Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
ICSFuzz preview

ICSFuzz

GitHubmomalab/icsfuzz

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

dynamic-code-analysisembedded-systems-securityfuzzing+3
30
4 years ago
Kamerka-GUI preview

Kamerka-GUI

GitHubwoj-ciech/kamerka-gui

Ultimate Internet of Things/Industrial Control Systems reconnaissance tool.

exploitationinformation-gatheringiot-security+6
8662 months ago
apxutil preview

apxutil

GitHubfinngineering/apxutil

A tool to manipulate Schneider Electric PLC archive files

binary-analysisembedded-systems-securityexploitation+5
117 months ago
sparkplugFuzzer preview

sparkplugFuzzer

GitHubbishopfox/sparkplugfuzzer

Fuzzer for the Sparkplug B IIoT protocol

authenticationdynamic-analysis-sandboxingfuzzing+5
11 month ago
CVE-2025-69985 preview

CVE-2025-69985

GitHubkaleth4/cve-2025-69985

PoC exploit for CVE-2025-69985: authentication bypass leading to RCE in FUXA SCADA ≤1.2.8. Includes a modular Python exploit with interactive shell,…

authentication-authorizationexploitationpayload-development+5
3 months ago
CVE-2025-69985 preview

CVE-2025-69985

GitHubjoshuavanderpoll/cve-2025-69985

Python exploit for CVE-2025-69985 targeting FUXA SCADA software. Sends crafted JSON payload to /api/runscript endpoint to bypass authentication and…

authenticationexploitationremote-access-tool+3
36 months ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubmanuelsantosiglesias/cve-2021-31630

OpenPLC 3 WebServer Authenticated Remote Code Execution.

command-and-controlexploitationpenetration-testing+4
2 years ago
CVE-2021-26828_ScadaBR_RCE preview

CVE-2021-26828_ScadaBR_RCE

GitHubhev0x/cve-2021-26828_scadabr_rce

Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

exploitationpenetration-testingremote-access-tool+3
95 years ago
Terrminus-CVE-2026-2406 preview

Terrminus-CVE-2026-2406

GitHubridpath/terrminus-cve-2026-2406

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

exploitationinformation-gatheringiot-security+8
27 months ago
CVE-2025-41646---Critical-Authentication-Bypass- preview

CVE-2025-41646---Critical-Authentication-Bypass-

GitHubgreenforcenetworks/cve-2025-41646---critical-authentication-bypass-

CVE-2025-41646 - Critical Authentication bypass

authentication-authorizationexploitationids-ips-evasion+5
11 year ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubuserb1ank/cve-2021-31630

Exploit for CVE-2021-31630 in OpenPLC, providing a Python script and manual steps to achieve remote code execution via malicious ST file upload and…

command-and-controlexploitationpayload-development+3
10 months ago
SCADAShutdownTool preview

SCADAShutdownTool

GitHubpentdebra/scadashutdowntool

SCADA Security Testing tool

fuzzingpenetration-testingscada-ics-security+1
10 years ago