Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
Rail-OT-Protector preview
Archived

Rail-OT-Protector

GitHubspinfosecurity/rail-ot-protector

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

defensive-toolsinformation-gatheringnetwork-security+6
1
4 days ago
Terrminus-CVE-2026-2406 preview

Terrminus-CVE-2026-2406

GitHubridpath/terrminus-cve-2026-2406

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

exploitationinformation-gatheringiot-security+8
26 months ago
Kamerka-GUI preview

Kamerka-GUI

GitHubwoj-ciech/kamerka-gui

Ultimate Internet of Things/Industrial Control Systems reconnaissance tool.

exploitationinformation-gatheringiot-security+6
8662 months ago
nmap preview

nmap

GitHubnmap/nmap

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

bluetooth-securitydatabase-securitydata-exfiltration+18
13.5k1 day ago
randy preview

randy

GitHubsourceincite/randy

A pre-authenticated RCE exploit for Inductive Automation Ignition

authentication-authorizationexploitationpenetration-testing+3
504 years ago
CVE-2021-26828_ScadaBR_RCE preview

CVE-2021-26828_ScadaBR_RCE

GitHubhev0x/cve-2021-26828_scadabr_rce

Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

exploitationpenetration-testingremote-access-tool+3
95 years ago
CVE-2025-69985 preview

CVE-2025-69985

GitHubjoshuavanderpoll/cve-2025-69985

Python exploit for CVE-2025-69985 targeting FUXA SCADA software. Sends crafted JSON payload to /api/runscript endpoint to bypass authentication and…

authenticationexploitationremote-access-tool+3
36 months ago
CVE-2025-69985 preview

CVE-2025-69985

GitHubkaleth4/cve-2025-69985

PoC exploit for CVE-2025-69985: authentication bypass leading to RCE in FUXA SCADA ≤1.2.8. Includes a modular Python exploit with interactive shell,…

authentication-authorizationexploitationpayload-development+5
3 months ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubuserb1ank/cve-2021-31630

Exploit for CVE-2021-31630 in OpenPLC, providing a Python script and manual steps to achieve remote code execution via malicious ST file upload and…

command-and-controlexploitationpayload-development+3
10 months ago
CVE-2025-41646---Critical-Authentication-Bypass- preview

CVE-2025-41646---Critical-Authentication-Bypass-

GitHubgreenforcenetworks/cve-2025-41646---critical-authentication-bypass-

CVE-2025-41646 - Critical Authentication bypass

authentication-authorizationexploitationids-ips-evasion+5
11 year ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubmanuelsantosiglesias/cve-2021-31630

OpenPLC 3 WebServer Authenticated Remote Code Execution.

command-and-controlexploitationpenetration-testing+4
2 years ago
scapy preview

scapy

GitHubsecdev/scapy

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

bluetooth-securitycryptographydata-exfiltration+23
12.5k4h 17m ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k3 days ago
UltraViolet preview

UltraViolet

GitHubyakushstanislav/ultraviolet

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

dns-analysisincident-responseiot-security+6
447 days ago
CVE-2022-29593 preview

CVE-2022-29593

GitHub9lyph/cve-2022-29593

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

authenticationexploitationfuzzing+8
81 year ago
CVE-2026-9645-ScadaBR-Analysis preview

CVE-2026-9645-ScadaBR-Analysis

GitHub0xmhany/cve-2026-9645-scadabr-analysis

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

educationpapers-researchscada-ics-security+1
19 days ago
CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara preview

CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara

GitHubgainsec/cve-2017-16744-and-cve-2017-16748-tridium-niagara

Proof of Concept (PoC) for CVE: 2017-16744 and 2017-16748

exploitationpenetration-testingscada-ics-security+2
54 years ago
CVE-2021-26828-Ultimate preview

CVE-2021-26828-Ultimate

GitHubridpath/cve-2021-26828-ultimate

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

command-and-controlexploitationinformation-gathering+6
58 months ago
Previous123Next