Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
97 results
Unauthenticated-RCE-FUXA-CVE-2023-33831 preview

Unauthenticated-RCE-FUXA-CVE-2023-33831

GitHubrodolfomarianocy/unauthenticated-rce-fuxa-cve-2023-33831

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

exploitationpayload-generationpenetration-testing+4
12
1 year ago
CVE-2023-30459 preview

CVE-2023-30459

GitHubtoxich4/cve-2023-30459

CVE-2023-30459

exploitationpayload-generationremote-access-tool+2
33 years ago
trommel preview
Archived

trommel

GitHubcertcc/trommel

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

embedded-systems-securityfirmware-analysishardware-security+6
2136 years ago
Malcolm preview

Malcolm

GitHubcisagov/malcolm

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

dns-analysisforensicsids-ips-evasion+7
2.5k22 days ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k20 days ago
fapro preview

fapro

GitHubfofapro/fapro

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…

defensive-toolsfingerprint-spoofinginformation-gathering+3
1.6k1 year ago
nerva preview

nerva

GitHubpraetorian-inc/nerva

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian

information-gatheringiot-securitymisconfiguration+4
3523 days ago
ics-forensics-tools preview

ics-forensics-tools

GitHubmicrosoft/ics-forensics-tools

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

digital-forensicsforensicsincident-response+2
3721 year ago
ICSSecurityScripts preview

ICSSecurityScripts

GitHubtijldeneut/icssecurityscripts

Python scripts for security assessment of industrial PLCs: scanning, enumeration, control, and exploitation of Beckhoff, Siemens, Schneider,…

exploitationnetwork-mappingscada-ics-security+1
1515 months ago
randy preview

randy

GitHubsourceincite/randy

A pre-authenticated RCE exploit for Inductive Automation Ignition

authentication-authorizationexploitationpenetration-testing+3
504 years ago
bof preview

bof

GitHuborange-cyberdefense/bof

BOF (Boiboite Opener Framework) is a testing framework for industrial protocols implementations and devices.

exploitationfuzzinginformation-gathering+6
531 year ago
ripple20 preview

ripple20

GitHubcorelight/ripple20

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

anomaly-detectionintrusion-detectioniot-security+3
324 years ago
Indushell preview

Indushell

GitHubsecarmalabs/indushell

PoC C&C for the Industroyer malware

command-and-controlexploitationmalware-analysis+3
269 years ago
Industrial Security Auditing Framework preview

Industrial Security Auditing Framework

GitLabd0ubl3g/industrial-security-auditing-framework

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.

exploit-frameworksnetwork-securitypenetration-testing+2
75 years ago
CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara preview

CVE-2017-16744-and-CVE-2017-16748-Tridium-Niagara

GitHubgainsec/cve-2017-16744-and-cve-2017-16748-tridium-niagara

Proof of Concept (PoC) for CVE: 2017-16744 and 2017-16748

exploitationpenetration-testingscada-ics-security+2
54 years ago
CVE-2021-26828-Ultimate preview

CVE-2021-26828-Ultimate

GitHubridpath/cve-2021-26828-ultimate

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

command-and-controlexploitationinformation-gathering+6
58 months ago
Rail-OT-Protector preview

Rail-OT-Protector

GitHubspinfosecurity/rail-ot-protector

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

defensive-toolsinformation-gatheringnetwork-security+6
14 days ago
FUXAPWN preview

FUXAPWN

GitHubhann1bl3l3ct3r/fuxapwn

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

exploitationinformation-gatheringlateral-movement+8
2 months ago
Previous123456Next