Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker
api-security-testingids-ips-evasioninformation-gathering+6
331 day ago
CVE-2026-26119 preview

CVE-2026-26119

GitHubcyb3rwitch3r/cve-2026-26119

Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

exploitationpenetration-testingred-teaming+1
111 days ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubjendmaoul/xss2shell-cve-2026-64638

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

exploitationpayload-developmentpenetration-testing+4
112 days ago
evilwaf preview

evilwaf

GitHubmatrixleons/evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

fingerprint-spoofinginformation-gatheringosint+6
88613 days ago
CVE-2025-8110 preview

CVE-2025-8110

GitHub9xh4kv/cve-2025-8110

PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

exploitationpenetration-testingred-teaming+2
15 days ago
MegaQuagga_Pentesting_Report preview

MegaQuagga_Pentesting_Report

GitHubaktia1/megaquagga_pentesting_report

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

educationexploitationpenetration-testing+5
3 months ago
frida-c2-mcp preview

frida-c2-mcp

GitHubs4dp4nd4/frida-c2-mcp

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

android-securitycommand-and-controldynamic-analysis-sandboxing+8
615 months ago
Anvil preview

Anvil

GitHubshellkraft/anvil

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

binary-analysisexploitationpenetration-testing+5
375 months ago
ToolShell preview

ToolShell

GitHubl0ggg/toolshell

Exploit for ToolShell

exploitationpenetration-testingred-teaming+1
159 months ago
CVE-2025-64446-FortiWeb-CGI-Bypass-PoC preview

CVE-2025-64446-FortiWeb-CGI-Bypass-PoC

GitHubsxyrxyy/cve-2025-64446-fortiweb-cgi-bypass-poc
exploitationpenetration-testingred-teaming+3
139 months ago
ThingsBoard-IoT-Platform-CVE-2024-55466 preview

ThingsBoard-IoT-Platform-CVE-2024-55466

GitHubcybsecsid/thingsboard-iot-platform-cve-2024-55466
exploitationpenetration-testingprivilege-escalation+3
1 year ago
cc-ddos preview

cc-ddos

GitHubnayumidev/cc-ddos

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

penetration-testingred-teamingweb-application-exploitation
811 year ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705
command-and-controlexploitationpayload-development+5
1 year ago
msi-central_privesc preview

msi-central_privesc

GitHubnam3lum/msi-central_privesc

CVE-2022-38532 - Local Privilege Escalation vulnerability in MSI Center Application

binary-analysisexploitationpenetration-testing+3
71 year ago
CVE-2024-0195-SpiderFlow preview

CVE-2024-0195-SpiderFlow

GitHubhack-with-rohit/cve-2024-0195-spiderflow
code-analysisexploitationpenetration-testing+3
1 year ago
CVE-2024-30270-PoC preview

CVE-2024-30270-PoC

GitHubalchemist3dot14/cve-2024-30270-poc

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

exploitationpayload-developmentpenetration-testing+3
42 years ago
proxychains preview

proxychains

GitHubhaad/proxychains

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…

dns-analysisnetwork-securitypenetration-testing+1
7.9k2 years ago
vaultize_CVE-2024-36079 preview

vaultize_CVE-2024-36079

GitHubdxrvs/vaultize_cve-2024-36079
exploitationpenetration-testingprivilege-escalation+3
12 years ago
Previous123Next