Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
61 results
mySCADA-myPRO-7-Hardcoded-FTP-Username-and-Password preview

mySCADA-myPRO-7-Hardcoded-FTP-Username-and-Password

GitHubemreovunc/myscada-mypro-7-hardcoded-ftp-username-and-password

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

embedded-systems-securityexploitationhardware-iot-security+4
12
8 years ago
CVE-2025-41656 preview

CVE-2025-41656

GitHubwallyschag/cve-2025-41656

This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656

educationexploitationiot-security+3
210 months ago
CVE-2021-31630-HTB preview

CVE-2021-31630-HTB

GitHubhunt3r0x/cve-2021-31630-htb

proof of Concept (PoC) exploit for CVE-2021-31630, targeting the OpenPLC service running on the WifineticTwo box on the Hack The Box platform.

ctfeducationexploitation+3
92 years ago
0day-Rubbish preview

0day-Rubbish

GitHubexploit-garbage/0day-rubbish

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to…

ai-securitycurated-resourcesexploitation+3
2097 days ago
metasploit-framework preview

metasploit-framework

GitHubrapid7/metasploit-framework

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

command-and-controldatabase-securitydata-exfiltration+20
39.0k3h 54m ago
CVE-2023-0861-POC preview

CVE-2023-0861-POC

GitHubseifallahhomrani1/cve-2023-0861-poc

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

educationembedded-systems-securityexploitation+5
73 years ago
CVE-2026-21018-OPC-UA-Authentication-Bypass-via-None-Security-Policy preview

CVE-2026-21018-OPC-UA-Authentication-Bypass-via-None-Security-Policy

GitHubgeorge0papasotiriou/cve-2026-21018-opc-ua-authentication-bypass-via-none-security-policy

Proof-of-concept exploit for OPC UA authentication bypass using None security policy, including a simulated server to demonstrate unauthorized…

authenticationexploitationmisconfiguration+3
1 month ago
Pwn2Own-Auto-2024-CHARX preview

Pwn2Own-Auto-2024-CHARX

GitHubret2/pwn2own-auto-2024-charx

Working exploit for Phoenix Contact CHARX SEC-3100 using Scapy raw Ethernet packets to trigger vulnerabilities and obtain an interactive connect-back…

embedded-systems-securityexploitationiot-security+2
142 years ago
Indushell preview

Indushell

GitHubsecarmalabs/indushell

PoC C&C for the Industroyer malware

command-and-controlexploitationmalware-analysis+3
269 years ago
CVE-2023-30459 preview

CVE-2023-30459

GitHubtoxich4/cve-2023-30459

CVE-2023-30459

exploitationpayload-generationremote-access-tool+2
33 years ago
CVE-2026-22553-InSAT-MasterSCADA-BUK-TS-MMadmServ preview

CVE-2026-22553-InSAT-MasterSCADA-BUK-TS-MMadmServ

GitHubmbanyamer/cve-2026-22553-insat-masterscada-buk-ts-mmadmserv

Unauthenticated OS command injection exploit for InSAT MasterSCADA BUK-TS MMadmServ web interface. Delivers reverse shell with root privileges via…

command-and-controlexploitationpayload-generation+3
4 months ago
CVE-2026-36226 preview

CVE-2026-36226

GitHubnullbyte8080/cve-2026-36226

Benign proof-of-concept for CVE-2026-36226, a cross-site scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 Admin Dashboard Create…

educationexploitationpenetration-testing+3
3 months ago
CVE-2024-8232 preview

CVE-2024-8232

GitHubz3usx01/cve-2024-8232

SpiderControl SCADA Web Server File Upload Vulnerability

educationexploitationpayload-generation+3
1 year ago
zeek preview

zeek

GitHubzeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

anomaly-detectionanti-botdefensive-tools+14
8.0k14h 30m ago
CVE-2023-31716 preview

CVE-2023-31716

GitHubmateustesser/cve-2023-31716

Proof-of-concept exploit for CVE-2023-31716, a Local File Inclusion vulnerability in FUXA SCADA/HMI software versions <= 1.1.12, enabling arbitrary…

embedded-systems-securityexploitationscada-ics-security+2
2 years ago
Purdue-Model-for-Industrial-Control-System-Environments preview

Purdue-Model-for-Industrial-Control-System-Environments

GitHubmurataydemir/purdue-model-for-industrial-control-system-environments

Purdue Model for Industrial Control System (ICS) Environments (Turkish)

educationnetwork-securitypapers-research+1
36 years ago
Active-Scanning-and-Information-Gathering-in-ICS-SCADA-Networks-Using-Network-Mapper-NMAP preview

Active-Scanning-and-Information-Gathering-in-ICS-SCADA-Networks-Using-Network-Mapper-NMAP

GitHubmurataydemir/active-scanning-and-information-gathering-in-ics-scada-networks-using-network-mapper-nmap

Active Scanning and Information Gathering in ICS/SCADA Networks using Network Mapper (NMAP) (Turkish)

educationinformation-gatheringnetwork-mapping+3
26 years ago
CVE-2025-54962 preview

CVE-2025-54962

GitHubeyodav/cve-2025-54962

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

educationexploitationpenetration-testing+3
1 year ago
Previous1234Next