Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
CVE-2025-55182 preview

CVE-2025-55182

GitHubsentinelxofficial/cve-2025-55182

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

exploitationids-ips-evasionpayload-development+5
1
2 months ago
oopso preview

oopso

GitHubb3rito/oopso

An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.

information-gatheringosintreconnaissance+2
41 month ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubmoneertv/cve-2023-23397

CVE-2023-23397 C# PoC

exploitationpassword-crackingpayload-generation+3
13 years ago
vbrute preview

vbrute

GitHubnccgroup/vbrute

Virtual host brute forcer

information-gatheringnetwork-mappingreconnaissance+1
2212 years ago
CVE-2023-27163 preview

CVE-2023-27163

GitHubdavuxvi/cve-2023-27163

Proof-of-concept exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in request-baskets up to v1.2.1. Includes automated…

exploitationlabs-practicepenetration-testing+3
13 years ago
CVE-2024-3400-Check preview

CVE-2024-3400-Check

GitHubsxyrxyy/cve-2024-3400-check

Python script to check for CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS SSL VPN by probing /ssl-vpn/hipreport.esp and verifying file…

exploitationpenetration-testingreconnaissance+2
2 years ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubayiezola/cve-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

exploitationinformation-gatheringpayload-development+4
2 months ago
EvilCrowRF_Custom_Firmware_CC1101_FlipperZero preview

EvilCrowRF_Custom_Firmware_CC1101_FlipperZero

GitHubh-rat/evilcrowrf_custom_firmware_cc1101_flipperzero

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

embedded-systems-securityhardware-hackinghardware-iot-security+5
5972 years ago
CVE-2019-0708-Check-Device-Patch-Status preview

CVE-2019-0708-Check-Device-Patch-Status

GitHubfourtwizzy/cve-2019-0708-check-device-patch-status

PowerShell script to check if a remote device is patched against CVE-2019-0708 by verifying termdd.sys file version against Microsoft's May 2019…

exploitationinformation-gatheringpenetration-testing+3
187 years ago
tachyon preview

tachyon

GitHubdelvelabs/tachyon

Fast http dead file finder.

information-gatheringreconnaissancevulnerability-scanners+1
2211 month ago
bbot-ui preview

bbot-ui

GitHubk11h-de/bbot-ui

a terminal UI to browse bbot reports

information-gatheringlog-analysisreconnaissance+2
97 months ago
CVE-2024-34470 preview

CVE-2024-34470

GitHubmr-r00t11/cve-2024-34470

A critical vulnerability has been found in HSC Mailinspector up to version 5.2.18. This vulnerability affects an unknown functionality of the file…

exploitationinformation-gatheringpenetration-testing+3
52 years ago
CVE-2023-33246 preview

CVE-2023-33246

GitHub0xkayala/cve-2023-33246

Exploits Apache RocketMQ brokers vulnerable to CVE-2023-33246 remote code execution and checks targets via IP, CIDR, or file input.

exploitationinformation-gatheringpenetration-testing+3
22 years ago
CVE-2023-27997-Check preview

CVE-2023-27997-Check

GitHubimbas007/cve-2023-27997-check

Lightweight Python script to check Fortinet SSL VPN instances for CVE-2023-27997 vulnerability, supporting single URL and batch file scanning.

exploitationpenetration-testingreconnaissance+2
13 years ago
CVE-2024-9466 preview

CVE-2024-9466

GitHubholypryx/cve-2024-9466

Proof-of-concept script to detect CVE-2024-9466 by checking HTTP responses for a specific debug file path on target URLs.

exploitationpenetration-testingreconnaissance+2
11 year ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubcharanvoonna/cve-2021-41773

Nmap NSE script to detect Apache HTTP Server path traversal vulnerability (CVE-2021-41773) by sending crafted requests and analyzing responses for…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubpuckiestyle/cve-2021-41773

Python script to exploit CVE-2021-41773, a path traversal vulnerability in Apache 2.4.49, allowing file disclosure and remote code execution.

exploitationpenetration-testingreconnaissance+2
4 years ago
PCredz preview

PCredz

GitHublgandx/pcredz

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

forensicsinformation-gatheringnetwork-security+3
2.5k6 months ago
Previous1…678…13Next