Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
CVE-2023-31717 preview

CVE-2023-31717

GitHubmateustesser/cve-2023-31717

Proof-of-concept SQL injection exploit for FUXA SCADA software (<=1.1.12) via HTTP POST JSON id parameter, enabling extraction of SQLite database…

database-securityexploitationscada-ics-security+2
3 years ago
CVE-2018-7848 preview

CVE-2018-7848

GitHubyanissec/cve-2018-7848

CVE-2018-7848

embedded-systems-securityexploitationpenetration-testing+2
2 years ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubflojboj/cve-2021-31630

POC Exploit for CVE-2021-31630 written in Python3 and using C reverse shell with non-blocking mode

ctfeducationexploitation+3
2 years ago
CVE-2018-7846 preview

CVE-2018-7846

GitHubyanissec/cve-2018-7846

CVE-2018-7846

embedded-systems-securityexploitationpenetration-testing+2
2 years ago
CVE-2021-31630-OpenPLC-3-Authenticated-RCE preview

CVE-2021-31630-OpenPLC-3-Authenticated-RCE

GitHubmind2hex/cve-2021-31630-openplc-3-authenticated-rce

OpenPLC 3 WebServer Authenticated Remote Code Execution.

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2018-7854 preview

CVE-2018-7854

GitHubyanissec/cve-2018-7854

CVE-2018-7854

embedded-systems-securityexploitationpenetration-testing+2
2 years ago
CVE-2025-54962 preview

CVE-2025-54962

GitHubeyodav/cve-2025-54962

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

educationexploitationpenetration-testing+3
1 year ago
CVE-2023-31716 preview

CVE-2023-31716

GitHubmateustesser/cve-2023-31716

Proof-of-concept exploit for CVE-2023-31716, a Local File Inclusion vulnerability in FUXA SCADA/HMI software versions <= 1.1.12, enabling arbitrary…

embedded-systems-securityexploitationscada-ics-security+2
3 years ago
BAS-Guardian preview
Archived

BAS-Guardian

GitHubspinfosecurity/bas-guardian

Free BACnet/BMS vulnerability scanner for building automation systems. Detects CVE-2026-3611 (CVSS 10.0), CVE-2026-24060, and exposed HVAC/BAS…

defensive-toolsinformation-gatheringiot-security+6
11 month ago
Rail-OT-Protector preview
Archived

Rail-OT-Protector

GitHubspinfosecurity/rail-ot-protector

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

defensive-toolsinformation-gatheringnetwork-security+6
11 month ago
trommel preview
Archived

trommel

GitHubcertcc/trommel

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

embedded-systems-securityfirmware-analysishardware-security+6
2136 years ago
CVE-2026-22553-InSAT-MasterSCADA-BUK-TS-MMadmServ preview

CVE-2026-22553-InSAT-MasterSCADA-BUK-TS-MMadmServ

GitHubmbanyamer/cve-2026-22553-insat-masterscada-buk-ts-mmadmserv

Unauthenticated OS command injection exploit for InSAT MasterSCADA BUK-TS MMadmServ web interface. Delivers reverse shell with root privileges via…

command-and-controlexploitationpayload-generation+3
4 months ago
APOLOGEE preview
Archived

APOLOGEE

GitHubrosesecurity/apologee

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

authenticationexploitationexploit-frameworks+8
501 year ago
Kamerka-GUI preview

Kamerka-GUI

GitHubwoj-ciech/kamerka-gui

Ultimate Internet of Things/Industrial Control Systems reconnaissance tool.

exploitationinformation-gatheringiot-security+6
8714 months ago
nerva preview

nerva

GitHubpraetorian-inc/nerva

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian

information-gatheringiot-securitymisconfiguration+4
3634 days ago
Exploits preview

Exploits

GitHubsadfud/exploits

Real world and CTFs exploiting web/binary POCs.

binary-exploitationctfexploitation+3
796 years ago
on-the-fly preview

on-the-fly

GitHubtelefonica/on-the-fly

on-the-fly

exploitationinformation-gatheringiot-security+4
872 years ago
randy preview

randy

GitHubsourceincite/randy

A pre-authenticated RCE exploit for Inductive Automation Ignition

authentication-authorizationexploitationpenetration-testing+3
504 years ago
Previous12345Next