Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
158 results
secretsdump.py preview

secretsdump.py

GitHubfin3ss3g0d/secretsdump.py

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

data-exfiltrationpassword-attackspenetration-testing+2
2593 years ago
zyxel-social-login-bypass-cve-2026-8508 preview

zyxel-social-login-bypass-cve-2026-8508

GitHubminanagehsalalma/zyxel-social-login-bypass-cve-2026-8508

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

authenticationexploitationnetwork-access-control+4
11 days ago
CVE-2026-4484 preview

CVE-2026-4484

GitHubnxploited/cve-2026-4484

Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator

authentication-authorizationexploitationpenetration-testing+4
4 months ago
CVE-2026-1492 preview

CVE-2026-1492

GitHubnxploited/cve-2026-1492

User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration

educationexploitationpenetration-testing+4
4 months ago
CVE-2026-27542-CVE-2026-27540- preview

CVE-2026-27542-CVE-2026-27540-

GitHubnxploited/cve-2026-27542-cve-2026-27540-

Unauthenticated Privilege | Unauthenticated Arbitrary File Upload

exploitationpenetration-testingprivilege-escalation+3
4 months ago
http-react2shell preview

http-react2shell

GitHubmoisestapia/http-react2shell

Detection of the React Server Actions Exploit vector – CVE-2025-55182 / CVE-2025-66478

devsecopseducationexploitation+6
8 months ago
PoC---CVE-2023-26482-RCE-LAB-Nextcloud preview

PoC---CVE-2023-26482-RCE-LAB-Nextcloud

GitHubisabbii/poc---cve-2023-26482-rce-lab-nextcloud

Docker-based lab reproducing CVE-2023-26482 (Nextcloud RCE) with automated exploit script for educational vulnerability analysis and exploitation…

educationexploitationlabs-practice+5
6 months ago
SharpSpray preview

SharpSpray

GitHubjnqpblc/sharpspray

C# tool for automated password spraying attacks against Active Directory users via LDAP, with configurable delays and password lists, designed for…

authenticationpassword-attackspenetration-testing+1
1957 years ago
CVE-2025-59718-PoC preview

CVE-2025-59718-PoC

GitHubexfil0/cve-2025-59718-poc

Fortinet announced two closely related authentication‑bypass vulnerabilities on 9 December 2025. Both flaws involve improper verification of…

authenticationeducationexploitation+5
68 months ago
CVE-2024-41570 preview

CVE-2024-41570

GitHubdiemoeve/cve-2024-41570

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

command-and-controlexploitationpayload-generation+5
121 year ago
chromebackdoor preview
Archived

chromebackdoor

GitHubgraniet/chromebackdoor

Chromebackdoor is a PoC of pentest tool, this tool use a MITB technique for generate a windows executable ".exe" after launch run a malicious…

command-and-controlpayload-generationpenetration-testing+2
5139 years ago
linset preview

linset

GitHubvk496/linset

Evil Twin Attack Bash script

educationphishingred-teaming+3
57612 years ago
WSL_Payload_Builder preview

WSL_Payload_Builder

GitHubm1ddl3w4r3/wsl_payload_builder

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

payload-developmentpayload-generationpenetration-testing+1
729 months ago
CVE-2022-45701 preview

CVE-2022-45701

GitHubgeniuszly/cve-2022-45701

it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script…

educationexploitationiot-security+6
52 years ago
CVE-2021-21425-RCE preview

CVE-2021-21425-RCE

GitHubs1lentf00thold/cve-2021-21425-rce

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

exploitationpayload-generationpenetration-testing+3
2 months ago
tor-ip-changer preview

tor-ip-changer

GitHubianxtianxt/tor-ip-changer

Simple shell script to automatically request new Tor identity at configurable intervals for IP rotation.

educationids-ips-evasionprivacy+1
26 years ago
CVE-2024-1709-ConnectWise-ScreenConnect-Authentication-Bypass preview

CVE-2024-1709-ConnectWise-ScreenConnect-Authentication-Bypass

GitHubsxyrxyy/cve-2024-1709-connectwise-screenconnect-authentication-bypass

Python exploit script for CVE-2024-1709, an authentication bypass vulnerability in ConnectWise ScreenConnect. Adds a new administrative user to the…

authentication-authorizationexploitationpenetration-testing+3
12 years ago
cve-2023-30800-multithread-doser preview

cve-2023-30800-multithread-doser

GitHubdiemaxxing/cve-2023-30800-multithread-doser

Multithredded DoS Python Script For CVE-2023-30800

exploitationpenetration-testingred-teaming+1
11 year ago
Previous1…789Next