Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
201 results
freedomfighting preview

freedomfighting

GitHubjusticerage/freedomfighting

A collection of scripts which may come in handy during your freedom fighting activities.

crawlerencryption-decryption-toolsforensics+8
418
3 years ago
DCOMrade preview

DCOMrade

GitHubsud0woodo/dcomrade

Powershell script for enumerating vulnerable DCOM Applications

lateral-movementpenetration-testingpost-exploitation+2
2647 years ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

exploitationinformation-gatheringlateral-movement+7
2452 months ago
chuckle preview

chuckle

GitHubnccgroup/chuckle

An automated SMB relay exploitation script.

exploitationlateral-movementpenetration-testing+3
15110 years ago
prefetch-tool preview

prefetch-tool

GitHubexploits-forsale/prefetch-tool

Windows KASLR bypass using prefetch side-channel

binary-exploitationexploitationinformation-gathering+4
2152 years ago
pinecone preview

pinecone

GitHubpinecone-wifi/pinecone

Modular WLAN auditing framework for red teams with deauthentication, rogue AP, and WPA handshake capture modules. Features a Metasploit-like CLI for…

exploitationinformation-gatheringpenetration-testing+3
1638 months ago
ResetSpy preview

ResetSpy

GitHubmlcsec/resetspy

Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal

authenticationdefensive-toolsidentity-management+6
5726 days ago
Whisper_Bully preview

Whisper_Bully

GitHubymsniper/whisper_bully

Three-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)

bluetooth-securityexploitationinformation-gathering+4
393 months ago
couchdb-exploit preview

couchdb-exploit

GitHubdarabium/couchdb-exploit

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

exploitationinformation-gatheringpenetration-testing+4
22 days ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
64 months ago
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
120 days ago
VulnForge preview

VulnForge

GitHubrootless-ghost/vulnforge

Vulnerability & exploit intelligence — ExploitDB, NVD, Metasploit search with CVE→ATT&CK mapping and LogNorm/HuntForge integration | Part of Nebula…

exploitationinformation-gatheringred-teaming+5
22 months ago
POC-CVE-2026-54121-Certighost preview

POC-CVE-2026-54121-Certighost

GitHubsam00/poc-cve-2026-54121-certighost

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

exploitationimpersonation-toolspenetration-testing+5
2 months ago
CVE-2026-4631-cockpit-RCE preview

CVE-2026-4631-cockpit-RCE

GitHubexdev994/cve-2026-4631-cockpit-rce

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

command-and-controlexploitationinformation-gathering+6
3 months ago
Terrminus-CVE-2026-2406 preview

Terrminus-CVE-2026-2406

GitHubridpath/terrminus-cve-2026-2406

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

exploitationinformation-gatheringiot-security+8
28 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHublutfifakee-project/cve-2026-41940

cPanel/WHM CVE-2026-41940 - Mass Scanner & Exploiter

authenticationcommand-and-controlexploitation+6
15 months ago
vBulletin-CVE-2025-48828-Multi-target preview

vBulletin-CVE-2025-48828-Multi-target

GitHubill-deed/vbulletin-cve-2025-48828-multi-target

Batch RCE scanner for vulnerable vBulletin instances using replaceAdTemplate exploit.

exploitationpenetration-testingreconnaissance+3
1 year ago
CVE-2026-39047 preview

CVE-2026-39047

GitHubazhariramadhan/cve-2026-39047

Printer exploitation framework for security testing via raw port 9100, featuring PCL payload delivery, DoS bombing, C2 QR codes, phishing QR codes,…

data-exfiltrationexploitationnetwork-security+4
6 months ago
Previous1…101112Next