pentest preview

wordpress-cve-2024-10924-pentest

GitHubademto/wordpress-cve-2024-10924-pentest

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

authenticationeducationexploitation+5
31 year ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubvulnpire/cve-2024-24919

Exploit script for CVE-2024-24919 targeting Check Point SSL VPN, with Shodan and FOFA search queries for vulnerable devices.

exploitationpenetration-testingreconnaissance+2
2 years ago
CVE-2018-13379 preview

CVE-2018-13379

GitHubzierax/cve-2018-13379

CVE-2018-13379 fortiOS vulnerability POC

exploitationinformation-gatheringpenetration-testing+3
27 months ago
getaltname preview

getaltname

GitHubfranccesco/getaltname

Extract subdomains from SSL certificates in HTTPS sites.

dns-subdomain-enumerationinformation-gatheringpenetration-testing+2
3902 months ago
Previous12Next