Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
quiver preview

quiver

GitHubstevemcilwain/quiver

Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.

exploitationinformation-gatheringpenetration-testing+4
216
6 years ago
nec_aterm_tools preview

nec_aterm_tools

GitHubinfobyte/nec_aterm_tools

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.

embedded-systems-securityexploitationfirmware-analysis+4
34 years ago
cve-2022-1388-1veresk preview

cve-2022-1388-1veresk

GitHubiveresk/cve-2022-1388-1veresk

Simple shell script for the exploit

exploitationpenetration-testingreconnaissance+2
14 years ago
Lin_enum preview

Lin_enum

GitHubh3x0v3rl0rd/lin_enum

Shell script for automated enumeration of Linux systems to identify privilege escalation vectors and configuration weaknesses.

information-gatheringpenetration-testingpost-exploitation+2
1 year ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubghxstsec/cve-2026-39987

Exploit for Marimo pre-auth RCE via terminal WebSocket, providing command execution, interactive PTY shell, and reverse shell capabilities for…

exploitationpenetration-testingreconnaissance+3
5 days ago
React2Shell-PoC-CVE-2025-55182 preview

React2Shell-PoC-CVE-2025-55182

GitHubeagle-nett/react2shell-poc-cve-2025-55182

Proof-of-concept exploit for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Includes a scanner for vulnerable hosts and a…

educationexploitationlabs-practice+4
5 months ago
weevely3 preview

weevely3

GitHubepinna/weevely3

Weaponized web shell

penetration-testingpost-exploitationprivilege-escalation+4
3.5k11 months ago
smb preview

smb

GitHubhackingyseguridad/smb

Shell script collection for SMB protocol auditing, vulnerability detection (EternalBlue, SMBGhost), null session enumeration, credential brute-force,…

exploitationinformation-gatheringnetwork-security+5
7 months ago
cve-2024-24919 preview

cve-2024-24919

GitHubsatchhacker/cve-2024-24919

Shell script that tests for CVE-2024-24919 by sending curl requests to specified IPs/domains, intended for educational vulnerability assessment.

educationexploitationreconnaissance+2
2 years ago
WMIcmd preview

WMIcmd

GitHubnccgroup/wmicmd

A command shell wrapper using only WMI for Microsoft Windows

information-gatheringlateral-movementpenetration-testing+3
3349 years ago
GitLab-CVE-2021-22205-scanner preview

GitLab-CVE-2021-22205-scanner

GitHubfaisalfs10x/gitlab-cve-2021-22205-scanner

Python-based scanner for GitLab CVE-2021-22205 remote code execution, with Shodan integration for target discovery and reverse shell delivery.

exploitationpenetration-testingreconnaissance+2
64 years ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubgraphite-org/cve-2024-4577

Shell script to scan domains for CVE-2024-4577 PHP remote code execution vulnerability via crafted POST requests, exporting vulnerable targets for…

exploitationpenetration-testingreconnaissance+2
2 years ago
Port-enumeration preview

Port-enumeration

GitHubivanglinkin/port-enumeration

Have you ever faced with the lack of possibility of using NMap? For instance if you have reverse shell as an unprivileged user and there are no…

network-securitypenetration-testingport-scanning+1
333 years ago
CVE-2026-42945-NGINX-Rift preview

CVE-2026-42945-NGINX-Rift

GitHubrenison-gohel/cve-2026-42945-nginx-rift

Python exploit for CVE-2026-42945 (NGINX Rift) with reverse shell capability and Shodan-based target discovery for penetration testing.

exploitationinformation-gatheringpenetration-testing+3
13 months ago
Cybersec preview

Cybersec

GitHubamitr12/cybersec

Single-file HTML cheat sheet for red teamers and pentesters with auto-injecting attacker/target variables, OS-aware reverse shell generator, and…

command-and-controlctfeducation+9
918 days ago
CVE-2026-0073 preview

CVE-2026-0073

GitHub0xbinder/cve-2026-0073

An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized…

android-securityexploitationmobile-security+5
263 months ago
hatiyar preview

hatiyar

GitHubajutamangdev/hatiyar

Modular penetration testing framework with a Metasploit-like interactive shell, pre-built CVE exploit modules, and cloud/network reconnaissance…

cloud-securityeducationexploit-frameworks+5
239 months ago
CVE-2023-35078 preview

CVE-2023-35078

GitHublager1/cve-2023-35078

Shell script to check Ivanti EPMM (MobileIron Core) instances for CVE-2023-35078 remote unauthenticated API access vulnerability, with Shodan dorks…

exploitationinformation-gatheringreconnaissance+2
53 years ago
Previous1234Next