Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
FinalRecon preview

FinalRecon

GitHubthewhiteh4t/finalrecon

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

crawlerdns-analysisinformation-gathering+7
3.0k
4 months ago
tpotce preview

tpotce

GitHubtelekom-security/tpotce

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

defensive-toolseducationinformation-gathering+7
9.6k9 days ago
DROS-VEP-lite preview

DROS-VEP-lite

GitHubtop-celestial-company-ltd/dros-vep-lite

Open-source, 100% reproducible AI Agent Runtime Security Benchmark & Sandbox Environment (RFC-010 Draft Protocol).

ai-securitydefensive-toolsdynamic-analysis-sandboxing+8
1210 days ago
CVE-2024-55591-POC preview

CVE-2024-55591-POC

GitHubexfil0/cve-2024-55591-poc

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

authentication-authorizationexploitationnetwork-security+6
121 year ago
briefr preview

briefr

GitHubsoldier0x0/briefr

Open Vulnerability Intelligence platform, aggregated intel in one dashboard, with correlation and IOC lookups, completely self hosted. All resources…

defensive-toolsioc-managementthreat-feeds-aggregators+2
311 days ago
gasmask preview

gasmask

GitHubtwelvesec/gasmask

Information gathering tool - OSINT

dns-analysisemail-harvestinginformation-gathering+4
1.5k5 years ago
Rock-ON preview

Rock-ON

GitHubsilverpoision/rock-on

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

crawlerdns-subdomain-enumerationinformation-gathering+5
2896 years ago
ghostrecon preview

ghostrecon

GitHubcappricio-securities/ghostrecon

gh0str3con is a All in one cloud based web Recon tool.

crawlerdns-analysisinformation-gathering+5
282 months ago
reconvault preview

reconvault

GitHubparbatzone/reconvault

🔍 Recon notes organizer for bug bounty hunters and CTF players — subdomains, ports, endpoints, vulns, all in one place.

ctfeducationinformation-gathering+6
13 months ago
papers preview

papers

GitHubalt3kx/papers

A handy collection of my public papers, all in one place.

curated-resourceseducationexploitation+3
28 years ago
Grafana-Final-Scanner preview

Grafana-Final-Scanner

GitHubzierax/grafana-final-scanner

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

configuration-auditinginformation-gatheringvulnerability-analysis+3
24422 days ago
CVE-2021-24307-all-in-one-seo-pack-admin-rce preview

CVE-2021-24307-all-in-one-seo-pack-admin-rce

GitHubdarkpills/cve-2021-24307-all-in-one-seo-pack-admin-rce

Proof-of-concept exploit for CVE-2021-24307, an authenticated admin RCE in All in One SEO Pack <= 4.1.0.1 via PHP unserialization, enabling arbitrary…

exploitationpayload-generationpenetration-testing+3
44 years ago
CVE-2021-4045 preview

CVE-2021-4045

GitHub234329a423853/cve-2021-4045

CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all…

embedded-systems-securityexploitationfirmware-analysis+3
19 months ago
conscryptchecker preview

conscryptchecker

GitHubroeeh/conscryptchecker

This app verifies if your device is still vulnerable to CVE-2015-3825 / CVE-2015-3837, aka "One Class to Rule Them All", by checking if it contains…

android-securitymobile-securityvulnerability-analysis+1
410 years ago
CVE-2025-57819-exploit preview

CVE-2025-57819-exploit

GitHubjeanback1/cve-2025-57819-exploit

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

educationexploitationpayload-generation+4
23 months ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubrhz0d/cve-2025-3102

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

authentication-authorizationeducationexploitation+3
21 year ago
CVE-2024-12594 preview

CVE-2024-12594

GitHubrandomrobbiebf/cve-2024-12594

ALL In One Custom Login Page <= 7.1.1 - Missing Authorization to Authenticated (Subscriber+)Privilege Escalation

exploitationpenetration-testingprivilege-escalation+2
1 year ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubnxploited/cve-2025-3102

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

authentication-authorizationeducationexploitation+3
81 year ago
Previous12Next