Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
260
3 years ago
CVE-2024-22120-RCE preview

CVE-2024-22120-RCE

GitHubw01fh4cker/cve-2024-22120-rce

Time Based SQL Injection in Zabbix Server Audit Log --> RCE

exploitationpenetration-testingred-teaming+2
1362 years ago
CVE-2024-9593 preview

CVE-2024-9593

GitHubrandomrobbiebf/cve-2024-9593

Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

code-analysisexploitationpenetration-testing+3
81 year ago
certsync preview

certsync

GitHubzblurx/certsync

Dump NTDS with golden certificates and UnPAC the hash

authenticationexploitationpenetration-testing+4
6502 years ago
RasmanPotato preview

RasmanPotato

GitHubcrisprss/rasmanpotato

Abuse Impersonate Privilege from Service to SYSTEM like other potatoes do

exploitationpenetration-testingpost-exploitation+2
4033 years ago
CVE-2023-46747-RCE preview

CVE-2023-46747-RCE

GitHubw01fh4cker/cve-2023-46747-rce

Exploit for CVE-2023-46747, a remote code execution vulnerability in F5 BIG-IP, allowing unauthorized user creation and command execution.

authenticationexploitationpenetration-testing+3
2051 year ago
Shiva preview

Shiva

GitHubs0md3v/shiva

Improved DOS exploit for wordpress websites (CVE-2018-6389)

exploitationpenetration-testingred-teaming+2
1315 years ago
pyobfuscate preview

pyobfuscate

GitHubmachine1337/pyobfuscate

A simple and efficent script to obfuscate python payloads to make it completely FUD

exploitationmalware-analysispayload-development+2
392 years ago
FuguHub-8.4-Authenticated-RCE-CVE-2024-27697 preview

FuguHub-8.4-Authenticated-RCE-CVE-2024-27697

GitHubsanjindedic/fuguhub-8.4-authenticated-rce-cve-2024-27697

Arbitrary Code Execution on FuguHub 8.4

command-and-controlexploitationpayload-development+5
102 years ago
sliver-n8n-notifications preview

sliver-n8n-notifications

GitHub0x0trace/sliver-n8n-notifications

Real-time notification system for Sliver C2 implant callbacks, integrating n8n workflows to deliver color-coded alerts to Discord and Slack with…

command-and-controlpenetration-testingred-teaming+1
129 months ago
React2Shell preview

React2Shell

GitLabletchupkt/react2shell

Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

command-and-controlexploitationpenetration-testing+3
19 months ago
CTT-Sovereign-Vortex preview

CTT-Sovereign-Vortex

GitHubsimoesctt/ctt-sovereign-vortex

Exploit for CVE-2026-2406 targeting Terrminus Authentication Gateways, using temporal dispersion to bypass fingerprinting and behavioral AI,…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2014-5284 preview

CVE-2014-5284

GitHubmbadanoiu/cve-2014-5284

Bash implementation of CVE-2014-5284

exploitationpenetration-testingprivilege-escalation+2
7 years ago