Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
mass3 preview

mass3

GitHubsmiegles/mass3

Multi-threaded DNS-based enumeration tool for discovering AWS S3 buckets using pre-compiled wordlists and custom DNS resolvers, with optional Docker…

cloud-securitydns-analysisinformation-gathering+2
125
7 years ago
pegasus-neo preview

pegasus-neo

GitHubsobri3195/pegasus-neo

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

exploitationforensicsosint+9
1287 months ago
webstor preview

webstor

GitHubrossgeerlings/webstor

Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

dns-analysisinformation-gatheringreconnaissance+2
1582 years ago
Custom-Nuclei-Templates preview

Custom-Nuclei-Templates

GitHubk3ystr0k3r/custom-nuclei-templates

A list of custom Nuclei templates you can use for your scans.

reconnaissancevulnerability-scannersweb-security
71 month ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubqingsiweisan/cve-2022-40684

Python exploit for CVE-2022-40684 targeting FortiGate devices. Supports single and batch execution with custom SSH public key injection for…

exploitationpenetration-testingreconnaissance+2
93 years ago
CVE-2019-0708Poc-BatchScanning preview

CVE-2019-0708Poc-BatchScanning

GitHubht0ruial/cve-2019-0708poc-batchscanning

Batch scanning tool for CVE-2019-0708 (BlueKeep) vulnerability detection on Windows systems, supporting single and multi-IP scanning with custom IP…

exploitationinformation-gatheringnetwork-security+3
57 years ago
Make-and-Break preview

Make-and-Break

GitHubrayferrufino/make-and-break

Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine

educationexploitationexploit-frameworks+6
17 years ago
ESXi-Ransomware-Scanner-mi preview

ESXi-Ransomware-Scanner-mi

GitHubcyberthreatanalysis/esxi-ransomware-scanner-mi

ESXi EZ - A custom scanner that takes list of IPs either in JSON, CSV or individually and checks for infection CVE-2021-21974

information-gatheringreconnaissancescripting-automation+2
23 years ago
Penetration-Testing-Walkthrough-Hacksudo-Thor preview

Penetration-Testing-Walkthrough-Hacksudo-Thor

GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

ctfeducationexploitation+8
5 months ago
FOFA-API-Threaded-Searcher preview

FOFA-API-Threaded-Searcher

GitHubjenderal92/fofa-api-threaded-searcher

Multi‑threaded Python tool to query FOFA API, extract custom fields (IP, port, cert, TLS, etc.), deduplicate results, and resume interrupted searches.

information-gatheringiot-securityosint+1
4 months ago
Vite-CVE-2025-30208-EXP preview

Vite-CVE-2025-30208-EXP

GitHublilil3333/vite-cve-2025-30208-exp

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2016-6210-exploit preview

CVE-2016-6210-exploit

GitHubgoomdan/cve-2016-6210-exploit

Custom exploit written for enumerating usernames as per CVE-2016-6210

exploitationinformation-gatheringpassword-attacks+3
12 years ago
CVE-2019-0708-scan preview

CVE-2019-0708-scan

GitHublisinan988/cve-2019-0708-scan

Batch scanner for CVE-2019-0708 (BlueKeep) RDP vulnerability with Windows and Linux support, using rdpscan and custom Cscan for mass IP range…

exploitationinformation-gatheringnetwork-security+3
4 years ago
WordList preview

WordList

GitHubrix4uni/wordlist

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

dns-subdomain-enumerationfuzzinginformation-gathering+6
1533 months ago
melody preview
Archived

melody

GitHubma111e/melody

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.

information-gatheringintrusion-detectionnetwork-security+5
1391 year ago
pulsar preview
Archived

pulsar

GitHub0x0fb0/pulsar

Network footprint scanner platform. Discover domains and run your custom checks periodically.

cloud-securitydns-subdomain-enumerationinformation-gathering+6
4294 years ago
CVE-2026-58480 preview

CVE-2026-58480

GitHubshinthink/cve-2026-58480

CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

exploitationpayload-generationpenetration-testing+3
32 months ago
nmap preview

nmap

GitHubnmap/nmap

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

bluetooth-securitydatabase-securitydata-exfiltration+18
13.7k21h 25m ago
Previous12345Next