Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3496 results
of-CORS preview

of-CORS

GitHubtrufflesecurity/of-cors

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

information-gatheringmisconfigurationphishing+3
153
3 years ago
CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration preview

CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration

GitHubmbanyamer/cve-2026-27579-collabplatform-appwrite-cors-misconfiguration

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

exploitationphishing-toolsred-teaming+3
7 months ago
stunner preview

stunner

GitHubfirefart/stunner

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

exploitationmisconfigurationnetwork-security+3
86729 days ago
Shadow-Vault preview

Shadow-Vault

GitHubjenderal92/shadow-vault

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

authentication-authorizationemail-securityidentity-access-management+3
4 months ago
web-mitm-lab preview

web-mitm-lab

GitHubdereeqw/web-mitm-lab

Web traffic interception simulation tool for cybersecurity research and defensive learning in isolated lab environments.

educationinformation-gatheringnetwork-security+5
36 months ago
CVE-2026-21858-n8n-FullChain preview

CVE-2026-21858-n8n-FullChain

GitHubzerodayevil/cve-2026-21858-n8n-fullchain

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection…

ai-securityexploitationpayload-development+7
8826 days ago
NtlmRelayToEWS preview

NtlmRelayToEWS

GitHubarno0x/ntlmrelaytoews

ntlm relay attack to Exchange Web Services

email-securityexploitationinformation-gathering+4
3318 years ago
AndroidClient preview

AndroidClient

GitHubrev-code/androidclient

Android remote administration client

android-securitycommand-and-controlmobile-security+3
118 years ago
ESP-RFID-Tool preview

ESP-RFID-Tool

GitHubrfidtool/esp-rfid-tool

A tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed directly into an existing…

embedded-systems-securityfuzzinghardware-hacking+5
5874 years ago
fireprox preview

fireprox

GitHubustayready/fireprox

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

api-securitycloud-securityinformation-gathering+5
2.3k4 years ago
SharpADWS preview

SharpADWS

GitHubwh0amitz/sharpadws

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

authenticationexploitationlateral-movement+6
6052 years ago
shellerator preview

shellerator

GitHubshutdownrepo/shellerator

Simple CLI tool for the generation of bind and reverse shells in multiple languages

payload-generationpenetration-testingred-teaming+1
3943 months ago
Preferred-Network-List-Sniffer preview

Preferred-Network-List-Sniffer

GitHubaleksamcode/preferred-network-list-sniffer

A reconnaissance tool for capturing and displaying SSIDs from device's Preferred Network List.

information-gatheringpacket-sniffing-analysisreconnaissance+3
1789 months ago
watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553 preview

watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553

GitHubwatchtowrlabs/watchtowr-vs-solarwinds-webhelpdesk-cve-2025-40552-cve-2025-40553

Detection artifact generator for SolarWinds Web Help Desk pre-auth RCE chain (CVE-2025-40552 + CVE-2025-40553). Verifies authentication bypass and…

authentication-authorizationexploitationpenetration-testing+3
47 months ago
pFuzz preview

pFuzz

GitHubredsection/pfuzz

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

fuzzingpenetration-testingred-teaming+2
1615 years ago
WeBaCoo preview

WeBaCoo

GitHubanestisb/webacoo

Web Backdoor Cookie Script-Kit

command-and-controlpayload-generationpenetration-testing+2
18614 years ago
Vajra preview

Vajra

GitHubtrouble-1/vajra

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

cloud-securityinformation-gatheringmisconfiguration+4
4091 year ago
CVE-2026-44402 preview

CVE-2026-44402

GitHub0xcyp1337/cve-2026-44402

Exploit for CVE-2026-44402 targeting Voltronic Power SNMP Web Pro 1.1, enabling unauthenticated remote code execution via malicious firmware upload.…

exploitationpenetration-testingred-teaming+3
1 month ago
Previous12…100Next